UK Fraud Reports Surge Sevenfold as Criminals Exploit QR Codes in Parking Meters and Phishing Emails
National cybersecurity officials warn consumers against third-party scanner apps as 'quishing' schemes harvest bank details through fake payment stickers and disguised web links.
Reports of fraudulent Quick Response code scams across England, Wales, and Northern Ireland have increased by more than seven hundred percent over the past four years, prompting cybersecurity authorities to issue nationwide warnings about the escalating threat.
Known as quishing, the criminal practice involves placing malicious QR code stickers over legitimate signage in public places, such as parking meters and railway stations, or embedding disguised links inside unsolicited phishing emails.
Data from the national reporting service Report Fraud indicates that incidents referencing QR codes reached 2,743 over a twelve-month period, up sharply from 341 reports recorded in 2022. Because many victims do not report minor losses, officials consider the figures an underestimate.
Local councils across the United Kingdom, including Cyngor Gwynedd in North Wales, have reported discovering and removing counterfeit QR stickers affixed to physical payment meters.
Victims who scanned the codes were directed to fraudulent payment platforms where their credit card details were captured and used to establish unauthorized recurring monthly subscription charges.
Technical experts warn that the rapid adoption of digital codes has created a dangerous gap in consumer vigilance.
Unlike plain-text web addresses, black-and-white QR patterns cannot be visually evaluated for authenticity before scanning, allowing deceptive links to bypass conventional email spam filters.
In corporate environments, automated filters often struggle to analyze image-based links, enabling malicious emails to reach employee inboxes.
Software analysis recorded 18.7 million malicious QR code instances in corporate messaging in a single month earlier this year.
The National Cyber Security Centre advises the public to avoid downloading standalone third-party QR scanning applications, which frequently contain unvetted advertisements that direct users to deceptive websites.
Instead, consumers are urged to use their smartphone's native camera software to inspect URLs before opening them and to verify payment methods directly through official municipal apps or contactless card terminals.