Case Library / Quishing (QR Code Phishing) / UK Council Car Park QR Code ("Quishing") Scams - Cheltenham, Swindon & Somerset

UK Council Car Park QR Code ("Quishing") Scams - Cheltenham, Swindon & Somerset

Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset, tricking drivers into paying "parking fees" on cloned sites that harvested full card details or signed them up for hidden subscriptions.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Starting in the week of 28 June 2024, fake QR-code stickers began appearing on parking payment machines in Cheltenham Borough Council car parks; a member of the public reported fraudulent bank activity to police after scanning one. Council officers patrolled and removed the fake codes, but BBC reported the problem persisting with daily patrols still needed as of 15 October 2025. Somerset Council issued a formal public warning on 14 August 2024 after being told fraudulent QR stickers were appearing on its parking machines, telling drivers to use only the official PayByPhone app, website, or phone line. By March 2025, Swindon Borough Council was investigating similar fake codes in its car parks (notably the Wyvern car park), and by May 2026 scam stickers were found pasted directly onto official PayByPhone signage in Swindon's town centre, including near the Princes Street payment machines, with one sticker observed peeling to reveal it was concealing a genuine app-download symbol underneath. In May 2025, Avon and Somerset Police confirmed a specific case in Watchet, West Somerset, where a fraudulent QR sticker was placed on top of a genuine PayByPhone code and led to a site that charged victims £50 for parking after collecting their details; Somerset warnings also followed reports in Frome, Glastonbury, Street, Shepton Mallet (2025) and earlier in Bridgwater and Burnham (2024). This is part of a wider UK-wide phenomenon covered extensively by BBC News, drawing on Action Fraud data showing quishing reports had risen sharply: BBC cited 1,386 reports in 2025 compared with 100 in 2019 (though the exact year the 1,386 figure refers to is applied slightly inconsistently across BBC's own April 2025 and May 2026 articles, both citing Action Fraud), while Action Fraud's own June 2025 press release separately reported 784 quishing reports between April 2024 and April 2025 with nearly £3.5 million lost. A separate 2024 case documented by BBC involved Castleford, West Yorkshire photographer Milton Haworth, who scanned a QR code at a council car park, downloaded an unauthorized "Finda" app, paid a 90p "verification" fee, and was then charged £39 for a subscription he had not knowingly agreed to (Finda's own email described this as a monthly recurring charge triggered after a 24-hour trial; a later BBC article characterized it as a "£39 yearly fee," an inconsistency in BBC's own coverage), with no refund offered. Security firm Netcraft separately documented the underlying "IRL quishing" mechanics at parking meters (including in Southampton), tracking roughly 10,000 visits and 2,199 form submissions to phishing sites over summer 2024. In response, PayByPhone stopped issuing QR codes as a payment method to its UK council and parking-operator partners entirely.

How the Attack Worked

Fraudsters physically affixed adhesive QR-code stickers onto legitimate parking payment machines and signage in council-run car parks, frequently placing them directly over or alongside genuine PayByPhone-branded codes/signage (sometimes multiple stickers per meter). Drivers needing to pay for parking scanned the fake code, believing it was the official payment method, and were routed to a fraudulent website impersonating the parking operator. These sites requested payment/location details and full card information (including security codes); some displayed fake "processing" or "payment accepted" screens, or deliberately showed a fake failure page to prompt victims to enter a second card. In documented cases the scam either directly overcharged the card (e.g., a flat £50 "parking fee" in Watchet, Somerset) or redirected victims to download an unauthorized app that enrolled them in a recurring paid subscription (e.g., a £39 subscription charge, billed monthly per Finda's own terms as quoted to the victim, in Castleford after an initial 90p "verification" fee). Security researchers (Netcraft) also observed exfiltration of harvested data via Telegram bots, and tracked roughly 10,000 visits to phishing pages with 2,199 confirmed form submissions across two monitored sites during summer 2024.

The Lure & the Tell

Lure: an official-looking QR sticker placed on trusted, government-operated parking infrastructure (often directly over or beside a genuine PayByPhone code/branding) at the exact moment a driver urgently needs to pay to avoid a parking fine. Public infrastructure carries an implicit trust that email/SMS phishing lacks, and the "need to pay right now" framing suppresses scrutiny. Tell: the sticker is often visibly layered on top of the original code, placed at a slight angle, low-quality print, or peeling to reveal an official "download" symbol underneath; the destination URL, once scanned, does not match the operator's real domain; and the site requests unusually complete data (full card number plus security code, or app "verification" fees) that a normal one-tap parking payment would not require.

Outcome

Cheltenham Borough Council, Somerset Council and Swindon Borough Council all issued public warnings and instituted officer patrols to locate and strip fraudulent stickers from parking machines (Cheltenham described this as an ongoing "daily patrol" as of October 2025). PayByPhone, whose branding was widely spoofed, stopped providing QR codes as a payment method to its UK council and parking-operator partners altogether, directing users instead to its official app or website. Swindon Borough Council announced plans to install new card-payment-capable machines later in 2026 to reduce reliance on app/QR-only payment. No arrests or named suspects were reported in any of the sources reviewed as of the most recent (21 May 2026) BBC report; police and Action Fraud were treating it as an ongoing, unsolved fraud problem, with the Chartered Trading Standards Institute describing it as significantly under-reported and linked to organized crime hierarchies.

