Get all your news in one place.
100’s of premium titles.
One app.
Start reading
TechRadar
TechRadar
Ellen Jennings-Trace

Mass quishing attacks linked to organized crime gangs across the UK

QR Code scanned via phone.

  • QR code phishing is on the rise, report warns
  • These attacks claimed over 1,300 victims in 2024
  • Cybercriminals are disguising their QR codes as legitimate payment methods

“Quishing”, or QR code phishing is claiming more victims in the UK than ever, with Action Fraud receiving 1,386 reports of incidents last year, a serious increase from 2019 where 100 attacks were recorded.

These are especially prevalent in “contactless payment hotspots” like parking meters and restaurant menus, where criminals will stick their own malicious QR code over an existing legitimate QR code.

Victims of these scams are urged to scan a malicious QR code using their phones, and then redirected to websites controlled by criminals, and are prompted to hand over their financial information by a fake payment page, or malware is deployed to their device.

Caution is key

These attacks are difficult to spot even after the fact, as criminals often take smaller amounts but more frequently, disguising the payments as legitimate-looking subscriptions or parking charges for example - which fly under the radar and aren’t always reported.

“QR codes were designed to make things more convenient but threat actors have taken advantage of this and cleverly made cloned and fake sites that look authentic at the end of a click,” comments Jake Moore, Global Cybersecurity advisor at ESET.

“QR scams can often be difficult to protect against as there is very little that immediately meets the eye to make the user aware of anything fraudulent. It can be difficult to tell these codes apart especially when the link that the QR code generates doesn’t look any different to what you may expect such as a parking payment website.”

As with all social engineering attacks, the key to staying safe is staying vigilant. Only scan QR codes you are 100% certain are safe, and never hand out your payment information to an unverified source.

Via BBC

You might also like

Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.