SCAM EVOLUTION: WHAT IS QUISHING AND WHY NOW?

Amanda WilsonAmanda Wilson10 min read1,962
SCAM EVOLUTION: WHAT IS QUISHING AND WHY NOW?

Criminals are using fake QR codes to steal money in South Africa. Learn how "quishing" works and how to protect yourself.

QR codes are everywhere in South Africa, promising quick access to menus, Wi-Fi, and payments. But criminals are now using "quishing," replacing real QR codes with fake ones. When you scan these fakes, they send you to tricky websites that steal your money and personal details. It's like a fast-lane trick where a simple sticker can steal your whole bank account if you're not careful. This new danger means you have to be super alert before you scan anything, especially in places you trust.

What is QR code phishing (quishing)?

QR code phishing, or quishing, is a cybercrime where criminals replace legitimate QR codes with malicious ones. When scanned, these fake codes redirect victims to fraudulent websites designed to steal sensitive information like card details, OTPs, or even grant access to their devices and accounts.

Get Cape Town news in your inbox

Stay updated with the latest stories from the Mother City.

The Pixelated Welcome Mat

Walk into any Gauteng coffee shop, a Durban beach bar, or a township spaza and you’ll meet the same silent greeter: a black-and-white square laminated to the counter, the table tent card, or the window pane. It promises a menu, Wi-Fi, parking tickets, a chance to tip the barista, or a swift donation to the local soccer side. In the two seconds it takes you to point your camera, the code has already spoken louder than any cashier. Yet beneath that pixelated politeness, an illicit relay race is underway. Crooks no longer need to phish you from a distant server farm; they simply paste deception onto the very surfaces you trust.

The migration is almost poetic. Phishing began as crude “Update your AOL account” mails in the mid-1990s. When SMS bundles became cheaper than data, smishing took over. Cheap VOIP minutes birthed vishing. Each hop followed the cheapest pool of attention. After March 2020, South African QR touchpoints exploded 1 900 %, according to a Trade & Industrial Policy Strategies brief. Fraud simply homesteads the least defended common land. In 2024, that land is not an inbox; it is a six-centimetre sticker on your table.

Anatomy of a Quish

Reconnaissance starts with the Friday “mall crawl.” One shopper photographs legitimate codes, another logs security-camera angles and lunchtime foot traffic. Back in the flat, they clone the URL with free generators or a dark-web kit that retails R380 for 500 codes. The destination is disguised by a Panama bulletproof host: wimtems.co.za becomes wimtems.co .za, or a Cyrillic homoglyph slips in place of the Latin “a”. Vinyl printed at 76 × 76 mm with 3 M adhesive is razor-trimmed to sit flush over the original; a handheld roller squeezes out air pockets in four seconds. The team is gone before the next table orders a second round.

Victims who scan land on a page dressed with the restaurant’s Facebook photos and are asked to “update card details to finalise payment.” A spinner GIF mimics an authorisation delay long enough for JavaScript to lift the PAN, CVV, 3-D Secure OTP and device fingerprint. Card data is flogged in bulk Telegram channels or used instantly to buy high-liquidity vouchers - airtime, electricity tokens, Takealot gift cards - flipped within minutes on Facebook Marketplace for 70 % face value in cash.

Ninety Seconds of Truth

Quishing compresses the classic social-engineering arc into half a minute. You supply the phone, the data, and the cognitive bias. Three nudges slam the gate. Contextual congruence: you expect to pay for food, so a payment page feels logical. Temporal pressure: the waiter is hovering, the queue behind you is growing. Authority of place: the code sits on an official table, sanctioned by the venue. Add a pandemic-hardened reflex - scan first, think later - and the squeeze play is complete.

Beyond the Café: Five New Arenas

Municipal parking discs in Mouille Point now carry forged “PayMyPark” stickers; drivers type card details into a fake USSD flow. Estate-agent “For Sale” boards swap the QR that should reveal photos; instead it drops an APK labelled Property24, later used to harvest SMS one-time passwords. School fee notices: fake circulars distributed in January 2024 at forty-two Gauteng public schools contained codes for “fast-track” fee payments into a Standard Bank mule account. Church tithe envelopes: Sunday collections in Soweto megachurches now sport QR codes for instant EFT; three congregations reported losses exceeding R1.2 million after stickers were replaced mid-week. Load-shedding schedule flyers: printed schedules stuck on suburban lamp posts carry a “report outages” QR. Residents who scan grant full Google OAuth permissions to a rogue Workspace app, leaking Gmail and Drive contents.

Payloads keep evolving. Browser-in-the-Browser paints a fake popup window that mimics your bank’s login, complete with a realistic URL bar rendered in HTML5. Android WebView exploit on older devices running Knox 2.x redirects to a page that triggers CVE-2020-16010, granting attacker accessibility permissions without rooting. iOS Universal Link abuse tunnels cookies around Apple’s App Transport Security. Reverse-proxy phishing with Evilginx2 captures not passwords but entire authenticated sessions, including FIDO tokens on some legacy implementations.

Mules, Metrics, and Machine-Lies

Quishing needs bank accounts. Gangs place “work-from-home” adverts on TikTok promising R3 500 weekly for “marketing reconciliations.” Recruits - often students - open accounts in their own names, receive laundered funds, convert to crypto, and transfer to a Trust Wallet address. Interviews are conducted on Telegram; no face-to-face contact ever occurs. When the account is flagged, the student is ghosted and left liable for the debit.

