Drivers paying at carpark kiosks and coupon-less lots face a newer scam shape: criminals overlay legitimate-looking QR stickers that route phones to phishing pages mimicking Land Transport Authority (LTA) or mall-operator payment portals. The Cyber Security Agency (CSA) issued a refreshed advisory on “quishing”—QR-enabled phishing—warning that tampered stickers have appeared on payment machines and lamp posts at multiple locations, and urging motorists to type known URLs or use official apps instead of scanning unknown codes.
How quishing works at carparks
Scammers print stickers with embedded QR codes that resolve to lookalike domains, often swapping a single letter in a trusted hostname. Victims who scan expecting a quick PayNow or card flow instead enter credentials or approve malicious app installs. Singapore Police Force (SPF) media releases this week highlighted cases where drivers lost money after following fake “outstanding parking fee” prompts; funds moved quickly through mule accounts, the standard scam playbook adapted to a two-second scan.
CSA’s SingCERT channel asks organisations to report compromised signage so operators can audit lots. LTA’s official parking guidance lists authorised payment methods—CashCard readers, official mobile apps, and operator websites—not ad-hoc stickers slapped beside card slots.
Why carparks are attractive targets
Carparks mix high throughput and low dwell time: drivers want to pay and leave, making them less likely to inspect URLs. Older kiosks with faded branding are easier to spoof visually. Mall and HDB estate lots managed by different vendors create inconsistent sticker designs, so a fake QR can blend in. CSA notes quishing also appears on restaurant table tents and parcel delivery notices; carparks are simply the latest high-volume surface.
Mobile browsers that preview URLs help, but only if users pause to read them. Attackers use URL shorteners to hide destinations until after the tap. Police advise against installing APK files or sideloaded “parking helper” apps prompted by scans—legitimate operators publish through official app stores with verifiable developer names. Workplace fleet managers should add quishing to driver briefings alongside diesel theft and gantry card sharing.
Defensive habits for households
Prefer the official app you already used last month over a new QR on the machine. If the kiosk screen offers payment, use the built-in flow rather than a sticker. When in doubt, pay at a manned counter or use validated coupons rather than risk a spoofed link. Report tampered stickers to mall security or town council operators and file a police report if money left your account.
Businesses managing carparks should schedule sticker audits after CSA alerts—remove unauthorised overlays and laminate official codes where appropriate. Security teams can rotate QR payloads less predictably and monitor certificate transparency logs for homograph domains targeting their brands.
Government coordination
CSA coordinates with SPF and sector regulators under the national anti-scam framework. Quishing sits beside SMS phishing and fake government impersonation calls; education campaigns now include “look before you scan” messaging on social channels. SingCERT publishes indicators of compromise when campaigns are attributed, helping web filters block fresh domains faster.
For enterprises with fleet cards, fleet managers should brief drivers on the same rules—commercial lots are not immune. Insurance and cyber policies may treat user-authorised transfers differently from card fraud; prevention remains cheaper than recovery.
What to do if you scanned
If you entered credentials, change passwords immediately from a clean device, enable two-factor authentication on financial apps, and call your bank’s fraud hotline. Preserve screenshots of the URL and time of scan for police statements. CSA’s reporting form helps aggregate location data so operators can sweep affected carparks.
Quishing exploits convenience; the fix is friction where it matters—verify the operator, use known apps, and treat surprise QR stickers like surprise card skimmers. Carparks will stay targets as long as scans stay faster than reading fine print. Elderly drivers who rely on grandchildren to pay should agree on one official app profile rather than experimenting with new scans at the gantry.








