The very next day, the insidious nature of the fraud became chillingly clear as criminals began systematically siphoning money from his bank account in alarming £60 increments. Howard’s experience is far from isolated; new figures released by Report Fraud indicate a staggering 700% increase in QR code-related scams over the past four years. This exponential rise underscores how criminals are rapidly adapting their tactics, exploiting the widespread adoption of QR codes in daily life to ensnare unsuspecting individuals. These malicious uses range from embedding suspicious links in seemingly innocuous emails to gaining illicit access to victims’ messaging applications, and, as Howard discovered, coercing people into downloading fraudulent apps designed to steal their financial data and personal information.
Describing his fateful visit to Caernarfon, Howard recounted his initial steps. "We went to the car park where we normally go," he told the BBC Scam Secrets podcast. "I normally have change in the car to pay for the parking, but this time I didn’t. So there was a QR code to download and get an app and pay via an app." The convenience of modern technology, promising a seamless transaction, was precisely what made the trap so effective. He observed other motorists in the car park following the same procedure, further legitimising the process in his mind. Yet, an instinctual unease began to surface. "I thought ‘I don’t like the idea of this because I’m going to have to put my card details into an app that I’ve only just downloaded, which wasn’t of my choosing’." This flicker of suspicion, though present, wasn’t enough to entirely halt the process at its initial stages.

Despite his growing apprehension, Howard proceeded far enough into the download and registration process for the criminals to gain a foothold. He eventually stopped, deleted the suspicious application from his phone, and sought alternative parking. However, the damage had already been done. Shortly after deleting the app, he received a notification: £1 had been debited from his account. While a small sum, it was a clear warning sign. The following day, the true scale of the attack became apparent when another notification arrived, this time for a hefty £60, destined for the same unknown recipient. Realising the severity of the situation, Howard immediately contacted his bank. "I told them I’d downloaded it, I tried to stop, but I’d obviously gone too far," he explained. The bank representative’s response was stark: "She said ‘it’s a good job you rang up, because they’ve set up a monthly £60 subscription’." Howard had narrowly avoided a continuous drain on his finances, but the initial losses still stung.
The local authority responsible for car parks in the area, Cyngor Gwynedd, confirmed that it does not utilise QR codes for parking payments. Furthermore, the council revealed that it had removed two fake QR code stickers from its car parks within the last year, underscoring the proactive and deceptive nature of these criminal operations. This tactic of placing fraudulent QR code stickers over legitimate ones, or on meters that don’t even offer QR payments, has been observed in car parks and railway stations across the United Kingdom, indicating a coordinated and widespread criminal network.
Data obtained from the City of London Police through a Freedom of Information Act request paints a concerning picture of the escalating problem of QR code-related scams, a phenomenon now colloquially known as "quishing." The scale of the increase is startling. Report Fraud, the national reporting centre for fraud and cybercrime for England, Wales, and Northern Ireland, reported a massive surge, receiving 2,743 reports mentioning QR codes in the 12 months leading up to August 2023, a dramatic leap from just 341 in the preceding year. Experts believe this figure is likely a significant underestimate, as many victims, perhaps due to embarrassment or simply not knowing where to report, choose not to come forward.

"We’re definitely seeing a rise in the use of QR codes to conduct a range of criminal activity," stated Ollie Whitehouse, the chief technology officer for the National Cyber Security Centre (NCSC). "I think as they become more commonplace, naturally criminals will jump on to the back of that." This opportunistic exploitation is precisely what makes QR codes such an attractive tool for scammers. Their ubiquity in everything from restaurant menus to payment portals creates a fertile ground for deception.
The NCSC highlights various methods criminals employ. This includes tricking individuals into scanning QR codes that surreptitiously link a victim’s messaging application to a criminal’s device, granting them access to private conversations and contacts. Furthermore, even when the QR code itself is genuine, unsuspecting users can still fall prey to scams. The NCSC advises individuals to always use the built-in QR scanner that comes with their smartphone – typically integrated into the camera application – rather than downloading separate, third-party QR scanner apps. This crucial advice stems from the fact that many standalone scanner apps are laden with advertisements, making it difficult for users to discern which links are legitimate and which are malicious. These ad-infested apps can inadvertently direct users to phishing sites or install malware, even if the original QR code was benign.
Another victim, Keith Betton from Farnham in Surrey, experienced this exact scenario. The 66-year-old was attempting to purchase a book about sports cars, advertised in a magazine. He scanned a QR code from the advert using a third-party app he had downloaded. Unbeknownst to him at the time, he was presented with two links: one for the genuine book purchase, and another leading to a fraudulent website that prompted him to enter his payment details. Within moments, he received a request on his banking app to authorise a "zero pounds transaction," which he approved, believing it to be part of the legitimate payment setup. "I don’t hear anything more for a while," Betton recalled. "And then about a month later, my bank contacted me because there was an amount of £59.99 from a company in Prague trying to take that money off my account." It turned out this was the second such charge, with an earlier one having already gone unnoticed. Thankfully, Betton eventually managed to secure a full refund from his bank, but his experience underscores the subtle dangers of seemingly innocuous app downloads and ambiguous transaction requests.

The insidious nature of QR codes extends to email phishing campaigns, a technique Microsoft identified as the fastest-growing scam method targeting email users, with a staggering 18.7 million cases recorded in March of this year alone. Professor Filipo Sharevski of DePaul University in Chicago, who has extensively studied the malicious applications of QR codes, explains why this method is so effective: QR codes allow scam links to "slip through" email filters that would typically flag and block embedded URLs. Furthermore, the black and white squares effectively obscure the true destination of the link. Even if a smartphone attempts to preview the URL before clicking, it is often shortened or disguised, making it virtually impossible for users to verify its legitimacy.
A key factor contributing to the success of these scams is the inherent trust people place in QR codes, according to Prof. Sharevski. His team’s experiments, involving placing QR codes around university campuses and workplaces to gauge scanning willingness, revealed a high level of compliance. "We don’t question our boarding pass on our phone, we don’t question our concert ticket," he noted. This ingrained trust, born from years of using QR codes for legitimate and convenient purposes, makes individuals less likely to scrutinise them. "We learn slowly through scam experiences. Our phone rings… we abandon that. We get an email, and we abandon that… but these QR codes, we have no reason to suspect them."
To protect oneself from these evolving threats, vigilance and caution are paramount. Always verify the source of a QR code; if it’s on a public sign or meter, check for signs of tampering, such as stickers placed over original codes. If a QR code directs you to download an app for payment, pause and consider if this is the official method for that service. Look for official branding, secure website addresses (https://), and avoid apps that request excessive permissions or personal data without clear justification. As the NCSC advises, stick to your phone’s native camera app for scanning, as it often includes built-in security features and avoids the pitfalls of third-party apps. Regularly review your bank and credit card statements for any unauthorised transactions, however small. Should you suspect you’ve fallen victim to a QR code scam, contact your bank immediately and report the incident to Report Fraud or Action Fraud to help authorities track and combat these criminal enterprises. In an increasingly digitised world, where convenience often takes precedence, understanding and mitigating the risks associated with ubiquitous technologies like QR codes is essential for safeguarding personal finances and data.