Why It Matters

This case shows quishing escaping the inbox: rather than phishing via email or SMS, criminals exploited physical trust in government-run public infrastructure (parking meters, official signage) to plant scan-triggered phishing at the exact moment of a transaction, sidestepping email/SMS spam filters and security awareness training aimed at digital channels. Because individual losses are often small (£1-£50, or a disguised subscription fee), victims frequently under-report, letting the scheme scale nationally (Action Fraud recorded a multi-fold rise in reports over 2019-2025) while remaining low-priority for police, illustrating how "emerging vector" attacks that blend physical placement with a conventional phishing backend can evade both technical controls and law-enforcement resourcing models built around larger single-incident losses.

Defenses

Do not scan QR codes in open/unattended public spaces (car parks flagged as higher-risk than restaurants/pubs since codes are easier to tamper with); before scanning, check for physical tampering signs such as a sticker placed at an angle or layered over an existing code; after scanning, preview/verify the destination URL matches the expected official domain before entering any data; prefer paying via the official app (downloaded directly from Apple/Google app stores) or by typing the operator's website address manually, or use contactless payment instead of QR; councils (Cheltenham, Somerset, Swindon) instituted officer patrols to spot and strip fake stickers and published public warnings stating they never use QR codes for payment; PayByPhone discontinued QR codes as a payment method for its UK council/parking-operator partners entirely and states legitimate QR codes are embedded in sticker designs, never placed over them; victims are advised to contact their bank immediately, report to Action Fraud/police (101), and seek support via Victim Support.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and site selection: Fraudsters likely scouted council-run car parks and other high-footfall public payment points that rely on QR-code-based digital payment, favoring unattended, low-surveillance sites where a sticker could stay in place for hours or days before removal, consistent with the wide geographic spread documented across Cheltenham, Swindon, Somerset, Aberdeen, Southampton and dozens of other UK councils and hospitals.
Countering Stage 1: Open, unattended public car parks cannot realistically be closed off from physical scouting or access; the practical control is downstream, hardening how QR codes are displayed (tamper-evident holders embedded in signage) and running regular officer patrols to inspect and remove foreign stickers before drivers scan them, which is what Cheltenham, Somerset and Swindon began doing.
2
Phishing infrastructure and brand cloning: Attackers built cloned websites (and in the Castleford case, a fraudulent 'Finda' app) visually mimicking the real parking-payment provider's branding (PayByPhone, RingGo, etc.) and registered look-alike domains; Netcraft's research documented harvested-data exfiltration routed through Telegram bots, and a separate Bureau of Investigative Journalism/European Investigative Collaborations probe traced some UK quishing sites to a Dubai-based network of shell companies with a subscription-billing pipeline run through a 'high-risk' merchant relationship with payment processor Worldline.
Countering Stage 2: Individual councils and drivers have no visibility into or control over attacker-side phishing infrastructure or offshore payment-processing arrangements; this is more effectively addressed further up the chain, by brand-protection and anti-phishing firms like Netcraft monitoring and taking down cloned domains, and by payment companies tightening due diligence on high-risk merchant relationships, as the Bureau of Investigative Journalism's reporting on Worldline recommended.
3
Sticker production and physical placement: Low-level operatives, likely near the bottom of an organized-crime hierarchy per the Chartered Trading Standards Institute, printed adhesive QR-code stickers encoding the fraudulent site's address and physically affixed them directly over or beside the genuine PayByPhone-branded code and signage on parking meters and machines, sometimes placing multiple stickers per meter.
Countering Stage 3: PayByPhone's own fix, discontinuing QR codes as a payment method entirely for UK council and parking-operator partners, removes the attack surface an overlay sticker exploits, and embedding legitimate QR codes directly into sticker/signage designs (never placed over them) makes tampering visibly detectable.
4
Victim scan at point of need: A driver needing to pay for parking scanned the sticker, trusting it as the official payment method because it appeared on legitimate, government-operated infrastructure at the exact moment they urgently needed to pay to avoid a fine.
Countering Stage 4: Driver-side behavior change breaks the chain at the point of trust: do not scan QR codes in open, unattended public spaces, and instead pay via the operator's official app downloaded directly from an app store, by typing the operator's website address manually, or by using contactless/card payment at the machine.
5
Data harvesting on the cloned payment page: The scan routed the victim to the fraudulent website, which requested full card details including the security code and, in some documented cases, showed a fake 'processing' screen or a deliberately-failed payment page to prompt entry of a second card, maximizing the financial data captured in a single visit.
