Letter threatens account suspension
A man from the German city of Görlitz lost 10,000 euros after scanning a QR code in a fake bank letter, according to a police report dated 7 October 2026 and carried by several regional news sites. The man found a letter from what appeared to be his business bank in his mailbox on Tuesday, 6 October.
The letter threatened to suspend his account and asked him to scan a QR code, police said. The man did so. The perpetrators then gained access to his accounts and debited a total of 10,000 euros. He filed a criminal complaint. The report did not name the bank the perpetrators impersonated.
A QR code hides the address it leads to. Police pointed out that the decisive part of a web address is easily overlooked on small smartphone screens.
Call displaying the bank's real number
Police in the state of Brandenburg reported a similar case. A 61-year-old woman from Gumtow in the Prignitz district received a letter that appeared to come from her bank, according to the Polizeidirektion Nord. That letter also contained a QR code, which the woman scanned with her smartphone, the newspaper Nordkurier reported on 6 October 2026.
Shortly afterwards she received a phone call. Her bank's actual phone number appeared on the display, police said. The callers claimed her account details had been stolen and persuaded her to confirm several debits. She later became suspicious and contacted her bank directly. The loss amounts to a low five-figure sum, police said. Criminal investigators are investigating the case as fraud.
| Görlitz | Gumtow (Prignitz) | |
|---|---|---|
| Reported | 7 October 2026 | 6 October 2026 |
| Letter sender | Supposedly his business bank | Supposedly her own bank |
| Pretext | Threatened account suspension | Not stated |
| After the scan | Perpetrators gain access to the accounts | Call showing the bank's real number on the display |
| Loss | 10,000 euros | Low five-figure sum |
Freiburg police reported cases in August
The combination of a QR code and supposed bank employees has been reported in other regions as well. Freiburg police warned in August 2026 of a cluster of such cases. The perpetrators posed as bank employees and claimed suspicious direct debits had reached the victims' accounts, police said. To cancel them, victims were told to follow a QR code. The total loss amounted to several tens of thousands of euros, according to police.
In September 2026, a doctor from Thuringia lost about 100,000 euros after a fake Apobank letter and a follow-up phone call (report). In March 2026, Heilbronn police warned of bank letters with QR codes after a case in Tauberbischofsheim (report).
Police advice
- • If in doubt, do not scan a QR code from an unexpected letter.
- • Check your bank's website for warnings about current fraudulent letters.
- • After scanning, check the displayed address carefully before opening the page.
- • Use your bank's app for online banking instead of a QR code.
- • A bank number shown on the display does not prove the call is genuine. Hang up and call the bank yourself on the number you know.
- • If money has already left your account, inform your bank immediately, have your cards blocked and report the case to the police.
Check QR codes before opening them
QRTrust displays a QR code's full destination address and checks it against multiple phishing databases and AI models before it opens.
The quishing map lists documented incidents with location, date, method and source.
View the quishing map →Sources
- Die Sachsen: Quishing in Görlitz: Mann verliert 10.000 Euro nach QR-Code-Betrug (07.10.2026)
- news.de: Polizei-News Görlitz, 07.10.2026: Betrügerischer QR-Code und weitere Fälle
- Nordkurier: Prignitzerin mit QR-Code betrogen (06.10.2026)
- Polizeipräsidium Freiburg: Warnmeldung vor Betrug mit manipulierten QR-Codes (August 2026)
About QRTrust
QRTrust is Germany's first QR code security platform, developed in Dortmund. AI-powered real-time detection, a local threat database and multi-layered security checks protect citizens, authorities and businesses from quishing attacks. GDPR compliant, hosted in Germany.
