Skip to content
LNU News
  • Economy
  • Geopolitics
  • Health
  • Society
  • Technology
truffa postino QR code

A letter containing a QR code can empty your account: how to recognize the “postman scam”

November 25, 2024

An apparently harmless letter delivered by the postman, which appears to come from an authoritative body such as the Italian Post Office, contains a QR code, i.e. a square identification code made of black and white “pixels”. Known as “postman scam”this fraud uses social engineering to trick users into downloading a fake app containing malware by scanning the malicious QR code. Once installed, in fact, the malware takes control of the user’s sensitive data, including banking credentials and personal information, putting your digital security at risk. The phenomenon, initially reported in Switzerland, is also spreading in Italy, particularly affecting Android users. Below, we explain in more detail How the “postman scam” workshow to recognize it and how to protect yourself.

How the “postman scam” arrived in Italy works and how to recognize it

The scam presents itself with a physical letter, apparently sent by a government institution or a reliable body, inviting you to download a dedicated app, often linked to security or emergency issues, such as weather alerts or civil protection notifications. The trick is simple but effective: at the bottom of the letter you will find a QR codewhich is a square image with black modules on a white background which, if scanned, redirects you to the download of ainfected app. The QR code, originally conceived to simplify access to digital content, has also become a popular means for scammers, thanks to its spread during the pandemic, causing incidents of Quishing or QR phishing (i.e. phishing perpetrated through the use of QR codes).

A recent example of this fraud emerged in Switzerland, where many citizens received bogus letters apparently sent by the Federal Office of Meteorology and Climatology MeteoSwiss and from FOCP (Federal Office for Civil Protection). The QR code in question redirected to the download of an app named Severe Weather Warning Appwhich instead contained the malware Cover (also known as Octo2). This malicious software, once installed on Android devices, disguises itself as an official civil protection app, even modifying the graphic appearance to appear authentic. In reality, the malware aims to steal login credentials from over 380 appsincluding home banking services, thus putting the victims’ current accounts at risk.

Similar cases have also been reported in Italy, with stickers containing fake QR codes attacked in car parks or inserted in messages apparently sent by banking institutions. In this context, scammers use phishing techniques, a form of digital deception that uses fake messages or websites to steal personal data. For example, they clone QR codes of banking portals or payment systems, tricking victims into entering their credentials on fake pages.

One of the letters delivered to Switzerland by scammers. Credit: NCSC.

How to protect yourself from the QR code scam that can empty your bank account

To protect yourself from this threat, take some basic precautions. Never scan a QR code that comes from an unknown or suspicious source. Remember that applications from public bodies, banks, etc. must be downloaded exclusively from official stores such as the Google Play Store or the App Store. And if you are contacted in some way by your bank (via a paper letter, via e-mail, via message, with a phone call, etc.), ensure the legitimacy of the communications receivedespecially if you are invited to carry out potentially suspicious actions, perhaps contacting customer service yourself to ascertain how things really are.

If you suspect you have fallen for a scam, act quickly. Uninstall the suspicious app and reset your device to factory settings to eliminate the malware. Equally important, report the incident to the competent authoritieslike the Postal Police.

Categories Technology
What is an Ops, the type of offer that Unicredit uses to buy Banco Bpm
Cargo plane crashes into a building near Vilnius airport in Lithuania: causes still unknown
Recent posts
BancoPosta Universo Tematico, come funziona il fondo che investe nei megatrend del futuro
BancoPosta Universo Tematico, how the fund that invests in the megatrends of the future works
OpenAI: perché il rinvio dell’IPO al 2027 sta facendo tremare i mercati
OpenAI postpones IPO to 2027: markets and Big Tech stocks collapse
The schism of the Lefebvrians is not the first in history: because a separation between believers can occur
The schism of the Lefebvrians is not the first in history: because a separation between believers can occur
Whatsapp activates the username instead of the phone number: how to get it and why to do it immediately
Whatsapp activates the username instead of the phone number: how to get it and why to do it immediately
BCE: Lagarde a Sintra delinea nuova strategia su tassi e inflazione
ECB: Lagarde defends interest rate policy “meeting by meeting”
Spread Btp-Bund a 69 punti base, il differenziale crolla con i rendimenti al 3,58%
Btp-Bund spread at 69 basis points, the differential collapses with yields at 3.58%
fondo pensione
What changes for TFR and pension fund from 1st July: silent consent starts for 60 days for new hires
Deaths from heat, Italy is the European country most at risk: 94% of the regions worsen every year
Deaths from heat, Italy is the European country most at risk: 94% of the regions worsen every year
Aste dei titoli di Stato, 19,25 miliardi raccolti tra il 24 e il 26 giugno: i rendimenti
Government bond auctions, 19.25 billion raised between 24 and 26 June: the yields
Fondi pensione, nuove regole dal 1° luglio: ecco cosa sapere
Pension funds, new rules from 1 July
© 2026 LNU News - [email protected]
About us Contact