Blindfy — Digital Protection

The fake QR code Pix scam: anatomy of the diversion

How tampered QR codes redirect legitimate payments to mule accounts.

Audience: Companies and Operations · Risk level: CRITICAL

Blindfy Intelligence Unit · Technical review by Blindfy

Scenario

A retail store discovers that several customers paid for their purchases, but the money never arrived. The checkout QR code had been covered with a sticker bearing the QR code of a mule account.

How the scam works

Attackers print stickers with QR codes linked to Pix keys of accounts opened with leaked documents and place them over the original QR code in busy stores.

Common mistake

Using printed static QR codes without daily visual validation by checkout staff.

Impact

Direct loss of the sale amount, customers distrusting the store and a Procon complaint.

What works

Dynamic per-transaction QR codes, visual validation at checkout and monitoring of Pix keys associated with the brand.

Protection checklist

  • Migrate to dynamic per-transaction QR codes
  • Visually validate the QR code every shift
  • Train staff to spot tampering
  • Confirm receipt before releasing the product
  • Monitor Pix keys using the company name
  • Notify the Central Bank about mule accounts
  • Communicate transparently with affected customers

Editorial sources

Pix is only as secure as your checkout protocol. Update the operation.

← All risk analyses · Blindfy initial assessment