Crime "Quishing" / QR code fraud - "Quishing" = QR + phishing; a man-in-the-middle attack against a parking lot service provider using QR code stickers

  • Want to keep track of this thread?
    Accounts can bookmark posts, watch threads for updates, and jump back to where you stopped reading.
    Create account
Short translations by yours truly. Original source 1 [A], original source 2 [A]

"Quishing"​

No, not the preparing of quiche. Quishing. A classic man-in-the-middle attack due to a lack of authentication, just in pink.

Just like from the textbook of fundamentals of IT security: Wrong Easypark QR codes have surfaced

Apparently there is a "parking service provider" (apparently just a parking spot landlord) that wanted to save money on parking meters and instead placed a sign with the QR code of the website where you pay using your phone. According to the article, what's supposed to happen normally is that you get sent to the app, if you don't have it already, that's used for the payment.

Fraudsters simply glued "Scan & Pay" stickers with their own QR code on top, which redirect to a genuine-looking payment website on which you enter your payment details. "Quishing" = QR + phishing.

As profane as it is, that attack is classic: Sign = unsecured communication. Gluing a sticker on top = man-in-the-middle attack.



Wrong Easypark QR codes have surfaced​

Fraudsters have started putting fraudulent QR codes on parking meters. That fraud scheme is already being used in multiple German cities.​


1731862038264.png
This is what the fake QR code stickers look like.

Using fake QR codes of the parking service provider Easypark, fraudsters try to obtain the payment details of users. "The stickers are quite well designed and make fraudulent use of the logo of the service provider and even the fitting color as an outline", the State Office of Criminal Investigation (LKA) of Lower Saxony said on November 14th 2024. According to the city of Hanover, fraudulent codes appeared before that in Berlin and Landau.

If you scan the QR code to start the parking procedure, according to the statement, you are redirected to a website which is "designed almost identically to the original page". As the city of Hanover further wrote, the employees first noticed the fraudulent codes on November 12th 2024. According to the LKA, the amount of discovered fakes so far is "in the low double digits". The fraud is called quishing, a portmanteau of QR code and phishing.

Customers are required to enter payment details​


Accordingly, fraudsters made use of the domain Easypark.live for their scheme. There, just like in the original app by Easypark, you can select a parking zone as well as enter a license plate and a parking duration. Afterwards, credit card details are to be entered. "Whether a fee and what fee is charged in that moment is still unknown at the moment. It could be that the culprits collect the credit card data and use it later in an abusive way", the LKA writes. The content of the domain Easypark.live are currently no longer available, however.

On its websites, Easypark also warns about the quishing fraud. According to the provider, QR codes never redirect to a website, but always to the Easypark app. If that isn't installed yet, the codes only redirect to the download of the app.

In addition, the codes are always part of the official signage. "If it looks like a sticker or it's located at a strange place, it could be a case of fraud", the company writes.

Quishing is widespread already​


Deception using fake QR codes is being used more often by criminals, such as at charging stations for electric cars. In August of 2024, consumer protection agencies warned about quishing attempts in fake letters to bank account holders. And fraudulent traffic tickets have already been used for the scheme.

The LKA Lower Saxony reported on a strange case in the area of the Harz municipality. There, on an outdoor donation box, a sticker asked for donations using Bitcoins. But the sticker was not from the association that operates the donation box.
 
Never use QR codes for anything ever. In fact, you should carry a handful of your own stickers with you. Maybe a roll of duct tape, or an eyedropper filled with acetone. Anything to cover up or obliterate this retarded scourge upon humanity.
 
Never use QR codes for anything ever. In fact, you should carry a handful of your own stickers with you. Maybe a roll of duct tape, or an eyedropper filled with acetone. Anything to cover up or obliterate this retarded scourge upon humanity.
In the future everyone will have QR codes tattooed onto themselves for quick access to their resume, dating profile and medical history.
 
I'm honestly surprised this type of thing isn't already a well known common scam. QR codes are fucking everywhere and people seem to have no problem just blindly scanning them without a second thought.
 
Every time some app or site has me scan a fucking QR CODE instead of just letting me log in like a normal person, I want to (FEDPOST REDACTED). I knew it was just a matter of time before someone did something like this, the only surprise is it took so long.
 
Every time some app or site has me scan a fucking QR CODE instead of just letting me log in like a normal person, I want to (FEDPOST REDACTED). I knew it was just a matter of time before someone did something like this, the only surprise is it took so long.
No joke: I've seen an airport "restaurant" that had no physical menu and you couldn't just talk to the guys and tell them what you wanted.
Instead, they had a fucking QR code at the bar they expected you to scan that would take you to an online menu where you make your order and pay.

Dumbest bullshit I've ever seen.
 
Last time I had to deal with QR crap was in Chick-Fil-A. They had sales reps giving out the delivery drivers some coupon for either something free or a couple bucks off whatever purchase but you had to scan the QR code on the card and take a survey in order to activate it, all the while they were eyeballing you like a hawk on the other side of the store waiting for you to finish the survey.

I just walked out and canceled the delivery i was supposed to pick up. I avoided Chick-Fil-A for like a week just to be on the safe side of never having to see those sales reps again.
 
I don't mind QR codes.
I think they're overused for some things and don't understand the benefits of using them to replace actual menus but they're great for when you have to organise groups of people into doing things and need to send them somewhere.
No more "what does that say? What's a slash? Is that .com or .org?" etc.
Even a monkey (or a zoomer - same thing) knows how to use a camera.
For "More information" type linking I find them very useful.

Sucks that they've been ruined by the lowest common denominator.
Similarly how link shortening got ruined and got blocked by most government systems because of nefarious actors.

itsallsotiresome.jpg

Personally, I blame dindus. Most scams in Australia originate from overseas (India, China, Russia). This scam appears to be in Germany so it's probably gypsies, or Arabs, or Indians or some other flavour of non white.
 
Last time I had to deal with QR crap was in Chick-Fil-A. They had sales reps giving out the delivery drivers some coupon for either something free or a couple bucks off whatever purchase but you had to scan the QR code on the card and take a survey in order to activate it, all the while they were eyeballing you like a hawk on the other side of the store waiting for you to finish the survey.

I just walked out and canceled the delivery i was supposed to pick up. I avoided Chick-Fil-A for like a week just to be on the safe side of never having to see those sales reps again.
At first I was horrified that someone’s order would just disappear into the aether, but then I realized that the system would just ping another driver and the machine would keep on humming.

Still, you’re responsible for some rando getting their food a little bit late. You monster.
 
Back
Top Bottom