The Guardia Civil has issued an alert over a parcel scam targeting residents across Spain.
The force urged members of the public to think twice before scanning QR codes found inside unexpected deliveries.
The fraud begins when a package addressed to the recipient arrives at their home, even though they have not ordered anything.
Inside is a QR code accompanied by instructions to scan it in order to ‘check the order’ or ‘arrange a return’.
However, the code could direct the recipient to a fraudulent website designed to obtain sensitive information, including their contact details, passwords or banking data.
‘Just because the parcel is real does not mean the story inside it is too,’ the Guardia Civil warned in a message published on its official social-media account.
The force advised anyone receiving an unexpected delivery not to act hastily or scan the code automatically.
Recipients should first check their genuine online purchases and subscriptions to establish whether the parcel could be connected to a legitimate order.
They should also examine the package carefully to identify the sender and determine whether the company or individual listed actually exists.
Most importantly, the Guardia Civil warned people never to enter personal or financial information through suspicious links opened using a QR code.
People who receive a package they do not recognise should contact the retailer or delivery company using independently verified details from its official website, not the telephone number, email address or link provided inside the parcel.
Anyone who has already scanned a suspicious code should avoid entering further information and close the website immediately.
If banking details have been submitted, the affected person should contact their bank as soon as possible so that transactions can be monitored and cards or accounts secured where necessary.
Passwords entered through the suspicious website should also be changed immediately, particularly when the same login details have been used for other accounts.
Evidence including the packaging, QR code, website address and any messages should be retained in case the incident needs to be reported to the Guardia Civil, Policia Nacional or Spain’s National Cybersecurity Institute.
The scam is a physical variation of ‘quishing’, a form of phishing that uses QR codes rather than conventional clickable links to direct victims towards fraudulent websites.
Because QR codes conceal their destination until they are scanned, it can be difficult for users to judge whether the site behind them is legitimate.
