Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
Social Engineering Examples·14 sources
Starting in the week of 28 June 2024, fake QR-code stickers began appearing on parking payment machines in Cheltenham Borough Council car parks; a member of the public reported fraudulent bank activity to police after scanning one. Council officers patrolled and removed the fake codes, but BBC reported the problem persisting with daily patrols still needed as of 15 October 2025. Somerset Council issued a formal public warning on 14 August 2024 after being told fraudulent QR stickers were appearing on its parking machines, telling drivers to use only the official PayByPhone app, website, or phone line.
By March 2025, Swindon Borough Council was investigating similar fake codes in its car parks (notably the Wyvern car park), and by May 2026 scam stickers were found pasted directly onto official PayByPhone signage in Swindon's town centre, including near the Princes Street payment machines, with one sticker observed peeling to reveal it was concealing a genuine app-download symbol underneath.
In May 2025, Avon and Somerset Police confirmed a specific case in Watchet, West Somerset, where a fraudulent QR sticker was placed on top of a genuine PayByPhone code and led to a site that charged victims £50 for parking after collecting their details; Somerset warnings also followed reports in Frome, Glastonbury, Street, Shepton Mallet (2025) and earlier in Bridgwater and Burnham (2024).
This is part of a wider UK-wide phenomenon covered extensively by BBC News, drawing on Action Fraud data showing quishing reports had risen sharply: BBC cited 1,386 reports in 2025 compared with 100 in 2019 (though the exact year the 1,386 figure refers to is applied slightly inconsistently across BBC's own April 2025 and May 2026 articles, both citing Action Fraud), while Action Fraud's own June 2025 press release separately reported 784 quishing reports between April 2024 and April 2025 with nearly £3.5 million lost.
A separate 2024 case documented by BBC involved Castleford, West Yorkshire photographer Milton Haworth, who scanned a QR code at a council car park, downloaded an unauthorized "Finda" app, paid a 90p "verification" fee, and was then charged £39 for a subscription he had not knowingly agreed to (Finda's own email described this as a monthly recurring charge triggered after a 24-hour trial; a later BBC article characterized it as a "£39 yearly fee," an inconsistency in BBC's own coverage), with no refund offered.
Security firm Netcraft separately documented the underlying "IRL quishing" mechanics at parking meters (including in Southampton), tracking roughly 10,000 visits and 2,199 form submissions to phishing sites over summer 2024. In response, PayByPhone stopped issuing QR codes as a payment method to its UK council and parking-operator partners entirely.
Fraudsters physically affixed adhesive QR-code stickers onto legitimate parking payment machines and signage in council-run car parks, frequently placing them directly over or alongside genuine PayByPhone-branded codes/signage (sometimes multiple stickers per meter). Drivers needing to pay for parking scanned the fake code, believing it was the official payment method, and were routed to a fraudulent website impersonating the parking operator.
These sites requested payment/location details and full card information (including security codes); some displayed fake "processing" or "payment accepted" screens, or deliberately showed a fake failure page to prompt victims to enter a second card. In documented cases the scam either directly overcharged the card (e.g., a flat £50 "parking fee" in Watchet, Somerset) or redirected victims to download an unauthorized app that enrolled them in a recurring paid subscription (e.g., a £39 subscription charge, billed monthly per Finda's own terms as quoted to the victim, in Castleford after an initial 90p "verification" fee).
Security researchers (Netcraft) also observed exfiltration of harvested data via Telegram bots, and tracked roughly 10,000 visits to phishing pages with 2,199 confirmed form submissions across two monitored sites during summer 2024.
Lure: an official-looking QR sticker placed on trusted, government-operated parking infrastructure (often directly over or beside a genuine PayByPhone code/branding) at the exact moment a driver urgently needs to pay to avoid a parking fine. Public infrastructure carries an implicit trust that email/SMS phishing lacks, and the "need to pay right now" framing suppresses scrutiny.
Tell: the sticker is often visibly layered on top of the original code, placed at a slight angle, low-quality print, or peeling to reveal an official "download" symbol underneath; the destination URL, once scanned, does not match the operator's real domain; and the site requests unusually complete data (full card number plus security code, or app "verification" fees) that a normal one-tap parking payment would not require.
