QR / Quishing

The Malicious Parking QR Code

Attackers place fake QR codes on parking signs, payment notices, or posters to redirect scans to a credential-harvesting page instead of the intended service. This walkthrough is a fictional, illustrative example built for training.

The scenario

An employee parks in a building's visitor area and notices a printed sign taped over the usual parking payment terminal: 'Cashless Parking - Scan to Pay Your Parking Fee.' A QR code sits below the instructions, styled to match the building's usual signage.

Scanning the code opens a mobile browser page that looks like a standard e-wallet or bank payment portal, showing a small parking fee (for example Rp 5,000) to make the request feel routine and low-risk rather than alarming.

The page asks the visitor to log in with their e-wallet or mobile banking credentials to 'complete payment', or in some variants asks for a debit or credit card number, expiry date, and CVV directly on the page.

After submission, the page shows a fake 'Payment Successful' confirmation and may even redirect to the real e-wallet or bank homepage, so the victim drives away without suspecting anything, while the attacker now holds valid login or card details and, in some versions, has quietly registered a recurring or larger charge.

Red flags to spot

QR code sticker placed over or beside official signage

A code that looks slightly misaligned, printed on a separate sticker, or taped over existing signage is often physically added by an attacker rather than issued by the building or vendor.

Payment portal requests full banking login instead of a one-time guest payment method

Legitimate parking or vendor payment pages typically use a simple one-time payment flow (QRIS or card entry through a known payment gateway), not a request to log into your full banking or e-wallet account.

URL after scanning does not match the parking operator or building's known domain

Checking the address bar after scanning is one of the few ways to catch a quishing attempt before entering any information, since the destination domain rarely matches what a legitimate operator would use.

No physical staff, receipt option, or alternative payment method available nearby

Legitimate cashless parking systems usually coexist with a staffed booth, app-based option, or clear operator branding. A QR code as the sole, isolated payment method is a common quishing setup.

Fee amount is unusually small or vague, encouraging quick, unthinking payment

Small amounts are used deliberately to lower the visitor's guard. It feels too trivial to be a scam, which is exactly the psychological effect the attacker is relying on.

The lesson

Before scanning any public QR code, check whether it looks like a sticker placed over existing signage rather than part of the original printed material. After scanning, always check the URL that opens instead of typing in any information immediately. For payments, prefer a known, verified app (opened directly, not through the scanned link) or a manned counter over an unfamiliar web page reached by QR. If a QR-based payment page asks for full account login credentials or a card CVV rather than a simple one-time payment flow, stop and report the code to building security or the parking operator.

These are illustrative examples built for training purposes only, not real messages sent by Claro or any actual organization.

Frequently asked questions

  • The delivery method is a QR code instead of a link in an email or message, which bypasses many spam filters and email security scanning, and also removes the visual cues (like a hoverable link) people use to check a URL before clicking.

Run these patterns as real simulations

Claro turns each of these lures into a localized, trackable phishing simulation your team can learn from safely.

Request a demo