BankSorter
Loans Personal Accounts Savings Accounts Financial Apps Blog Rankings Loans Personal Accounts Savings Accounts
MARKET COMMENTARY

Phishing Wave Hits Sparkasse: What Quishing Means for You

Sparkasse, Volksbank and Postbank warn of phishing and QR-code fraud (quishing). Learn how to protect yourself and elderly relatives right now.

LH
Lukas Hoffmann · 13 July 2026 · 8 min read
Phishing Wave Hits Sparkasse: What Quishing Means for You
Key takeaways
What actually happened in early July
How quishing works technically and how it differs from classic phishing
Why older people are specifically targeted by the bank-employee trick
The perpetrators' calculation

Phishing Wave Hits Sparkasse, Volksbank and Postbank: What This Fraud Campaign Means for You

In early July 2026, specifically between 2 and 4 July, a targeted phishing wave swept over customers of Sparkasse, Volksbank and Postbank. Fraudsters sent fake emails and QR codes designed to look deceptively like official bank communications. Sparkasse responded as early as 2 July with an official warning to its customers. At the same time, police in several German states recorded cases in which fraudsters posed as bank security staff and specifically targeted elderly people to collect their debit cards and PINs. Two different scams, one common thread: both aim to exploit trust in one's own bank to obtain login credentials or cash directly. As a financial journalist, let me walk you through what this wave actually means, how the newer "quishing" method technically works, and why older people in particular are being targeted by the so-called bank-employee trick.

What actually happened in early July

The fake emails sent in the name of Sparkasse, Volksbank and Postbank followed a now-familiar pattern: recipients were asked, allegedly for security reasons, to confirm their login credentials, update their pushTAN app, or release a supposedly blocked transfer. The crucial difference from many earlier waves was the use of QR codes instead of classic links. Instead of clicking a blue underlined link, victims were asked to scan a QR code embedded in the email or an attached document using their smartphone. This detail is precisely what makes the current wave technically more sophisticated and harder for many spam filters to detect than classic text-based phishing.

At the same time, police in several regions reported cases of the so-called bank-employee trick: unknown callers phoned elderly people, claiming to be employees of the bank or savings bank, and alleged that the victim's debit card was faulty, compromised, or urgently needed replacing. During the call, they skilfully asked for the PIN as well, supposedly for "verification" or the card exchange. Shortly afterwards, a supposed courier or collection agent appeared in person at the victim's front door to pick up the "faulty" card. With the card and PIN in hand, the perpetrators were then able to withdraw cash at an ATM before the victims even realised something was wrong.

How quishing works technically and how it differs from classic phishing

Quishing is a portmanteau of "QR code" and "phishing" and describes fraud attempts in which fake QR codes are used instead of text links to steal login credentials. The underlying principle stays the same: after scanning, the victim ends up on a fake login page that looks deceptively similar to the real online banking portal and enters their credentials there. The crucial difference lies in how easily it can be spotted:

  • No visible link: With classic email phishing, you can hover your mouse over a link and check the destination URL in the status bar. A QR code does not reveal its destination until you have actually scanned it.
  • Switching devices: The email is often read on a computer, but the QR code is scanned with a smartphone. This means many of the security warnings built into email programs or the computer's browser protections never get a chance to trigger.
  • Lower vigilance toward images: Many people have by now learned not to click suspicious links, but still regard an image like a QR code as harmless.
  • Combination with phone fraud: In the current cases, scanning the code and entering data was sometimes followed by a call from a supposed bank employee who additionally requested a TAN for a transfer. This combination of digital and personal contact considerably increases the fraudsters' success rate.

It is important to know that QR codes can also appear on paper, for instance on fake letters, flyers, or even stickers placed over genuine QR codes at ATMs. The warning therefore applies not only to emails but to any QR code whose origin you cannot verify beyond doubt.

Why older people are specifically targeted by the bank-employee trick

The perpetrators' calculation

The so-called doorstep collection fraud is aimed almost exclusively at older people, and that is no coincidence but a calculated approach by the perpetrators. Several factors play into this. Statistically, older people are more often reachable at home alone and more likely to answer unknown calls than younger working people who are at the office during the day. In addition, the authority of bank employees and official institutions is, for many older people, historically more deeply anchored. Perpetrators deliberately exploit the respectful way older people treat a supposed authority figure on the phone by building pressure and leaving little time to think.

On top of that, many older people are less familiar with digital security warnings than with personal, direct contact: a phone call and a personal visit at the front door often seem more credible and legitimate to them than an email, where they have learned to be suspicious. The perpetrators exploit exactly this basis of trust to make their story sound plausible: a faulty card, a suspicious debit, an urgent card exchange. It all sounds like a helpful service, but it is in fact a carefully rehearsed fraud scheme.

What you should do right now

Regardless of whether you receive a suspicious email, an unknown QR code, or an unusual phone call, there are clear, simple rules that protect you against both forms of fraud.

  • Never disclose your PIN — not by phone, not in person, not in writing. No bank, no savings bank, and no genuine bank employee will ever ask for your PIN.
  • Do not scan QR codes from unknown sources — whether from emails, notes, stickers, or letters whose sender you cannot verify beyond doubt.
  • Your bank will never call to arrange a card collection at your front door. No institution in Germany sends a courier to personally collect your debit card. Anyone claiming otherwise is a fraudster.
  • Use only official contact channels: if you have any doubts about an email or a call, hang up and call the service number printed on your bank card or bank statement yourself, never a number provided in the suspicious message.
  • Block your card immediately if in doubt: the central blocking hotline 116 116 works free of charge from German landlines and mobile networks and blocks cards around the clock, regardless of your bank.
  • Actively inform older relatives: talk to parents or grandparents specifically about the bank-employee trick. A single clarifying conversation can prevent someone from handing over their own card out of respect or politeness.

Trust is the real target of the fraudsters

Both quishing and the bank-employee trick only work because perpetrators deliberately abuse trust in banks and official communication channels. This is precisely why it is worth knowing, as a general rule, how your own bank actually communicates: which numbers are officially registered, through which channels your institution normally gets in touch, and what would simply never happen. If you are considering reviewing or switching your current account anyway, also pay attention to transparent, clearly documented security and communication policies of the respective provider. Anyone who keeps larger sums in savings accounts or fixed-term deposits should also find out in advance how the provider reacts in case of fraud and through which channels a block is possible. And if you are currently planning to take out a loan, you should become suspicious the moment a supposed lender asks over the phone for login credentials or a card number, since fraudsters use similar tricks in the lending business too.

Conclusion: vigilance protects more than any technology

  • The current phishing wave targeting Sparkasse, Volksbank and Postbank combines classic phishing emails with the newer quishing method using QR codes.
  • QR codes hide their destination until you actually scan them, which is exactly why they are harder to see through than classic links.
  • The bank-employee trick specifically targets older people because it deliberately exploits trust in authority figures and personal contact.
  • Never hand over your PIN, never scan unknown QR codes, never accept a card collection at your front door — these three rules prevent the vast majority of losses.
  • When in doubt: hang up, call back yourself, and use official numbers. Your bank will always understand an extra security check.

Stay vigilant, talk to family members about these fraud schemes, and trust your gut feeling when in doubt. If you are already thinking about your banking relationship, use our current comparison of current accounts in Germany to find a provider with transparent security standards.

Ready to find the best offer?
Compare current bank offers and find the best one for you.
See the ranking →
LH
Lukas Hoffmann
Financial Specialist