Cheltenham Borough Council, Somerset Council and Swindon Borough Council all issued public warnings and instituted officer patrols to locate and strip fraudulent stickers from parking machines (Cheltenham described this as an ongoing "daily patrol" as of October 2025). PayByPhone, whose branding was widely spoofed, stopped providing QR codes as a payment method to its UK council and parking-operator partners altogether, directing users instead to its official app or website.
Swindon Borough Council announced plans to install new card-payment-capable machines later in 2026 to reduce reliance on app/QR-only payment. No arrests or named suspects were reported in any of the sources reviewed as of the most recent (21 May 2026) BBC report; police and Action Fraud were treating it as an ongoing, unsolved fraud problem, with the Chartered Trading Standards Institute describing it as significantly under-reported and linked to organized crime hierarchies.
This case shows quishing escaping the inbox: rather than phishing via email or SMS, criminals exploited physical trust in government-run public infrastructure (parking meters, official signage) to plant scan-triggered phishing at the exact moment of a transaction, sidestepping email/SMS spam filters and security awareness training aimed at digital channels.
Because individual losses are often small (£1-£50, or a disguised subscription fee), victims frequently under-report, letting the scheme scale nationally (Action Fraud recorded a multi-fold rise in reports over 2019-2025) while remaining low-priority for police, illustrating how "emerging vector" attacks that blend physical placement with a conventional phishing backend can evade both technical controls and law-enforcement resourcing models built around larger single-incident losses.
Do not scan QR codes in open/unattended public spaces (car parks flagged as higher-risk than restaurants/pubs since codes are easier to tamper with); before scanning, check for physical tampering signs such as a sticker placed at an angle or layered over an existing code; after scanning, preview/verify the destination URL matches the expected official domain before entering any data; prefer paying via the official app (downloaded directly from Apple/Google app stores) or by typing the operator's website address manually, or use contactless payment instead of QR; councils (Cheltenham, Somerset, Swindon) instituted officer patrols to spot and strip fake stickers and published public warnings stating they never use QR codes for payment; PayByPhone discontinued QR codes as a payment method for its UK council/parking-operator partners entirely and states legitimate QR codes are embedded in sticker designs, never placed over them; victims are advised to contact their bank immediately, report to Action Fraud/police (101), and seek support via Victim Support.
Social Engineering Examples. “UK Council Car Park QR Code ("Quishing") Scams - Cheltenham, Swindon & Somerset”. Accessed 19 September 2026. https://socialengineeringexamples.com/uk-council-car-park-qr-quishing-2024-2026
Fraudsters likely scouted council-run car parks and other high-footfall public payment points that rely on QR-code-based digital payment, favoring unattended, low-surveillance sites where a sticker could stay in place for hours or days before removal, consistent with the wide geographic spread documented across Cheltenham, Swindon, Somerset, Aberdeen, Southampton and dozens of other UK councils and hospitals.
Open, unattended public car parks cannot realistically be closed off from physical scouting or access; the practical control is downstream, hardening how QR codes are displayed (tamper-evident holders embedded in signage) and running regular officer patrols to inspect and remove foreign stickers before drivers scan them, which is what Cheltenham, Somerset and Swindon began doing.
Attackers built cloned websites (and in the Castleford case, a fraudulent 'Finda' app) visually mimicking the real parking-payment provider's branding (PayByPhone, RingGo, etc.) and registered look-alike domains; Netcraft's research documented harvested-data exfiltration routed through Telegram bots, and a separate Bureau of Investigative Journalism/European Investigative Collaborations probe traced some UK quishing sites to a Dubai-based network of shell companies with a subscription-billing pipeline run through a 'high-risk' merchant relationship with payment processor Worldline.
Individual councils and drivers have no visibility into or control over attacker-side phishing infrastructure or offshore payment-processing arrangements; this is more effectively addressed further up the chain, by brand-protection and anti-phishing firms like Netcraft monitoring and taking down cloned domains, and by payment companies tightening due diligence on high-risk merchant relationships, as the Bureau of Investigative Journalism's reporting on Worldline recommended.
