Fake Payment Notices Placed on Parked Cars
Polish media and authorities are warning of a quishing scheme in which criminals place flyers under the windshield wipers of parked cars designed to resemble official notices from KAS, the Polish National Revenue Administration (Krajowa Administracja Skarbowa). According to the tax administration, the cards carry an agency logo, a case number and an urgency note.
The flyers feature a QR code that purportedly allows recipients to check an outstanding claim or complete their data. Scanning the code leads to a replica of a government website. There, according to KAS, users are asked for a supposed additional payment, the PESEL number – Poland's national identification number – as well as login and credit card details.
KAS said the tax administration does not leave payment notices under windshield wipers and does not process payments via QR codes on flyers. Such cards are fraud attempts, the authority said.
How the Scheme Works
- Criminals print official-looking flyers with an agency logo, case number and payment demand
- The flyers are placed under wipers in busy parking areas, including city centres, hospitals and shopping centres
- Drivers scan the QR code to settle the supposed claim
- A cloned gov.pl page asks for the PESEL number, address, login details and a small additional payment by credit card
- With the stolen data, the perpetrators take over accounts, trigger debits or resell the identities
Warning Signs of the Fake Notices
Official Notice on a Parked Car
Tax offices, police and municipal authorities do not leave payment demands under windshield wipers. An official-looking letter on a windshield is an indicator of fraud.
QR Code for Payment
Authorities do not process payments via QR codes on flyers. A payment request via QR code points to fraud.
Time Pressure and Threats
Phrases such as 'final notice', 'act immediately' or 'enforcement imminent' are typical phishing markers intended to prompt a rushed reaction.
No Official Contact Channel
Genuine authorities provide a phone number, postal address and a verifiable case number – not only a link or QR code on a flyer.
Context: Quishing Cases Reported in Germany
Quishing cases have been reported in several European countries since 2024. In Germany, authorities have recorded fake bank letters (Tauberbischofsheim, March 2026), manipulated parking meters (Dortmund, since January 2025) and tampered EV charging stations (Schwabenheim, March 2026). Whether the windshield flyer variant will appear in Germany or the Netherlands is not yet known.
Safety Recommendations
- • Do not act on flyers behind windshield wipers that carry an agency logo and QR code; they are generally fraud attempts
- • Do not scan QR codes from unknown sources, especially when a payment is requested
- • Do not enter personal or payment data on pages reached via a QR code
- • Verify any supposed claim directly with the tax office, municipality or bank – via official phone numbers, not the contact details on the flyer
- • Report suspicious flyers to local police and photograph the flyer and the location where it was found
QRTrust: URL Checks Before a QR Code Is Opened
QRTrust checks the destination URL of a QR code before the page is opened. The 6-layer analysis compares the address in real time against databases including PhishTank and Google Safe Browsing, supplemented by an AI-based assessment.
The service operates in compliance with the GDPR and is hosted in Germany.
Check a QR Code →About QRTrust
QRTrust is Germany's first QR code security platform, developed in Dortmund. AI-powered real-time detection, a local threat database and multi-layered security checks protect citizens, authorities and businesses from quishing attacks. GDPR compliant, hosted in Germany.
