Criminals in parts of Europe have been mailing fake “replacement” bank cards or letters claiming a card is expiring, pushing victims to scan a QR code or visit a URL to “activate” the card. The QR code redirects to a fake banking site that harvests login and account details, potentially giving attackers access to real accounts. The article also notes ongoing payment-card skimming against magnetic-stripe benefit cards (EBT), showing older fraud methods remain profitable.
How the Attack Worked
Criminals in parts of Europe have been mailing fake replacement bank cards or letters claiming a card is expiring. The letters push victims to scan a QR code or visit a URL to activate the new card. Rather than leading to a real bank portal, the code or link redirects to a fake banking website designed to harvest login credentials and account details, potentially giving attackers direct access to victims' real accounts.
Some of the fake cards even include the victim's real name printed on them, a personalization detail meant to increase trust and improve conversion rates for the scam.
Why It Succeeded
This scam works because it exploits trust in physical mail and official-looking materials. Most people are trained to be wary of suspicious emails, but a letter with a printed card and their own name feels more legitimate. The urgency of an expiring card creates pressure to act quickly, and the QR code obscures the destination URL, making it harder for victims to spot a suspicious link before scanning.
The attack also blends old-school physical mail tactics with modern phishing infrastructure, catching people off guard because it does not match the digital patterns most awareness training focuses on.
What to Watch For
- Unexpected replacement card mail or letters, even when no card is actually expiring
- Requests to activate or register a card using a QR code or URL rather than a known bank channel
- Pressure language urging immediate registration or activation
- Cards or letters personalized with a real name, which is not proof of legitimacy
How to Build Resistance
Employees and consumers should treat unexpected mail about account or card changes the same way they would treat a suspicious email: verify through a trusted channel such as the official bank app, phone number, or website, not the QR code or link provided in the mailing. Organizations can reinforce this by reminding staff and customers that personalization does not equal authenticity.
The same report also highlights that magnetic-stripe skimming, particularly against EBT/SNAP benefit cards, remains a profitable and ongoing fraud method. Practical habits like avoiding card swiping when possible and checking payment terminals for signs of tampering or alteration can reduce exposure to this separate but related threat. Awareness programs should cover both digital and physical vectors, since this case shows attackers continuing to profit from older, low-tech methods alongside newer QR-based phishing.
Key Takeaway
QR codes and physical mail are not inherently trustworthy just because they arrive through an official-seeming channel. Verification through independently confirmed contact methods remains the most reliable defense against this type of social engineering.
Key findings
- Criminals have mailed phony replacement cards/letters that claim the victim’s card is expiring and must be “activated” via a QR code or URL.
- Scanning the QR code typically redirects victims to a fake banking website that requests sensitive details, enabling account takeover.
- Some fake cards include the victim’s real name to increase trust and conversion rates.
- The article also highlights ongoing magnetic-stripe skimming (especially targeting EBT/SNAP benefit cards) as a separate, still-profitable fraud method.
Who’s being targeted
- Commonly targeted roles: All employees, Finance, Executives, Customer support / helpdesk (for reporting and guidance).
- Affected industries: Retail banking / digital banks, Government benefits programs (EBT/SNAP), Consumers/households.
- Attack channels: physical, website.
- Impersonated: Victim’s bank / card issuer.
Red flags to watch for
- Unexpected replacement card/letter even if no card is expiring
- Activation request via QR code/URL leading to a login page
- Pressure to ‘register’/‘activate’ outside known bank channels
Frequently asked questions
How does the fake bank card mail scam work?
Criminals mail phony replacement cards or letters claiming a current card is expiring and must be activated via a QR code or URL. Scanning the code typically redirects victims to a fake banking website that harvests login and account details.
Why do people fall for fake replacement card letters?
Some fake cards include the victim's real name printed on them, which increases trust even though personalization is not proof the mail is legitimate.
What should I do if I get an unexpected card activation letter?
Verify through a trusted channel such as the official bank app, website, or phone number rather than the QR code or URL included in the letter.
Is this scam limited to QR codes and phishing sites?
No, the same report also notes that magnetic-stripe skimming, especially against EBT/SNAP benefit cards, remains a separate but still profitable fraud method.
Read the video transcript
You open your mail and see a shiny new bank card with your real name on it and a note: “Your card is expiring, activate this one now.” Here’s the trick: the letter pushes you to scan a QR code or visit a URL to “activate” it. That code sends you to a fake banking site that quietly steals your login and account details. Aha moment: just because your name is printed on the card doesn’t make it real. Criminals buy mailing lists, print your name, and rely on you trusting the QR code more than your own bank app. If you ever get an unexpected “replacement” card or activation letter, ignore the QR code and URL, open your official banking app or call the number on the back of your real card instead.