Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset, tricking drivers into paying "parking fees" on cloned sites that harvested full card details or signed them up for hidden subscriptions.
Reviewed by the Social Engineering Examples team.
Starting in the week of 28 June 2024, fake QR-code stickers began appearing on parking payment machines in Cheltenham Borough Council car parks; a member of the public reported fraudulent bank activity to police after scanning one. Council officers patrolled and removed the fake codes, but BBC reported the problem persisting with daily patrols still needed as of 15 October 2025. Somerset Council issued a formal public warning on 14 August 2024 after being told fraudulent QR stickers were appearing on its parking machines, telling drivers to use only the official PayByPhone app, website, or phone line. By March 2025, Swindon Borough Council was investigating similar fake codes in its car parks (notably the Wyvern car park), and by May 2026 scam stickers were found pasted directly onto official PayByPhone signage in Swindon's town centre, including near the Princes Street payment machines, with one sticker observed peeling to reveal it was concealing a genuine app-download symbol underneath. In May 2025, Avon and Somerset Police confirmed a specific case in Watchet, West Somerset, where a fraudulent QR sticker was placed on top of a genuine PayByPhone code and led to a site that charged victims £50 for parking after collecting their details; Somerset warnings also followed reports in Frome, Glastonbury, Street, Shepton Mallet (2025) and earlier in Bridgwater and Burnham (2024). This is part of a wider UK-wide phenomenon covered extensively by BBC News, drawing on Action Fraud data showing quishing reports had risen sharply: BBC cited 1,386 reports in 2025 compared with 100 in 2019 (though the exact year the 1,386 figure refers to is applied slightly inconsistently across BBC's own April 2025 and May 2026 articles, both citing Action Fraud), while Action Fraud's own June 2025 press release separately reported 784 quishing reports between April 2024 and April 2025 with nearly £3.5 million lost. A separate 2024 case documented by BBC involved Castleford, West Yorkshire photographer Milton Haworth, who scanned a QR code at a council car park, downloaded an unauthorized "Finda" app, paid a 90p "verification" fee, and was then charged £39 for a subscription he had not knowingly agreed to (Finda's own email described this as a monthly recurring charge triggered after a 24-hour trial; a later BBC article characterized it as a "£39 yearly fee," an inconsistency in BBC's own coverage), with no refund offered. Security firm Netcraft separately documented the underlying "IRL quishing" mechanics at parking meters (including in Southampton), tracking roughly 10,000 visits and 2,199 form submissions to phishing sites over summer 2024. In response, PayByPhone stopped issuing QR codes as a payment method to its UK council and parking-operator partners entirely.
Fraudsters physically affixed adhesive QR-code stickers onto legitimate parking payment machines and signage in council-run car parks, frequently placing them directly over or alongside genuine PayByPhone-branded codes/signage (sometimes multiple stickers per meter). Drivers needing to pay for parking scanned the fake code, believing it was the official payment method, and were routed to a fraudulent website impersonating the parking operator. These sites requested payment/location details and full card information (including security codes); some displayed fake "processing" or "payment accepted" screens, or deliberately showed a fake failure page to prompt victims to enter a second card. In documented cases the scam either directly overcharged the card (e.g., a flat £50 "parking fee" in Watchet, Somerset) or redirected victims to download an unauthorized app that enrolled them in a recurring paid subscription (e.g., a £39 subscription charge, billed monthly per Finda's own terms as quoted to the victim, in Castleford after an initial 90p "verification" fee). Security researchers (Netcraft) also observed exfiltration of harvested data via Telegram bots, and tracked roughly 10,000 visits to phishing pages with 2,199 confirmed form submissions across two monitored sites during summer 2024.
Lure: an official-looking QR sticker placed on trusted, government-operated parking infrastructure (often directly over or beside a genuine PayByPhone code/branding) at the exact moment a driver urgently needs to pay to avoid a parking fine. Public infrastructure carries an implicit trust that email/SMS phishing lacks, and the "need to pay right now" framing suppresses scrutiny. Tell: the sticker is often visibly layered on top of the original code, placed at a slight angle, low-quality print, or peeling to reveal an official "download" symbol underneath; the destination URL, once scanned, does not match the operator's real domain; and the site requests unusually complete data (full card number plus security code, or app "verification" fees) that a normal one-tap parking payment would not require.
Cheltenham Borough Council, Somerset Council and Swindon Borough Council all issued public warnings and instituted officer patrols to locate and strip fraudulent stickers from parking machines (Cheltenham described this as an ongoing "daily patrol" as of October 2025). PayByPhone, whose branding was widely spoofed, stopped providing QR codes as a payment method to its UK council and parking-operator partners altogether, directing users instead to its official app or website. Swindon Borough Council announced plans to install new card-payment-capable machines later in 2026 to reduce reliance on app/QR-only payment. No arrests or named suspects were reported in any of the sources reviewed as of the most recent (21 May 2026) BBC report; police and Action Fraud were treating it as an ongoing, unsolved fraud problem, with the Chartered Trading Standards Institute describing it as significantly under-reported and linked to organized crime hierarchies.
This case shows quishing escaping the inbox: rather than phishing via email or SMS, criminals exploited physical trust in government-run public infrastructure (parking meters, official signage) to plant scan-triggered phishing at the exact moment of a transaction, sidestepping email/SMS spam filters and security awareness training aimed at digital channels. Because individual losses are often small (£1-£50, or a disguised subscription fee), victims frequently under-report, letting the scheme scale nationally (Action Fraud recorded a multi-fold rise in reports over 2019-2025) while remaining low-priority for police, illustrating how "emerging vector" attacks that blend physical placement with a conventional phishing backend can evade both technical controls and law-enforcement resourcing models built around larger single-incident losses.
Do not scan QR codes in open/unattended public spaces (car parks flagged as higher-risk than restaurants/pubs since codes are easier to tamper with); before scanning, check for physical tampering signs such as a sticker placed at an angle or layered over an existing code; after scanning, preview/verify the destination URL matches the expected official domain before entering any data; prefer paying via the official app (downloaded directly from Apple/Google app stores) or by typing the operator's website address manually, or use contactless payment instead of QR; councils (Cheltenham, Somerset, Swindon) instituted officer patrols to spot and strip fake stickers and published public warnings stating they never use QR codes for payment; PayByPhone discontinued QR codes as a payment method for its UK council/parking-operator partners entirely and states legitimate QR codes are embedded in sticker designs, never placed over them; victims are advised to contact their bank immediately, report to Action Fraud/police (101), and seek support via Victim Support.
Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters, redirecting drivers who scanned…
LevelBlue's MDR SOC documented a real client quishing case in which a PDF impersonating a Microsoft MFA-setup notice, hiding a…
Hornetsecurity documented a QR-phishing (quishing) email sent to a single employee at a US-based MSP that spoofed an MFA-reactivation notice…