Low-level operatives, likely near the bottom of an organized-crime hierarchy per the Chartered Trading Standards Institute, printed adhesive QR-code stickers encoding the fraudulent site's address and physically affixed them directly over or beside the genuine PayByPhone-branded code and signage on parking meters and machines, sometimes placing multiple stickers per meter.
PayByPhone's own fix, discontinuing QR codes as a payment method entirely for UK council and parking-operator partners, removes the attack surface an overlay sticker exploits, and embedding legitimate QR codes directly into sticker/signage designs (never placed over them) makes tampering visibly detectable.
A driver needing to pay for parking scanned the sticker, trusting it as the official payment method because it appeared on legitimate, government-operated infrastructure at the exact moment they urgently needed to pay to avoid a fine.
Driver-side behavior change breaks the chain at the point of trust: do not scan QR codes in open, unattended public spaces, and instead pay via the operator's official app downloaded directly from an app store, by typing the operator's website address manually, or by using contactless/card payment at the machine.
The scan routed the victim to the fraudulent website, which requested full card details including the security code and, in some documented cases, showed a fake 'processing' screen or a deliberately-failed payment page to prompt entry of a second card, maximizing the financial data captured in a single visit.
Previewing and verifying the destination URL shown after a scan before entering any data, and treating a request for a full card number plus security code (unusual for a one-tap parking payment) as a red flag, stops the victim from submitting data even after a scan has already happened.
The scheme extracted funds either by directly charging an inflated one-off 'parking fee' to the card (£50 in Watchet) or by enrolling the victim in an unauthorized recurring subscription behind a small upfront 'verification' fee (90p leading to a £39 charge in Castleford), a pattern the Chartered Trading Standards Institute says typically starts with small charges (90p-£2.99) specifically to avoid triggering victim suspicion while still capturing usable card data.
Bank-side transaction monitoring that flags unusual one-off or recurring charges from unfamiliar merchants, combined with victims checking bank statements promptly, catches an inflated charge or hidden subscription before it recurs; victims are also advised to contact their bank immediately to seek a refund and block further charges.
Per Chartered Trading Standards Institute officer Katherine Hart, the captured card and personal data is often reused days or weeks later in a follow-on 'secondary scam,' with fraudsters calling victims while impersonating their bank, police, or Trading Standards and citing the exact date of the original transaction as false proof of legitimacy to extract larger sums, representing the scheme's fullest extraction of value from a single victim.
Reporting to Action Fraud and the police (101) immediately after any suspected QR scam, even for a small loss, is the main lever against this stage, since under-reporting is precisely what lets fraud rings retain and reuse harvested data for a secondary impersonation call; Victim Support and Trading Standards guidance both stress early reporting to flag a compromised card before a follow-on scam succeeds.
Browse by what this case has in common with others in the library.
Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters.
LevelBlue's MDR SOC documented a real client quishing case in which a PDF impersonating a Microsoft MFA-setup notice, hiding a…
Hornetsecurity documented a QR-phishing (quishing) email sent to a single employee at a US-based MSP that spoofed an MFA-reactivation notice…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.
An interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC.
Air Canada admitted in a sworn Ontario Superior Court affidavit that it hired private investigators who twice took trash from…
A Brighton-area kitchen fitter lost roughly £76,000, including four loans he was pressured into taking out.
A Pennsylvania shredding-business owner's 2010 qui tam suit alleged that Shred-It, Iron Mountain.
A retired 60-year-old Malaysian bank manager in Johor Baru lost RM936,000 (life savings) after a Macau-scam vishing syndicate posing successively.
Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank.
A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support.
JLR's five-week production halt and record £1.9bn UK economic hit were first blamed on helpdesk-vishing by a criminal collective calling…
The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019…
Fraudsters posing as RBS fraud-team staff talked Hamilton Academical FC's banking employee into moving nearly £1 million to fake accounts.
Fraudsters spoofed Barclays' real phone number and hold music, posed as the bank's fraud team in a two-caller vishing script.
A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA…
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
A Singaporean finance professional in her 50s lost S$1.2 million.
A trusted, decades-respected Kansas community bank CEO was groomed over WhatsApp into a crypto "pig butchering" scam.
A 16-member Colombian crime ring called and WhatsApp-messaged bank customers posing as fraud-prevention officers.
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.