Tech

Les used a QR code to download a parking app - but it was a scam

Scammers set up a monthly subscription of £60 from Les Howard's account after he downloaded an app.

Les Howard, 61, fell victim to a QR code scam after attempting to pay for parking during a trip to the coast. Unable to find change, he scanned a QR code on the meter to download a parking app. The following day, he discovered criminals were siphoning £60 increments from his bank account.

Reports indicate a 700% surge in QR code-related scams over the past four years, according to figures from Report Fraud. Experts note that as QR codes become more integrated into daily life, criminals are devising new methods to exploit them. This includes embedding suspicious links in emails, gaining access to victims' messaging apps, or prompting individuals to download fraudulent apps to steal money and data.

This is precisely what happened to Howard, from Widnes, while visiting Caernarfon in North Wales with his wife. He recounted his experience on the BBC Scam Secrets podcast: "We went to the car park where we normally go. I normally have change in the car to pay for the parking, but this time I didn't. So there was a QR code to download and get an app and pay via an app."

Howard grew suspicious when he realized he would have to input his card details into an app he had just downloaded, which wasn't "of my choosing." He deleted the app and parked elsewhere. However, he soon received a notification that £1 had been debited from his account. The next day, another £60 was taken by the same recipient, prompting him to contact his bank.

"I told them I'd downloaded it, I tried to stop, but I'd obviously gone too far," Howard explained. The bank representative informed him, "it's a good job you rang up, because they've set up a monthly £60 subscription."

Cyngor Gwynedd, the council responsible for car parks in the area, confirmed it does not use QR codes for parking payments and has removed two fake QR code stickers from its car parks in the past year. Similar tactics have been observed in car parks and railway stations nationwide.

Data from City of London Police, obtained via a Freedom of Information Act request, suggests a rise in "quishing," or QR code-related scams. Report Fraud, which covers England, Wales, and Northern Ireland, reported 2,743 mentions of QR codes in scam reports over the last 12 months, a significant increase from 341 in the year ending August 2022. This figure is likely an underestimate, as many victims do not report.

Ollie Whitehouse, Chief Technology Officer for the National Cyber Security Centre (NCSC), told Scam Secrets, "We're definitely seeing a rise in the use of QR codes to conduct a range of criminal activity. I think as they become more commonplace, naturally criminals will jump on to the back of that."

The BBC Scam Secrets podcast, featuring Shari Vahl, Dr. Lis Carter, and Alex Wood, explored how criminals exploit QR codes, including persuading people to scan codes that link a victim's messaging app to a criminal's device.

Even genuine QR codes can lead to scams. The NCSC advises using a phone's built-in QR scanner (usually the camera) instead of downloading separate apps, as some apps contain ads that can obscure legitimate links.

Keith Betton, 66, from Farnham in Surrey, experienced this firsthand. He scanned a QR code in a magazine advert for a sports car book using a downloaded app. He later realized he was presented with two links: one for the book and another for a website requesting payment details. After agreeing to a zero-pound transaction on his banking app, he heard nothing for a month until his bank contacted him about a £59.99 charge from a company in Prague. This was the second such charge, and Betton eventually secured a refund.

The NCSC also noted the increasing use of QR codes in phishing emails to mask malicious links. Microsoft reported 18.7 million such cases in March of this year, making it the fastest-growing email scam technique. Professor Filipo Sharevski of DePaul University in Chicago, who studies malicious QR code use, explained that QR codes allow scam links to bypass email filters that might flag embedded URLs as spam. The black and white squares also make it harder for users to discern the true destination of a link, as previews are often shortened or disguised.

Professor Sharevski added that people tend to inherently trust QR codes. His team's experiments placing QR codes on university campuses and in workplaces revealed a high willingness to scan them. "We don't question our boarding pass on our phone, we don't question our concert ticket," he said. "We learn slowly through scam experiences. Our phone rings… we abandon that. We get an email, and we abandon that…but these QR codes, we have no reason to suspect them."

Cookies on xabarchi

We use cookies to remember your language and theme, and to count how many people are reading right now — that count is anonymous, lasts only while your browser is open, and cannot be tied to you or to another visit. With your permission we also measure how the site is read: Microsoft Clarity, which records page views and on-page interactions, and our own count of returning readers. Nothing that recognises you across visits is measured until you accept.