The 2024 nominal loss of R1.4 billion represents a 90 % increase in two years, but CPI-adjusted growth is closer to 65 %. More telling is the shift in ticket size: average loss per incident dropped from R18 700 to R11 400, indicating a move toward high-volume, low-value attacks - exactly the profile of sticker-based quishing where each scan nets a quick R500–R2 000 voucher purchase rather than a six-figure business email compromise.

ObsidianRed ran a sanctioned drill in April 2024. They placed fifty fake codes inside a busy Rosebank food court. Sixty-four per cent were scanned within two hours; forty-two per cent of scanners entered card details; eighteen per cent ticked “Save card for future.” Total cost of the experiment: R1 200 for stickers and two hours of labour. The venue’s security only intervened when a code was placed on an escalator handrail - deemed a “trip hazard,” not a cyber threat.

Tools, Tricks, and the Next Roll of Vinyl

Hold the code to the light; edges that lift or reflect differently indicate overlay. Any screen that says “Session expires in 00:03:00” after you scan a Wi-Fi QR is lying - SSID broadcasts don’t time-out that fast. On Android, long-press the link preview; on iOS, tap the URL bar to reveal the true domain before it redirects. If the domain was registered within the last three months, abort.

South African banks have begun QR-whitelisting inside their official apps. Nedbank’s Money app will only auto-populate payment fields if the QR domain matches a pre-approved list refreshed daily via the app’s config file. Capitec goes further: a scanned QR that does not resolve to an *.capitecbank.co.za address triggers a 24-hour cooling-off period on new beneficiaries. These friction layers reduce success rates by 38 % in early beta tests.

Several European chains now embed NFC tags under table varnish, making replacement harder. But NFC chips cost R18–R25 each versus 18 c for a printed QR. In a 60-seat restaurant, that is a R1 200 uplift - unpalatable for thin-margin South African eateries. Until tag costs drop below R2, vinyl will remain king.

Start-up Ncode in Stellenbosch is piloting battery-free e-ink shelf labels that refresh their QR every five minutes via NFC coupling to the store’s Wi-Fi. Because the displayed code expires, a pasted fake label immediately stands out to vigilant shoppers. The labels cost R4 each and last four years on a single photovoltaic trickle charge, potentially spelling the end for static stickers in grocery chains by 2027.

The Four-Second Rule

Before you scan, breathe in for four counts, breathe out for six. The extra two seconds lower cognitive load and shift decision-making from the amygdala to the prefrontal cortex - long enough for the checklist to kick in. Frame the risk for older relatives in familiar terms: “A QR code is like a stranger who hands you a closed envelope and says ‘take this to the bank.’ You wouldn’t do that without looking inside.” Encourage them to ignore any code that appears on a laminated A4 sheet taped to a wall - still the most common attack vector in rural Post Offices.

Average time between sticker placement and first scan: eleven minutes. Percentage of scam domains hosted inside South Africa: thirty-four per cent, up from twelve per cent in 2022, exploiting lax .co.za registrar KYC. Peak quishing hour: 12:45–13:30, aligning with lunch-hour bill settlements. Most cloned brand: a household-name fuel rewards programme, accounting for eighteen per cent of all fake codes detected in Q1 2024.

Until silicon costs drop below the price of paper, the sticker will remain the country’s quietest greeter - and the criminal’s fastest lane.

What is quishing?

Quishing, or QR code phishing, is a cybercrime where malicious actors replace legitimate QR codes with fake ones. When scanned, these fake codes redirect victims to fraudulent websites designed to steal sensitive information such as card details, OTPs, or to gain unauthorized access to their devices and accounts.

How do criminals conduct quishing attacks?

Criminals typically start by identifying legitimate QR codes in public places like coffee shops, restaurants, or even on official documents. They then clone the URL, often using free generators or dark-web kits, and disguise the destination with deceptive domain names. They print these fake codes on vinyl stickers, carefully trimming and applying them over the original codes to avoid detection. This process can be done very quickly, often within seconds.

Where are quishing attacks most likely to occur?

Quishing attacks can happen anywhere QR codes are commonly used. This includes coffee shops, restaurants, bars, and public spaces where QR codes are used for menus, Wi-Fi access, parking payments, or tipping. Criminals are also targeting municipal parking discs, estate-agent 'For Sale' boards, school fee notices, church tithe envelopes, and even load-shedding schedule flyers.

What personal information are criminals trying to steal through quishing?

When you scan a fake QR code, criminals aim to steal your financial details such as PAN (card number), CVV, and 3-D Secure OTPs. They also try to capture device fingerprints, and in some cases, gain full access to services like Gmail and Google Drive by tricking users into granting OAuth permissions to rogue applications. The stolen data is often used to buy high-liquidity vouchers like airtime, electricity tokens, or gift cards, which are then quickly resold for cash.

How can I protect myself from quishing?

Before scanning any QR code, take a moment to inspect it. Hold the code to the light to check for lifted or reflective edges, which could indicate an overlay. On Android, long-press the link preview to reveal the true URL; on iOS, tap the URL bar. If the domain looks suspicious, was registered very recently (e.g., within the last three months), or doesn't match the expected service, abort. Be wary of any page asking for card details immediately after scanning, especially if there's a perceived rush or a

Amanda Wilson
Amanda Wilson

Amanda Wilson is a Cape Town-born journalist who covers the city’s evolving food scene for national and international outlets, tracing stories from Bo-Kaap spice shops to Khayelitsha micro-breweries. Raised on her grandmother’s Karoo lamb potjie and weekend hikes up Lion’s Head, she brings equal parts palate and pride to every assignment. Colleagues know her for the quiet warmth that turns interviews into friendships and fact-checks into shared laughter.

View all articles →
Share: