If you find a parking notice tucked under your windshield wiper with a QR code offering "immediate payment with a discount," don't scan it. Portuguese police have been warning for months about exactly this scam, and it's part of a broader wave of QR-code fraud spreading across the country, in email inboxes and on the street alike.
How widespread is the scam?
Cybersecurity firm ESET found that QR-code phishing, known in the industry as "quishing", was the seventh most detected email threat in Portugal between December 2025 and May 2026, accounting for 4.8% of all email threats the firm identified nationally. In ESET's global telemetry, roughly 11% of phishing emails it detected used QR codes, a trend that's kept climbing since the firm started tracking it separately in late 2025.
What quishing actually is
Quishing swaps the usual suspicious link for a QR code. A typical email impersonates a company, an HR department, or a familiar business platform, some campaigns mimic services like DocuSign, and asks the recipient to scan a code to view a document or confirm some urgent task. Scanning it leads to a fraudulent page built to steal login credentials, banking details, or other sensitive information. "Quishing is particularly effective because it reduces the visibility of the attack," said Ricardo Neves, ESET Portugal's communications lead, the malicious link never appears in the email body, and scanning shifts the interaction to a phone, a device that often carries fewer security protections than a work computer.
From inboxes to parking meters
QR-code fraud has also spread into public spaces. Fake codes have been found on parking meters, bike-share docks, and fraudulent parking or toll notices, directing victims to payment pages designed to steal card details or personal information.
This isn't just a theoretical risk. In Portugal, the GNR's Porto command issued a public warning in March describing criminals placing fake QR-code stickers over genuine ones on parking meters and restaurant menus. PSP has separately flagged similar cases, including fake windshield notices, printed to look like parking fines, sometimes carrying counterfeit EMEL or Polícia Municipal logos, designed to pressure drivers into making an immediate QR-code payment. One practical rule: a QR code left on a paper notice under your windshield wiper should be treated as suspicious. Portuguese authorities have warned that genuine parking enforcement does not rely on QR-code payment notices placed on vehicles.
How to avoid it
For codes you encounter in person, on a parking meter, a charging station, or a supposed fine, run a finger over the sticker before scanning. A code stuck on top of another, or one that's crooked, poorly aligned, or printed at a different quality than the rest of the machine, is a warning sign. Most phones also show you the destination web address before opening a scanned link, check it before continuing.
For codes arriving by email, treat them with the same suspicion you'd apply to an unfamiliar link: confirm the communication was actually expected, verify the sender, and be wary of anything demanding urgency or promising quick access to information about pay, benefits, or payments.
If you come across a fake code, photograph it and report it to the parking operator or local council so it can be removed. If you've entered personal or payment information, contact your bank immediately and report the incident to the PSP, GNR or Polícia Judiciária, depending on the circumstances.