Live data from Hacker News

Organised gangs behind rise in QR 'quishing' scams

bbc.com

31–40 of 49 posts

Re: Organised gangs behind rise in QR 'quishing' scams

#31

The government saw the basic problem in 2019 - a fragmented market with over 30 different parking apps - and funded a pilot to create a single unified parking payment platform. Unfortunately, the new government isn't interested in supporting the project further. https://npp.org.uk/ https://www.theguardian.com/money/2025/feb/22/uk-wide-parkin...

Why do we need an app to pay for parking? I think that's the real question.

Re: Organised gangs behind rise in QR 'quishing' scams

#32

The government saw the basic problem in 2019 - a fragmented market with over 30 different parking apps - and funded a pilot to create a single unified parking payment platform. Unfortunately, the new government isn't interested in supporting the project further. https://npp.org.uk/ https://www.theguardian.com/money/2025/feb/22/uk-wide-parkin...

Why do we need an app to pay for parking? I think that's the real question.

What’s the alternative? Machines to pay are much more expensive than a sign with a QR code.

Re: Organised gangs behind rise in QR 'quishing' scams

#33
post #21

Can we stop making new -ishing words for scams? This weird lingo is part of what turns the less savvy users off from paying much attention to their personal security. Just say a [type of] scam such as "a QR code scam" or "text message scams," etc. We do not need to coin a new term for each one of these things and nobody is winning any prizes for adding more layers of abstraction to fight through when trying to commun…

I am in full agreement. However, it seems to be human nature to make portmanteau words, acronyms, abbreviations and slang. All of my attempts to outlaw these things and impose fines have fallen on deaf ears. I must also confess that I have used these terrible words...

Re: Organised gangs behind rise in QR 'quishing' scams

#34

The government saw the basic problem in 2019 - a fragmented market with over 30 different parking apps - and funded a pilot to create a single unified parking payment platform. Unfortunately, the new government isn't interested in supporting the project further. https://npp.org.uk/ https://www.theguardian.com/money/2025/feb/22/uk-wide-parkin...

Why do we need an app to pay for parking? I think that's the real question.

SOMEBODY needs to create a canonical app, because otherwise that hole will be filled by organized gangs

Re: Organised gangs behind rise in QR 'quishing' scams

#35
post #4

Hey, guys, I have this crazy idea. How about we have people give small bits of paper to other people to pay for things? Or maybe even wave small cards of plastic in front of things that can read them? Maybe how about not using my fucking phone for every goddamn thing ? Crazy, right? KTHXBYE.

The divisibility of cash is fiddly and handling and counting it is not free. Both customers and businesses like switching to card.

The sweet spot is probably around contactless, but eventually more countries will get things like Vipps or WeChat pay and it will become a unified experience.

Re: Organised gangs behind rise in QR 'quishing' scams

#36

Earlier quoted context omitted.

Why do we need an app to pay for parking? I think that's the real question.

What’s the alternative? Machines to pay are much more expensive than a sign with a QR code.

You don't need an app to accept online payments.

There are indeed pay machines, and removing them is only a profit-squeezing play by the operators.

You also never need the QR code. It's only provided as a "convenience". And in fact they usually also provide a way to pay by phone (see illustrative picture in article).

So these are all issues created by bad engineering and operators trying to squeeze as much as they can without consideration for the users.

Re: Organised gangs behind rise in QR 'quishing' scams

#37
post #22

Earlier quoted context omitted.

they could just put a QR code of a different wechat account

Yes, so worst case you paid a little bit of money to the wrong account. This is much worse - usually the QR code leads you to an app that then authenticates with your bank and can transfer and arbitrary amount of money out.

The problem I think is with the bank. They don't give you a way to authorize a single payment or authenticate yourself without just giving away total access to your funds.

It should be like cryptocurrency where there is a separation of the public and private key. Or even better, something like chaumian e-cash. I feel like that would pretty much shut down the majority of financial crime.

Re: Organised gangs behind rise in QR 'quishing' scams

#38

The government saw the basic problem in 2019 - a fragmented market with over 30 different parking apps - and funded a pilot to create a single unified parking payment platform. Unfortunately, the new government isn't interested in supporting the project further. https://npp.org.uk/ https://www.theguardian.com/money/2025/feb/22/uk-wide-parkin...

Why do we need an app to pay for parking? I think that's the real question.

I far prefer using an app for parking - despite the frustration of having to have five or six different apps for this in my phone. I, like a lot of people don't carry small change (or even cash) and the apps offer considerable utility beyond simply paying for the parking - being able to extend your parking slot remotely, for example. It also means that you don't have to hunt around for the parking meter for a particular location - most of the time you can search by the street name, or an ID code, and it will automatically locate you to the correct zone.

It also makes it far easier for parking monitoring - with a description of each vehicle and the registration plate, a traffic warden can easily look at the cars parked in a particular area, discount the ones that have an active parking session, and focus their attention on the vehicles that have exceeded the allowed booking, or have bought a paper ticket from the machine.

It also means that you can do an approximation of real-time capacity in parking areas, without having to go to the expense of installing sensors in parking bays etc.

So lots of advantages, I think, over cash. The obvious downside is when the app doesn't work (I've had this happen on occasion) and for drivers who don't have smart phones (a small number, I think, but still worth considering) or technically less adept users - some of these apps have truly awful UX, which I've struggled with on occasion, so for people who struggle with technology, and particularly perhaps older people, they may be exclusionary. However, in most areas, you can still pay via the machine.

Re: Organised gangs behind rise in QR 'quishing' scams

#39
post #14
post #8

Earlier quoted context omitted.

The same way you might treat a URL randomly written on a billboard. Barring vulnerabilities in your QR reader, it should be enough to just read the URL.

and how do you know the real parking company's URL is 'city-secure-parking.com' and not 'express-city-parking.com'?

I mean in this case I would recommend using a search engine to cross-reference, and any other phishing countermeasures you might normally use.

I think the situation is dire when it comes to non-technical users, but I don't think QR codes are the problems here, someone could equally well paste a sticker over the entire board with all the URLs replaced or with details of a completely different (fake) parking company (but I agree replacing QR codes probably makes it harder for an employee to spot).

Re: Organised gangs behind rise in QR 'quishing' scams

#40
post #21

Can we stop making new -ishing words for scams? This weird lingo is part of what turns the less savvy users off from paying much attention to their personal security. Just say a [type of] scam such as "a QR code scam" or "text message scams," etc. We do not need to coin a new term for each one of these things and nobody is winning any prizes for adding more layers of abstraction to fight through when trying to commun…

It's got to be pure marketing - the British media certainly loves a buzzword, but I suspect that's more to do with their clickbait strategy. ("What is blishing? Have I fallen for it?"). Perhaps it helps some people compartmentalise, but I couldn't find any research that looks into any increased cognitive load.

Our workplace cybersecurity training introduces at least 1 new word each year. This year's was "vishing" which apparently is just social engineering/credential extraction that takes place over the phone. Of course, it's presented to non-technical users as a well-adopted term that is very important to know (for the checkbox quiz in 3 slides time).

Post reply on HN