Fake Bank Cards in the Mail Still Work

Wired Security · Medium sophistication
Last updated September 28, 2026

Criminals in parts of Europe have been mailing fake “replacement” bank cards or letters claiming a card is expiring, pushing victims to scan a QR code or visit a URL to “activate” the card. The QR code redirects to a fake banking site that harvests login and account details, potentially giving attackers access to real accounts. The article also notes ongoing payment-card skimming against magnetic-stripe benefit cards (EBT), showing older fraud methods remain profitable.

How the Attack Worked

Criminals in parts of Europe have been mailing fake replacement bank cards or letters claiming a card is expiring. The letters push victims to scan a QR code or visit a URL to activate the new card. Rather than leading to a real bank portal, the code or link redirects to a fake banking website designed to harvest login credentials and account details, potentially giving attackers direct access to victims' real accounts.

Some of the fake cards even include the victim's real name printed on them, a personalization detail meant to increase trust and improve conversion rates for the scam.

Why It Succeeded

This scam works because it exploits trust in physical mail and official-looking materials. Most people are trained to be wary of suspicious emails, but a letter with a printed card and their own name feels more legitimate. The urgency of an expiring card creates pressure to act quickly, and the QR code obscures the destination URL, making it harder for victims to spot a suspicious link before scanning.

The attack also blends old-school physical mail tactics with modern phishing infrastructure, catching people off guard because it does not match the digital patterns most awareness training focuses on.

What to Watch For

  • Unexpected replacement card mail or letters, even when no card is actually expiring
  • Requests to activate or register a card using a QR code or URL rather than a known bank channel
  • Pressure language urging immediate registration or activation
  • Cards or letters personalized with a real name, which is not proof of legitimacy

How to Build Resistance

Employees and consumers should treat unexpected mail about account or card changes the same way they would treat a suspicious email: verify through a trusted channel such as the official bank app, phone number, or website, not the QR code or link provided in the mailing. Organizations can reinforce this by reminding staff and customers that personalization does not equal authenticity.

The same report also highlights that magnetic-stripe skimming, particularly against EBT/SNAP benefit cards, remains a profitable and ongoing fraud method. Practical habits like avoiding card swiping when possible and checking payment terminals for signs of tampering or alteration can reduce exposure to this separate but related threat. Awareness programs should cover both digital and physical vectors, since this case shows attackers continuing to profit from older, low-tech methods alongside newer QR-based phishing.

Key Takeaway

QR codes and physical mail are not inherently trustworthy just because they arrive through an official-seeming channel. Verification through independently confirmed contact methods remains the most reliable defense against this type of social engineering.

Key findings

  • Criminals have mailed phony replacement cards/letters that claim the victim’s card is expiring and must be “activated” via a QR code or URL.
  • Scanning the QR code typically redirects victims to a fake banking website that requests sensitive details, enabling account takeover.
  • Some fake cards include the victim’s real name to increase trust and conversion rates.
  • The article also highlights ongoing magnetic-stripe skimming (especially targeting EBT/SNAP benefit cards) as a separate, still-profitable fraud method.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Executives, Customer support / helpdesk (for reporting and guidance).
  • Affected industries: Retail banking / digital banks, Government benefits programs (EBT/SNAP), Consumers/households.
  • Attack channels: physical, website.
  • Impersonated: Victim’s bank / card issuer.

Red flags to watch for

  • Unexpected replacement card/letter even if no card is expiring
  • Activation request via QR code/URL leading to a login page
  • Pressure to ‘register’/‘activate’ outside known bank channels
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the fake bank card mail scam work?

Criminals mail phony replacement cards or letters claiming a current card is expiring and must be activated via a QR code or URL. Scanning the code typically redirects victims to a fake banking website that harvests login and account details.

Why do people fall for fake replacement card letters?

Some fake cards include the victim's real name printed on them, which increases trust even though personalization is not proof the mail is legitimate.

What should I do if I get an unexpected card activation letter?

Verify through a trusted channel such as the official bank app, website, or phone number rather than the QR code or URL included in the letter.

Is this scam limited to QR codes and phishing sites?

No, the same report also notes that magnetic-stripe skimming, especially against EBT/SNAP benefit cards, remains a separate but still profitable fraud method.

Read the video transcript

You open your mail and see a shiny new bank card with your real name on it and a note: “Your card is expiring, activate this one now.” Here’s the trick: the letter pushes you to scan a QR code or visit a URL to “activate” it. That code sends you to a fake banking site that quietly steals your login and account details. Aha moment: just because your name is printed on the card doesn’t make it real. Criminals buy mailing lists, print your name, and rely on you trusting the QR code more than your own bank app. If you ever get an unexpected “replacement” card or activation letter, ignore the QR code and URL, open your official banking app or call the number on the back of your real card instead.

Similar attacks

AI Search Results Turn Into Phishing Traps

AI Search Results Turn Into Phishing Traps

This bulletin describes multiple real-world scams where attackers make fake pages and messages look like routine, trusted experiences (search answers, Google login pop-ups, “giveaways,” and official-sounding calls). Examples include a fake Claude Max giveaway using a convincing fake Google sign-in…

September 24, 2026
FBI Warns of OAuth Consent Phishing Tricks

FBI Warns of OAuth Consent Phishing Tricks

A SecurityWeek roundup highlights multiple real-world scams and campaigns where attackers trick people rather than “hack” systems directly. Notable items include OAuth “consent phishing” (getting users to approve a malicious app’s access), and phishing-evasion using invisible Unicode characters…

September 11, 2026
Fake IRS Letters Push Crypto “Compliance Portal”

Fake IRS Letters Push Crypto “Compliance Portal”

Scammers are mailing official-looking “IRS” letters to cryptocurrency holders, urging them to scan a QR code and enroll in a fake “Digital Asset Compliance Portal.” The QR code leads to a fraudulent IRS-lookalike site that gathers wallet/exchange details and then prompts victims to provide a phone…

August 4, 2026
M365 “Direct Send” Abused for Internal-Looking Phish

M365 “Direct Send” Abused for Internal-Looking Phish

Researchers observed a real phishing campaign that abused Microsoft 365’s Direct Send feature to make emails look like they came from the victim organization’s own domain, without compromising an employee account. The campaign was timed to mimic human sending patterns during U.S. Eastern business…

September 14, 2026
Kali365 OAuth Phish Bypasses Password Theft

Kali365 OAuth Phish Bypasses Password Theft

The article describes an FBI-warned phishing operation (Kali365) that tricks Microsoft 365 users into approving access via a real Microsoft device-code login flow, often without stealing a password. Victims are lured with document-sharing themed emails and prompted to enter a device code,…

September 8, 2026
DocuSign Share Lure Steals Microsoft 365 Sessions

DocuSign Share Lure Steals Microsoft 365 Sessions

Researchers described an active phishing operation using real DocuSign notifications to trick employees into opening a fake “remittance-advice” document and clicking a hidden malicious link. The attack routes victims through legitimate Microsoft/Google pages before landing on an…

August 28, 2026