The Guarda Nacional Republicana issued a public warning about a sophisticated wave of fraud that combines fraudulent postal correspondence with cloned internet pages. Victims receive at home letters with graphics and logos copied from major credit institutions, containing a personalized bank card with their name. The message claims that card replacement is necessary due to imminent expiry or a mandatory update of security parameters, creating a sense of urgency through a short deadline for validation.
The scheme uses the technique called "quishing", a variant of digital identity theft that replaces traditional hyperlinks with QR codes. By scanning the code printed on the letter, victims are redirected to a computer platform identical to their banking institution's online banking portal. On this fake website, extremely sensitive data is requested, such as usernames, passwords, tax identification numbers and temporary confirmation codes sent by SMS.
The scammers deliberately exploit the traditional postal channel, taking advantage of the false sense of security associated with sealed letters on letterhead, which continue to enjoy a presumption of authenticity in the popular subconscious. QR codes also make it difficult to preview the true destination of the link, unlike text hyperlinks on the internet.
The damages are not limited to immediate financial theft, including illegitimate bank transfers and unauthorized purchases. In the medium term, the biometric, identity and contractual data captured feeds clandestine databases traded on obscure computer networks, enabling the subscription of credit contracts in someone else's name. GNR emphasizes that no national banking institution requires card activation through QR codes on paper support, and citizens should refuse to scan such codes, contact the bank directly through official channels and file a complaint if they receive suspicious material.




