Cashless parking operators do not put payment QR codes on their signs and do not request card details by text message. Money lost to a card entered on a cloned page is treated as an unauthorised transaction and must be refunded, while authorised bank transfers fall under reimbursement rules capped at 85,000 pounds.
TL;DR · LAST REVIEWED 14 August 2026
- Cashless parking operators including RingGo state they do not use payment QR codes on the signs they issue.
- Two versions circulate: a counterfeit QR sticker placed over a genuine sign, and a text claiming a parking charge is outstanding.
- Victims can lose twice, because no valid parking session is created and a genuine penalty notice may follow.
- Card details entered on a cloned page create unauthorised transactions, which must be refunded under the Payment Services Regulations 2017.
- Authorised bank transfers to a fraudster fall under mandatory reimbursement rules, capped at £85,000 per claim.
KEY FACTS
- Refund position on unauthorised card transactions: full refund unless the customer acted fraudulently or with gross negligence.
- Mandatory reimbursement cap for authorised push payment fraud: £85,000 per claim.
- Reimbursement deadline for firms: five business days, with limited extensions.
- Reporting route in England, Wales and Northern Ireland: Action Fraud. In Scotland: Police Scotland on 101.
- Suspicious texts can be forwarded free to 7726.
How the Two Versions Work
Two distinct frauds are running against drivers who pay for parking by phone, and they share a payment page. The first is quishing, a combination of QR codes and phishing. A counterfeit sticker is placed over or beside a genuine sign or pay and display machine, and a driver in a hurry scans it expecting the legitimate payment service. The page that loads carries familiar branding and asks for a vehicle registration and card details. The second version arrives by text, claiming that a routine or billing review has identified an outstanding parking charge, or that a session was never paid and a penalty will escalate unless the amount is settled. The sums quoted are deliberately small, low enough that paying feels quicker than checking, while the threat of a larger fine supplies the urgency.
The design of both is worth understanding because it explains the second loss. The fake page captures the card details and may present a fabricated receipt, but no parking session is created on the real operator's system. A civil enforcement officer checking the vehicle registration sees an unpaid bay, and a genuine penalty charge notice follows in the post days later. Victims therefore lose the money taken from the card, face unauthorised transactions afterwards where the details are reused or sold, and receive a real fine for the parking they believed they had paid for. Cashless parking covers hundreds of towns and cities across the United Kingdom, so on any given day a very large number of people genuinely do have a live session or a card stored, which is what makes an untargeted text blast effective.
What the Operators Actually Do
The single most useful verification rule is that cashless parking operators do not use payment QR codes on the signs they issue. RingGo states this explicitly in its own security guidance, and adds that it will never ask a customer to scan a code to download its app, share a PIN, transfer money, install another application or supply bank details through a link sent by text or email. Councils have issued the same warning alongside it. Hartlepool Borough Council, among others, has confirmed that it never uses QR codes as a payment option on its machines and has worked with the operator to place advisory notices on ticket machines after fraudulent stickers were found. Police forces including Cumbria have issued alerts after codes appeared across multiple car parks.
That gives drivers a clean test. A QR code on a parking sign or machine is either the council's own information code or it is fraudulent, and neither should be used to pay. Payment is made through the operator's app downloaded from the official app stores, through the operator's own website typed into the browser rather than reached through a link, by phone using the number printed on the sign, or by cash or card at the machine where that option exists. For texts, the equivalent test is that a genuine outstanding parking charge is not collected by SMS link. The status of any session can be checked inside the app or by signing in to the operator's website directly, which takes less time than reading the message.
Getting the Money Back
The recovery route depends on how the money left the account, and the distinction is worth getting right before contacting the bank. Where card details were entered on a cloned page and the fraudster then used them, the resulting payments are unauthorised transactions. Under the Payment Services Regulations 2017 the payment service provider must refund an unauthorised transaction, and may only decline where the customer acted fraudulently or with intent or gross negligence failed to keep credentials safe. Being deceived by a convincing clone is not, on its own, gross negligence. The refund should be made without undue delay and by the end of the following business day, with the account restored to the position it would have been in.
