Live data from Hacker News

Organised gangs behind rise in QR 'quishing' scams

bbc.com

21–30 of 49 posts

Re: Organised gangs behind rise in QR 'quishing' scams

#21
Can we stop making new -ishing words for scams? This weird lingo is part of what turns the less savvy users off from paying much attention to their personal security. Just say a [type of] scam such as "a QR code scam" or "text message scams," etc.

We do not need to coin a new term for each one of these things and nobody is winning any prizes for adding more layers of abstraction to fight through when trying to communicate security concepts to the people who really need to listen to it.

Re: Organised gangs behind rise in QR 'quishing' scams

#22

Having lived in China for five years and seeing how it is done there (literally everywhere), I see this as a payment problem. There is no sensible, low cost payment infrastructure to support this safely. Instead most of the west has a fractured app ecosystem where each app ‘does payment’ rather than via a set of trusted payment apps that do the security up front and then passes to the provider. For example, in the ar…

they could just put a QR code of a different wechat account

Re: Organised gangs behind rise in QR 'quishing' scams

#23
post #14
post #8

Earlier quoted context omitted.

The same way you might treat a URL randomly written on a billboard. Barring vulnerabilities in your QR reader, it should be enough to just read the URL.

and how do you know the real parking company's URL is 'city-secure-parking.com' and not 'express-city-parking.com'?

You don't. But the problem is not the QR code. The problem is the same as "URL randomly written on a billboard".

Re: Organised gangs behind rise in QR 'quishing' scams

#24

Having lived in China for five years and seeing how it is done there (literally everywhere), I see this as a payment problem. There is no sensible, low cost payment infrastructure to support this safely. Instead most of the west has a fractured app ecosystem where each app ‘does payment’ rather than via a set of trusted payment apps that do the security up front and then passes to the provider. For example, in the ar…

This is a cost saving play by the car parks operators.

Here in the UK we had car payment stations: You enter your car registration number, you pay by card or contactless. Done. Safe. It works.

BUT, this is more expensive for the operator to install and maintain than just sticking a notice to tell you to install an app and to use it to pay.

That being said, usually the QR code is not required it is just to make it "easier" as the notice explicitely says which app to install and provides the unique reference of the car park, too. You may also be able to pay over the phone rather than using the app. This is all shown on the article's first picture.

So, really they could just remove those scam-prone QR codes. I suspect that they don't care, though, and even profit from those scams since they can fine you for not having actually paid.

Re: Organised gangs behind rise in QR 'quishing' scams

#25
post #23
post #14

Earlier quoted context omitted.

and how do you know the real parking company's URL is 'city-secure-parking.com' and not 'express-city-parking.com'?

You don't. But the problem is not the QR code. The problem is the same as "URL randomly written on a billboard".

I think the term you two look for is "Lack of Authentication". The QR codes are not authenticated to the reader.

Re: Organised gangs behind rise in QR 'quishing' scams

#26
post #22

Having lived in China for five years and seeing how it is done there (literally everywhere), I see this as a payment problem. There is no sensible, low cost payment infrastructure to support this safely. Instead most of the west has a fractured app ecosystem where each app ‘does payment’ rather than via a set of trusted payment apps that do the security up front and then passes to the provider. For example, in the ar…

they could just put a QR code of a different wechat account

Since it's all tied to real IDs, wouldn't that involve heavy risks from the scammer's side? I know it's possible, but still a bit less risk if your Scam HQ operates overseas.

Re: Organised gangs behind rise in QR 'quishing' scams

#27
The government saw the basic problem in 2019 - a fragmented market with over 30 different parking apps - and funded a pilot to create a single unified parking payment platform. Unfortunately, the new government isn't interested in supporting the project further.

https://npp.org.uk/

https://www.theguardian.com/money/2025/feb/22/uk-wide-parkin...

Re: Organised gangs behind rise in QR 'quishing' scams

#28
post #21

Can we stop making new -ishing words for scams? This weird lingo is part of what turns the less savvy users off from paying much attention to their personal security. Just say a [type of] scam such as "a QR code scam" or "text message scams," etc. We do not need to coin a new term for each one of these things and nobody is winning any prizes for adding more layers of abstraction to fight through when trying to commun…

The delineation is useful for broad audiences.

Re: Organised gangs behind rise in QR 'quishing' scams

#29
post #14

Earlier quoted context omitted.

and how do you know the real parking company's URL is 'city-secure-parking.com' and not 'express-city-parking.com'?

Call the city to verify. If enough people do it, they'll find a way to solve the problem (e.g. a subdomain of the official city site, putting back regular parking meters/machines, ...)

A lot of these car parks are privately owned, so the local authority will reasonably respond by saying "nothing to do with us mate".

Re: Organised gangs behind rise in QR 'quishing' scams

#30
post #22

Having lived in China for five years and seeing how it is done there (literally everywhere), I see this as a payment problem. There is no sensible, low cost payment infrastructure to support this safely. Instead most of the west has a fractured app ecosystem where each app ‘does payment’ rather than via a set of trusted payment apps that do the security up front and then passes to the provider. For example, in the ar…

they could just put a QR code of a different wechat account

Yes, so worst case you paid a little bit of money to the wrong account. This is much worse - usually the QR code leads you to an app that then authenticates with your bank and can transfer and arbitrary amount of money out.
Post reply on HN