Countering Stage 5: Previewing and verifying the destination URL shown after a scan before entering any data, and treating a request for a full card number plus security code (unusual for a one-tap parking payment) as a red flag, stops the victim from submitting data even after a scan has already happened.
6
Monetization via direct overcharge or hidden subscription: The scheme extracted funds either by directly charging an inflated one-off 'parking fee' to the card (£50 in Watchet) or by enrolling the victim in an unauthorized recurring subscription behind a small upfront 'verification' fee (90p leading to a £39 charge in Castleford), a pattern the Chartered Trading Standards Institute says typically starts with small charges (90p-£2.99) specifically to avoid triggering victim suspicion while still capturing usable card data.
Countering Stage 6: Bank-side transaction monitoring that flags unusual one-off or recurring charges from unfamiliar merchants, combined with victims checking bank statements promptly, catches an inflated charge or hidden subscription before it recurs; victims are also advised to contact their bank immediately to seek a refund and block further charges.
7
Secondary-scam exploitation using harvested data: Per Chartered Trading Standards Institute officer Katherine Hart, the captured card and personal data is often reused days or weeks later in a follow-on 'secondary scam,' with fraudsters calling victims while impersonating their bank, police, or Trading Standards and citing the exact date of the original transaction as false proof of legitimacy to extract larger sums, representing the scheme's fullest extraction of value from a single victim.
Countering Stage 7: Reporting to Action Fraud and the police (101) immediately after any suspected QR scam, even for a small loss, is the main lever against this stage, since under-reporting is precisely what lets fraud rings retain and reuse harvested data for a secondary impersonation call; Victim Support and Trading Standards guidance both stress early reporting to flag a compromised card before a follow-on scam succeeds.
Quick Facts
Victim
Multiple UK local councils and their car park users: Cheltenham Borough Council, Swindon Borough Council, Somerset Council, plus other councils nationwide (Castleford/Wakefield area, Southampton, Aberdeen); PayByPhone (the parking-payment provider whose branding was spoofed) and individual motorists who scanned fake codes
Location
England (nationwide, multiple councils): Cheltenham (Gloucestershire), Swindon (Wiltshire) including the Wyvern car park and Princes Street machines, Somerset towns including Watchet, Frome, Glastonbury, Street, Shepton Mallet, Bridgwater and Burnham; also reported in Castleford (West Yorkshire), Southampton, and Aberdeen (Scotland)
Date
First confirmed sighting: week of 28 June 2024 (Cheltenham); Somerset Council warning 14 Aug 2024; Swindon investigation reported 10 Mar 2025; Watchet, Somerset incident reported May 2025; scam recurring/ongoing through BBC reports of 15 Oct 2025 and 21 May 2026. National Action Fraud figures cited span 2019-2025.
Impact
No single confirmed total for the Cheltenham/Swindon/Somerset incidents specifically. National context (Action Fraud): 784 quishing reports between April 2024-April 2025 with nearly £3.5 million lost (Action Fraud press release, corroborated by BBC Shared Data Unit reporting and The Independent, 10 Sep 2025); separately, BBC reported Action Fraud figures of 1,386 quishing reports in "2025" versus 100 in 2019 (a figure BBC's own April 2025 and May 2026 articles apply slightly inconsistently to the exact year, so treat the year-attribution as approximate rather than precisely dated). Action Fraud also noted total reports more than doubled between 2023 and 2024, with roughly 3,000 reports total over five years and a fifth tied to the Metropolitan Police area. Documented individual losses: a Watchet, Somerset victim was charged £50 for parking via a fraudulent site sitting atop a genuine PayByPhone code; a Castleford, West Yorkshire victim (Milton Haworth) was tricked into an unauthorized 90p "verification" fee that enrolled him in a £39 subscription charge with no refund. BBC's original 30 Oct 2024 report quotes Finda's own email to Haworth stating a monthly fee would be automatically taken if the subscription was not cancelled, indicating a recurring monthly charge (a later BBC article, 11 Apr 2025, describes it instead as a "£39 yearly fee," an inconsistency across BBC's own reporting; the primary Oct 2024 account is treated as authoritative here). Chartered Trading Standards Institute officer Katherine Hart said the broader quishing pattern often starts with small charges (90p-£2.99) used to harvest card data for follow-on "secondary scams" (bogus bank/police impersonation calls), and that "we've seen huge amounts lost this way... people have seen their life savings gone."
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Government & Public Sector, Transportation & Logistics
Threat Actor
Organized Crime
Related

Related Cases

Orlando Downtown ParkMobile QR Parking Meter Sticker Scam (2025)

Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters, redirecting drivers who scanned…

Incident 2025Read →

LevelBlue MTDR SOC "Quishing" Case Study - Fake Microsoft MFA-Setup QR Code Harvests Employee Credentials (2023)

LevelBlue's MDR SOC documented a real client quishing case in which a PDF impersonating a Microsoft MFA-setup notice, hiding a…

Incident 2023Read →

Hornetsecurity QRishing Attack on US-Based MSP (2023)

Hornetsecurity documented a QR-phishing (quishing) email sent to a single employee at a US-based MSP that spoofed an MFA-reactivation notice…

Incident 2023Read →