Where the victim was persuaded to make a bank transfer to an account controlled by the fraudster, that is authorised push payment fraud and falls under the mandatory reimbursement regime that applies to payments made through Faster Payments. Firms must reimburse eligible claims within five business days, subject to limited extensions where more information is needed, and the maximum reimbursement per claim is 85,000 pounds. A consumer standard of caution applies, and an excess may be charged, though vulnerable customers are exempt from both. Where a bank refuses, the complaint goes to the firm first and then to the Financial Ombudsman Service, which considers cases free of charge.
| How the money moved | Framework | Position |
|---|---|---|
| Card details captured, then used | Payment Services Regulations 2017 | Refund unless fraud or gross negligence |
| Card payment for goods or services not received | Chargeback, or section 75 above £100 | Claim through the card provider |
| Bank transfer to the fraudster | Mandatory reimbursement rules | Reimbursed up to £85,000, excess may apply |
| Refusal by the firm | Financial Ombudsman Service | Free independent review |
Reporting and the Genuine Penalty
Reporting serves two purposes: it creates the paper trail a bank claim relies on, and it gets the cloned site taken down. Fraud is reported to Action Fraud in England, Wales and Northern Ireland, and to Police Scotland on 101 in Scotland. Suspicious text messages can be forwarded free of charge to 7726, which routes them to the mobile operator for investigation, and suspicious websites can be reported to the National Cyber Security Centre. A physical fraudulent QR sticker should be reported to the landowner or council responsible for the car park and to the parking operator, both of which have processes to remove it and to have the site shut down. Photographing the sticker before it is removed helps.
The genuine penalty charge notice that arrives afterwards is a separate matter and is not cancelled by the fraud report. On council-run land it is a penalty charge notice with a statutory appeal process, and representations are made to the council within the time stated on the notice, with a right of appeal to an independent adjudicator if rejected. On private land it is a parking charge notice, a contractual claim rather than a fine, and the appeal runs to the operator and then to an independent appeals service where the operator belongs to an accredited trade association. In either case, evidence that a fraudulent code or message caused the failed payment should be submitted with the appeal, alongside the crime reference number.
DISCLAIMER
This article is editorial information, not financial advice. Kael Tripton Ltd is not authorised or regulated by the Financial Conduct Authority. Figures were correct at the last review date shown above; verify current rates and rules with the primary sources listed below before acting.
Frequently asked questions
Do parking apps use QR codes for payment?
No. RingGo states that it does not use QR codes on the signs it issues to help customers pay for parking, and councils including Hartlepool have confirmed they do not offer QR codes as a payment option on their machines. A QR code presented as a way to pay should be treated as fraudulent.
Is the text saying a parking session was unpaid genuine?
Almost certainly not. Cashless parking operators do not collect outstanding charges through a link sent by text message. The status of any session can be checked in the operator's app or by signing in to its website directly rather than through the link.
Can the money be recovered after entering card details on a fake page?
Yes in most cases. Payments made by the fraudster afterwards are unauthorised transactions, and under the Payment Services Regulations 2017 the provider must refund them unless the customer acted fraudulently or with gross negligence. Being deceived by a convincing clone is not by itself gross negligence.
What is the limit on reimbursement for a bank transfer scam?
Mandatory reimbursement for authorised push payment fraud is capped at 85,000 pounds per claim, with firms required to reimburse eligible claims within five business days subject to limited extensions. An excess may be charged, though vulnerable customers are exempt.
Does reporting the scam cancel the parking fine?
No. A penalty charge notice from a council or a parking charge notice from a private operator is handled through its own appeal process. Evidence of the fraudulent code or message, together with the crime reference number, should be submitted with the appeal.
SOURCES
- RingGo, staying safe from QR code scams – accessed 14 August 2026
- Payment Services Regulations 2017 – accessed 14 August 2026
- Payment Systems Regulator, authorised push payment reimbursement – accessed 14 August 2026
- Action Fraud, national fraud reporting centre – accessed 14 August 2026
- National Cyber Security Centre, reporting scam websites – accessed 14 August 2026
- Financial Ombudsman Service – accessed 14 August 2026