The Republican National Guard (GNR) is warning about a sophisticated bank fraud scheme that uses traditional mail to steal money and personal data. Victims receive at home a letter seemingly sent by their bank, which contains a supposed new bank card with their personal details, making the communication particularly convincing. The letter states that the previous card has expired and that it is necessary to quickly activate the new one to avoid the bank account being blocked.
The dangerous element of the letter is a QR code that must be scanned to supposedly activate the card. When scanning the code, the victim is redirected to a fake page that mimics the appearance of the bank's real website, a technique known as "quishing," a variant of phishing. When access credentials or banking information are entered on this page, the data is immediately handed over to the scammers, resulting in loss of money and potential identity theft.
This method has proven particularly effective because many Portuguese citizens are already suspicious of SMS and emails requesting clicks on links, whereas a physical letter received at home can transmit a greater sense of security. Additionally, unlike written links where users can observe the address before opening the page, the destination of a QR code is less evident to the user before scanning. According to GNR, this method has shown strong growth due to the trust associated with postal and banking services.
GNR recommends never using QR codes received by mail to activate bank cards, even if the letter appears legitimate. In case of doubt, citizens should contact the banking institution directly through official channels they already know, such as the bank's app, the official website, or the usual phone contact. Banking credentials or personal information should never be entered on pages opened through QR codes whose origin cannot be confirmed.




