Product1 publisher3 min readPublished
Fake replacement cards mailed in Europe use QR 'activation' codes to harvest banking details
Criminals in Portugal, France and Germany are posting fake replacement cards whose QR 'activation' codes lead to fake bank sites. Banks that warn only about texts and email now need a rule customers can apply to a letter that copies a renewal notice.
The Product Desk · Product desk

What happened
- Criminals in Portugal, France and Germany have mailed fake replacement cards or letters to potential victims in waves over recent years.
- The letters tell recipients to activate the new card through an enclosed QR code or URL.
- The code leads to a fake banking website that asks for the victim's details, potentially giving criminals direct access to their real accounts.
- Some of the fake cards carry the recipient's real name, according to Georg Hauer, an adviser to digital banks.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- decision Banks whose genuine renewal letters ask customers to scan a code or visit a URL have to weigh that convenience against giving customers a simple rule that exposes the fake.
- exposure If Hauer is right that the scheme has paid off, bank customers in countries beyond the three already hit are the next audience for the same envelope.
- cost With AI-copied designs making personalised fakes cheap, per Hauer, fraud teams now have to spend on warnings and support for the postal channel as well as for phones.
A customer whose card has years left to run can still open a letter warning that it is about to expire. The scam letters make that claim whether or not the recipient has a card near its expiry date [2]. The pitch only has to work on people who don't check the date on the card in their wallet.
"The card is almost like a token that creates the trust that is needed in order to fall for the actual trick," Hauer said [5]. The card is fake [1]. It is there so the QR code looks like the last step of a renewal the bank itself started.
A fraud team can easily assume that customers who have learned to distrust a link in a text will be just as suspicious of an envelope. Hauer's account of what customers actually do points the other way. He said the cost of making a personalised fake card has fallen because AI can copy a card design from an image [8]. He also said that "the higher conversion rate per victim might justify the extra costs" [8]. A fraudster pays for printing and postage only if a letter converts better than a text, and Hauer thinks it may.
He expects the scheme to spread. "This has been escalating for close to two years, and I believe that this type of scam might have proven to be successful enough to be rolled out in other countries," he said [7]. Wired's newsletter does not give loss figures for the European waves or name the banks whose cards were copied. The claim about conversion rests on Hauer alone.
Physical fraud channels are slow to close in the US too. Two Romanian nationals were indicted in the Northern District of Alabama on charges tied to skimming SNAP benefits from magnetic-stripe-only EBT cards [10]. "Skimmer fraud is rampant with losses in the United States alone reaching over $1 billion each year," US Attorney Phillip W. Williams Jr. said, a figure that covers several kinds of skimming [9]. Mastercard said it will stop issuing striped cards in 2029 and that the last of them will be out of circulation by 2033 [11]. Striped cards will stay in use for four years after issuing stops [12].
For a bank, the test is its own genuine renewal letter. Sort every customer message on two axes. One is whether it arrives on a screen or on paper. The other is whether it asks the customer to act inside the message, by scanning a code or typing a URL. The fake letter sits in the paper box that asks for action on the spot [3]. If the bank's real letter sits there too, the customer has no rule for telling the two apart. I think the real letter belongs in a different box. Send customers to activate in the app they already use, or by phoning the number on the back of the old card, and print on every renewal that the bank never asks for activation from a letter. The tradeoff is slower activation and more support calls after each card cycle. In return, customers get a rule they can check against any letter.
What to watch
- Reports of the mailed fake-card scheme outside Portugal, France and Germany would confirm Hauer's expectation that it spreads.
- Loss figures from banks or police in the three countries would test Hauer's claim that the letters convert better per victim.
- Banks whose cards have been copied dropping QR or URL activation from their genuine renewal letters.