Skip to content
EntityQ125149693· pop 5

Also known as QR code phishing, QR phishing

REDIRECT Phishing#Quishing

Described at

‘Pay here’: the QR code ‘quishing’ scam targeting drivers | Money | The Guardian

How to avoid costly double whammy as rise in app- and phone-based parking payment opens new frontier in fraud

theguardian.com

UK’s Action Fraud received 1,386 reports of scams involving QR codes – a small number, but more than double that in the previous year. Photograph: Witthaya Prasongsin/Getty Images UK’s Action Fraud received 1,386 reports of scams involving QR codes – a small number, but more than double that in the previous year. Photograph: Witthaya Prasongsin/Getty Images You park the car and look for somewhere to pay. A large QR code on the machine offers to take you directly to the right website where you put in your card details before going on with your day. Only much later are you hit with the double whammy: money gone from your account, and a fine for not paying the genuine parking company. The rise in app- and phone-based parking payment has opened a new frontier for fraudsters: quishing – so called because they are phishing attacks that start with a QR code. The fraudsters stick the codes in places where you would expect to see details of how to pay to park. When you scan one, it takes you to a site where you are asked for your payment details – as you would expect when booking parking. One victim who scanned a code in a station car park told the BBC that the fraudsters tried to take payments then posed as her bank to get more information from her, before running up £13,000 worth of debt in her name. Last year, the UK’s Action Fraud received 1,386 reports of scams involving QR codes – a small number, but more than double that in the previous year. In just the first three months of 2025 there were 502, suggesting the problem is growing. You may later get a call from someone pretending to be from your bank who will use the information you have given and tell you that you have been defrauded and need to move your money to a safe account. The safe account is actually in the control of the scammers. Do not do as they ask – your real bank would never request this. If you have the right parking app already on your phone, use that rather than scanning a code. When you land on a page through a QR code, check details to make sure it is not a fraudulent version. Giveaways include weird URLs and bad spelling. Check that the URL includes HTTPS, rather than HTTP, before handing over details. Keep an eye on your bank account and report any suspicious payments to your bank.

Excerpt from a page describing this subject · 6,168 chars · not written by Vinony

~1 min read

Article

REDIRECT Phishing#Quishing

Available in 5 languages

via Wikidata sitelinks · CC0

Connections