The Radar

QR code scams: the sticker attack

A parking pay station screen reading “insert ticket”, with the rate card beside it
Photo: miamibrickell · Flickr · CC0
pasted over the real one
one code pasted over anotherScannable — it opens this page

A couple in Whitley Bay scanned the code on a pay-and-display machine and lost £370 in charges that arrived the next morning. The code was a sticker. Councils across Britain are now issuing the same warning, and the interesting part for anyone who prints codes is where the defence actually sits.

What is a QR code scam?

A QR code scam, or quishing, replaces a legitimate printed code with one that leads to a fake payment page. The commonest form is a weather-proof sticker pasted over the real code on a parking meter, an EV charger or a table card. Nothing about the sticker looks wrong, because a QR code is unreadable to a human — that is the entire vulnerability.

The Whitley Bay case is the one that carried the story: a couple scanned the code on a machine at the Spanish City plaza, landed on a page carrying the branding of the parking firm RingGo down to the privacy policy in the footer, were told the transaction had declined, paid at the machine in cash instead, and then found five separate charges between £20 and £150 the following morning. RingGo has confirmed it does not put QR codes on its signs at all — so the presence of the code was itself the tell, and there was no way for a driver to know that.

It is not one incident. Councils have published near-identical warnings inKensington and Chelsea,York,Sunderland,Hartlepool,Cheshire West and Chester andSouth Lanarkshire. When six local authorities independently write the same press release, the pattern is established rather than emerging.

This is a physical attack, and that changes who has to fix it

Nothing is compromised in software. The attacker does not need your website, your domain or your QR provider — they need a printer and thirty seconds standing next to your sign. Which means no setting in a QR generator prevents it, and the countermeasures that work are the ones that belong to whoever owns the physical surface.

Most coverage of this story ends with advice for the person scanning: check the URL, look for a sticker. That advice is correct and it will not scale, because it asks a stranger in a car park in the rain to perform a security check on your behalf. The party who can actually change the outcome is the organisation that printed the code.

What actually helps, in order of how much

  1. Print the code as part of the panel, not as a label. A code screen-printed or engraved into the same surface as the surrounding artwork cannot be covered without the overlay being visible. A code on a laminated sticker invites another sticker on top of it.
  2. Put the destination in words next to the code. “Pays atparking.example.gov.uk” gives the scanner something to compare against the domain that appears in the banner. This single line does more than any amount of consumer education.
  3. Use a domain a customer already associates with you. An unfamiliar domain in the banner is indistinguishable from an attacker's unfamiliar domain.
  4. Inspect them on a schedule. Whoever empties the bins can check whether the code has grown a second layer. Councils that found these stickers found them because somebody looked.
  5. Say where you do not use codes. RingGo's statement — that its signs carry no QR codes — is the most useful sentence in the entire story, and it only works because they published it.

The part a link shortener is not supposed to admit

A short link hides the destination. That is its function, and in this specific context it is a genuine cost: klipqr.com/7hK2mQx in a notification banner tells a scanner nothing about where they are going, exactly when we have just argued that reading the domain is the best defence a scanner has.

We would rather write that down than let someone else point it out. Three things are true alongside it, and they are the reason we still think dynamic codes are the right choice for printed material.

The attacker does not need your shortener. Every case above involved a domain the attacker controlled, chosen to resemble the brand. Removing shorteners from the world removes nothing from this attack.

A link you control can be switched off; ink cannot. If a destination is compromised — your own site defaced, a campaign page hijacked — a dynamic code is re-pointed centrally and every printed copy follows within about thirty seconds. A static code encoding the address directly has no such lever: the only remedy is recalling the physical objects. We also screen destination URLs when a link is created, which a code printed straight from a design tool never is.

The branded domain is the answer to the banner problem, and it is why custom domains matter more here than as a vanity feature. A code that resolves throughpay.yourcouncil.gov.uk gives the scanner the same verification signal as a full URL while keeping the ability to re-point. Ours is on the roadmap and is not shipped yet; we are not going to describe it as though it were.

If you are the one holding the phone

  • Look at the code before you scan it. Raised edges, bubbling, a colour or paper stock that does not match the sign, a sticker at a slight angle. Run a thumb over it.
  • Read the banner, do not tap it. Both iOS and Android show the domain before opening. That half-second is the whole check.
  • Distrust any code that asks for card details on the spot. Legitimate parking, transit and utility payments almost always run through an app or a number printed on the sign as well.
  • If the payment “fails”, stop. A declined transaction on a page you reached by scanning a sticker is a common script — the details have already been captured, and the charges come later.
  • Report the sticker to whoever owns the sign. It is still there otherwise.

Why this matters in a scan-first market

Britain is where the reporting is; the exposure is larger where scanning is the default rather than a novelty. In Kenya a QR code at a counter is routine, and the payment sitting behind it is usually M-PESA. The reassurance there is structural: a genuineM-PESA code carries a merchant identifier, not a web address, and the payment happens inside the M-PESA app against a named till — so a fake sticker cannot quietly become a card-capture form the way it can on a page.

The failure mode shifts rather than disappearing: a sticker can redirect payment to adifferent real merchant. The check is the same one, moved earlier — before entering the PIN, confirm the business name the app displays is the business you are standing in.

Make a code that stays changeable after printing.Create a free account

Questions

What people ask after reading a story like this one.

Not answered here?

A person reads every message, usually the same day.

Email hello@klipqr.com
What is quishing?

Quishing is phishing delivered by QR code. Instead of a link in an email, the attacker gives you a printed pattern, which is unreadable to a human and therefore cannot be inspected before it is followed. The page it opens is an ordinary phishing site; the code is only the delivery mechanism.

How can I tell if a QR code is fake?

Look at the physical code before you scan: a sticker over a printed panel, a raised edge, a bubble, a code whose colour or paper does not match the sign around it. After scanning, read the domain in the notification banner before tapping. If the sign belongs to a company you know, the domain should too.

Should businesses stop using QR codes?

No. Removing codes moves customers to typed URLs, which are mistyped, and to search results, where the same attackers buy ads. The proportionate response is to make your own codes hard to overlay and easy to verify: tamper-evident printing, a domain customers recognise, and someone physically checking them.

Do short links make QR scams worse?

They make the destination harder to inspect, which is a genuine cost and worth saying plainly. What they add back is control: a link you own can be re-pointed or switched off centrally the moment abuse is reported, and it is checked against a blocklist when it is created. A static code pointing at a compromised page can do neither.

What should I do if I scanned a fraudulent code?

If you entered card details, contact your bank immediately and ask for the card to be stopped rather than only disputing the transaction — reported losses have come as several separate charges over the following days, not as one. Then report the sticker to whoever owns the sign, because it is still there for the next person.

© 2026 Klip · Page updated 2026-08-31 · Privacy · Terms