26/08/2026
You wouldn't click a random link stuck to a parking meter, but put that same link behind a QR code and suddenly it feels legitimate.
That's the problem.
The BBC has reported on Les Howard, who needed to pay for parking while visiting Caernarfon.
He scanned the QR code on the parking meter, apparently downloaded the parking app and carried on with his day.
Except it wasn't what it appeared to be.
The following day, money started disappearing from his account in £60 chunks.
And here's the statistic that caught my attention:
Reports of QR code-related scams have increased by 700% in four years.
QR codes aren't inherently dangerous, they're just links, but unlike a normal web link, you can't see where they're taking you before you scan them.
There's also a psychological element to this. A QR code on a parking machine feels official as it's attached to something we trust.
We're usually standing there thinking about paying for parking, getting to an appointment, meeting someone or avoiding a ticket.
We're not thinking about cyber security.
Criminals don't always need to hack technology.
Sometimes they just need to exploit context, trust and urgency.
My rule with QR codes is simple - Treat every QR code like a link you can't see.
If it's asking you to make a payment, download an app or enter login details, take a few seconds to verify it independently.
For parking apps in particular, I'd rather search for the operator's official app myself than trust a sticker on a machine.
Businesses using QR codes need to think about this too - If customers are being told to trust a QR code in your physical premises, who is checking that somebody hasn't put another one over the top?
Cyber security isn't always about sophisticated hackers.
Sometimes it's literally a sticker.
BBC story: Les used a QR code to download a parking app - but it was a scam - BBC News
https://www.bbc.co.uk/news/articles/cwyjqg578e1o