AI-Made Fake Cards Turn an Old Mail Scam Into a Growing Fraud Wave
Cheaper AI-assisted card forgery is reviving a mail scam that ships victims a fake replacement bank card, while old magnetic stripe technology keeps fueling a separate wave of US benefit-card fraud.
A letter shows up in the mail with a bank card inside it, your real name printed across the front, and a note warning that your current card is about to expire. A QR code on the letter promises to “activate” the replacement. Scan it, and the link routes straight to a cloned banking site built to harvest your login. The card is fake. The letter is fake. According to WIRED, this scheme has spread across Portugal, France, and Germany in recent years, and it is getting easier to run because generative AI can now copy a bank’s card design from little more than a reference photo.
Table Of Content
It is one half of a story about how the oldest, least glamorous parts of the payment system, paper mail and magnetic stripes, are becoming attractive targets again. The other half is playing out in Alabama, where federal prosecutors say two people installed skimmers on machines that read government benefit cards before being caught in a multistate operation. Neither attack is technically sophisticated. Both are proving durable precisely because the infrastructure underneath them has been slow to change.
A card whose only job is to be trusted
Georg Hauer, founder of the digital-banking advisory firm Hauer Fintech Advisory, first documented the fake-replacement-card scheme in a LinkedIn post after tracking cases in Portugal, where Banking 4.0 reported it first surfaced. He told WIRED the physical card itself does most of the psychological work in the scam. “The card is almost like a token that creates the trust that is needed in order to fall for the actual trick,” he said.
The mechanics are straightforward once you see them laid out. Fraudsters obtain a target’s real name and card-expiration date, information banks tend to treat as far less sensitive than a CVV or PIN, then use it to print a personalized card and a matching letter that mimics the issuing bank’s design. Recipients are told to scan a QR code to register the new card. That flow captures banking-app credentials, and Banking 4.0 reports that criminals follow up with a phone call impersonating customer support to talk victims into reading out an SMS verification code, the final step needed to drain the account.
Why the forgery got cheap enough to scale
Hauer put a number on why this particular scam is spreading now rather than staying a one-off curiosity. “The cost of producing a personalized fake card has dropped in recent years thanks to AI just being able to copy a design based on an image, and the higher conversion rate per victim might justify the extra costs,” he told WIRED. Banking 4.0’s reporting puts the production cost of a single personalized card at roughly 5 to 7 euros, cheap enough that targeting specific individuals, rather than blasting out generic mail fraud, pencils out. Hauer’s own framing of the economics is blunt: the goal usually is not to skim a couple thousand euros from a checking account but to get a victim to hand over access to a much larger savings balance.
“This has been escalating for close to two years, and I believe that this type of scam might have proven to be successful enough to be rolled out in other countries,” Hauer said. It is a familiar pattern in fraud: a technique proves itself in one market, then the tooling that made it profitable there travels.
The same weak point, minus the mail, on America’s benefit cards
A parallel case moving through federal court in Alabama shows the same dynamic without any AI involved at all. Prosecutors in the Northern District of Alabama indicted Cosmin Vaduva, 37, and Elena Andree Caldarareasa, 33, on charges of conspiracy to commit access device fraud and possession of device-making equipment, after accusing the pair of installing skimming devices at three Jefferson County businesses on February 24 and 25, 2026. The devices were built specifically to capture data from Electronic Benefit Transfer, or EBT, cards, the magnetic-stripe-only cards that distribute SNAP food-assistance benefits in most states.
The two were arrested on March 12 after a Grenada County, Mississippi sheriff’s deputy pulled over their car on Interstate 55 following an automated license-plate-reader alert. Investigators reportedly recovered skimming devices, about 15 counterfeit cards, more than $10,000 in cash, and card-building tools hidden in the vehicle’s center console. Alabama’s Department of Human Resources says the state alone logged nearly 40,000 stolen SNAP benefit claims between 2023 and 2025, totaling more than $16.5 million in losses, a figure separate from the roughly $1 billion a year U.S. Attorney Phillip W. Williams Jr. says all forms of card skimming cost victims nationwide. “It is a silent insidious theft that occurs by merely swiping a credit card at a point of sale,” Williams said.
EBT cards are an attractive target for exactly the reason the fake-replacement-card scam is attractive in Europe: the underlying technology has not caught up to the threat. Gary Warner, director of threat intelligence at the cybersecurity firm DarkTower, points out that dozens of states still issue EBT cards with only a magnetic stripe and no EMV chip fallback. “The risk here is that if the mag stripe is compromised, a clone of the card can be created and access not only the current value, but future value as well,” he said. Chip-enabled cards are not fully immune either, since a compromised terminal can be built to force a stripe read even when a chip is present, and Warner notes that “non-bank ATMs and smaller non-chain merchants may expose your chip-enabled card to mag stripe reading.”
A fix that is still years away
Card networks have known the magnetic stripe is a liability for a long time, and they are retiring it, just slowly. Mastercard’s stated plan is to stop issuing any new cards with a magnetic stripe starting in 2029, with the transition beginning in the U.S. in 2027, and to have stripes out of circulation entirely by 2033, apart from an exemption carved out for prepaid cards in the U.S. and Canada. For a technology that has been a known fraud vector for decades, a six-year runway from the transition’s US start date to full retirement is a reminder of how long legacy payment infrastructure stays in the field once it is issued to tens of millions of people.
That gap between “known weakness” and “retired weakness” is the throughline connecting both cases. Nothing about a magnetic stripe or a paper letter is new. What changed is the cost side of the equation: AI-assisted design tools make it cheaper to counterfeit a specific bank’s card convincingly, the same way sxz.io reported in September that attackers borrowed an AI prompt-injection trick to slip financial-lure phishing past keyword filters at a peak of 2.37 million emails a day. Neither trend required a novel exploit. Both required only that fraud get a little cheaper to run at scale, while the target infrastructure stayed exactly as it was.
What actually helps
WIRED’s practical advice tracks with what Warner and Hauer describe as the two real chokepoints in these schemes. For card-present fraud, avoid swiping a card at a terminal when a chip or tap option is available, and when a swipe is unavoidable, as it often is with EBT cards, check the terminal for anything that looks tampered with or loosely attached before using it. For the mail-based scheme, the chokepoint is the QR code: a legitimate card replacement never requires scanning a code from an unsolicited letter to “activate” it, and any card-activation flow that asks for a one-time SMS code over the phone from someone claiming to be a bank employee should be treated as the fraud attempt it almost certainly is.








No Comment! Be the first one.