The fake QR code Pix scam: anatomy of the diversion
How tampered QR codes redirect legitimate payments to mule accounts.
Audience: Companies and Operations · Risk level: CRITICAL
Blindfy Intelligence Unit · Technical review by Blindfy
Scenario
A retail store discovers that several customers paid for their purchases, but the money never arrived. The checkout QR code had been covered with a sticker bearing the QR code of a mule account.
How the scam works
Attackers print stickers with QR codes linked to Pix keys of accounts opened with leaked documents and place them over the original QR code in busy stores.
Common mistake
Using printed static QR codes without daily visual validation by checkout staff.
Impact
Direct loss of the sale amount, customers distrusting the store and a Procon complaint.
What works
Dynamic per-transaction QR codes, visual validation at checkout and monitoring of Pix keys associated with the brand.
Protection checklist
- Migrate to dynamic per-transaction QR codes
- Visually validate the QR code every shift
- Train staff to spot tampering
- Confirm receipt before releasing the product
- Monitor Pix keys using the company name
- Notify the Central Bank about mule accounts
- Communicate transparently with affected customers
Editorial sources
- Banco Central do Brasil — Orientações oficiais sobre golpes e Pix
- CERT.br / NIC.br — Cartilha de Segurança para Internet
- ENCCLA / Ministério da Justiça — Enfrentamento a golpes digitais
Pix is only as secure as your checkout protocol. Update the operation.