Insight

Quishing: German armed forces warn of QR code scam at the start of new military service

Fake official letters with manipulated QR codes target young adults in Germany. How quishing works, how to recognize fakes and what to do if you suspect fraud.

With the official launch of the new military service in Germany, the Bundeswehr (German armed forces) is warning of a targeted fraud campaign. Criminals are sending fake official letters containing manipulated QR codes to steal personal data from young adults. Consumer protection groups describe it as a growing quishing campaign.

Key safety rule: Access official websites manually in your browser. Do not blindly scan QR codes from letters.

Digital registration as an attack surface

The new service model starts with the digital registration of people born in 2008. Fraudsters exploit exactly this process with deceptively authentic letters that imitate official layouts, language and symbols — including the federal eagle and a formal administrative tone. The core element is a QR code that supposedly links to the official questionnaire.

What is “quishing”?

Quishing combines QR codes and phishing. After scanning, recipients are not taken to an official Bundeswehr website but to professionally designed fake sites that request sensitive information or prompt users to install malicious software.

Typical targets:

  • bank and credit card details
  • copies of ID documents
  • personal identity data
  • spyware or malware on smartphones, especially Android devices

How to recognize fake letters

The Federal Ministry of Defence highlights clear indicators:

  • Check the sender: legitimate letters come exclusively from the Federal Office for Bundeswehr Personnel Management.
  • Verify the URL: official content is only published under domains such as bundeswehr.de.
  • No sensitive data requests: the Bundeswehr never asks for PINs, online banking credentials or credit card numbers.
  • No fees: any request for payment related to registration is fraudulent.

Why now?

Large public initiatives with new digital processes create ideal conditions for fraud. Similar waves were seen with the energy relief payments and the property tax reform. The new military service is particularly attractive to criminals because it targets a young, digitally active audience with little experience of official correspondence and relies heavily on digital workflows.

What to do if you suspect fraud or data loss

  • Report suspicious letters to the police.
  • If data has already been entered: inform your bank immediately, change passwords, file a report.

What organizations can learn from it

The same trick works in companies: fake invoices, parcel notifications or “IT notices” with a QR code. QR codes often bypass email link scanning because they are scanned on a personal smartphone. Security awareness training should therefore cover quishing explicitly — and offer clear, blame-free reporting paths for suspicious messages.

Conclusion

For many young people, the first security test happens at their mailbox. Vigilance, healthy scepticism and careful verification of senders and URLs are the best protection.

Talk to us

Tell us what you’re working on.

contact@feldmanncyber.com · +49 (0)151 6275 6121