Fake Bank Letters with QR Codes in Circulation

Fraudsters are sending counterfeit letters that appear to come from Deutsche Bank, according to the bank. The letters often carry subject lines such as 'Banking App Update Required' or 'TAN Procedure Update Necessary' and contain a QR code.

The letters claim the QR code is needed to update the recipient's TAN device or BestSign procedure. According to police, it is in fact a so-called quishing attack, a combination of QR code and phishing.

How the Scheme Works

According to police, the perpetrators proceed in several steps:

  1. Fake letters are sent in Deutsche Bank's corporate design with copied logos and layouts
  2. The letters claim that identity verification or a TAN update is required under EU regulations (AML/KYC)
  3. A QR code is presented as a quick way to complete the supposed process
  4. Scanning the code leads to a counterfeit banking page
  5. Login credentials, TANs, credit card details or personal information are requested and harvested there

Signs of a Fake Letter

Unexpected Letters

The letters arrive unsolicited and refer to an update that was never requested

QR Codes in Bank Letters

Banks say they do not send QR codes for security updates by letter

Urgency and Threats

The letters create time pressure or threaten account suspension

Spelling Errors

Unusual wording or grammatical errors can indicate a forgery

No Personal Salutation

The correct salutation with the recipient's full name is often missing

Deutsche Bank's Response

Deutsche Bank advises recipients to disregard and dispose of such letters. Customers who have already scanned the QR code or entered data should contact the bank immediately, it said.

The bank said it never asks customers to enter sensitive data such as PINs, TANs or passwords by email, text message, phone or letter.

Deutsche Bank said it would never ask customers to enter their login credentials or update their TAN procedure via a QR code in a letter.

Recommended Precautions

  • Do not scan QR codes from unsolicited letters: Banks, authorities and insurers say they use other channels for security updates
  • Check destination addresses before opening: Verification services compare the address behind a QR code against databases of known phishing sites
  • Contact the bank directly: In case of doubt, use the phone number on the bank card, not the number given in the letter
  • Do not enter TANs on external sites: Banks say they do not ask customers to enter a TAN on a website reached via a link or QR code
  • Report suspicious letters: Deutsche Bank accepts reports at phishing@deutsche-bank.de; a police report can also be filed

Advice for Affected Customers

Police advise those who have already entered data to take the following steps:

  • 1.Have online banking blocked via the emergency hotline 116 116
  • 2.Contact the bank using its official service number
  • 3.Change all passwords and PINs
  • 4.File a report with the police
  • 5.Document the incident with screenshots and keep the letter

According to police, acting quickly improves the chances of limiting financial damage.

Background: Postal Mail as a Delivery Channel

The case shows that criminals are increasingly using traditional mail for phishing. Police point to similar cases in which letters were sent in the names of various banks.

Authorities advise against scanning unsolicited QR codes and recommend reporting suspicious letters to the bank or the police.

Check QR Codes Before Opening

QRTrust checks the destination URL of a QR code against databases of known phishing sites before the website opens.

Use QRTrust for Free

Sources and Further Information

This article is based on the following warnings and reports: