The scam: a fake traffic fine, a QR code, and your bank details gone
Here's how it works. You receive a text message — or sometimes an image sent via SMS or WhatsApp — that looks like an official traffic violation notice. It mentions an outstanding fine for a traffic violation involving your vehicle. It says the matter has entered a formal enforcement stage. It tells you to scan the QR code to pay the balance and avoid further consequences.
You scan it. Your phone's camera reads the QR code and opens a link. There's a CAPTCHA to solve — which makes the site look more legitimate and also prevents automated security tools from scanning it. After the CAPTCHA, you're redirected to a website that looks like a government agency's official portal — something resembling a regional transport office or traffic authority site. It shows you a small outstanding balance. You enter your name, address, phone number, email, and credit card or UPI details to pay. That information goes directly to scammers.
This is called "quishing" — QR code phishing. The QR code replaces the older method of including a direct link in the text message, because links are now more easily flagged by mobile security software and text message filters. QR codes are harder to automatically inspect — your phone camera just reads them as an instruction to open a URL, and most phones don't show you a preview of where that URL leads before opening it.
The global version — what's happening in the US
The campaign that's been widely documented in April 2026 targets US residents, impersonating state courts and motor vehicle agencies across New York, California, North Carolina, Illinois, Virginia, Texas, Connecticut, and New Jersey. The fake notices claim to be from entities like the "Criminal Court of the City of New York" and include language designed to create urgency: "This matter has now entered the formal enforcement stage."
The phishing sites use domain names that look superficially official — things like "ny.gov-skd.org" or "ny.ofkhv.life" — relying on the fact that most people don't carefully read a URL that appears right after they've scanned a QR code, especially if the page visually resembles a government website. The amount demanded is consistently small — $6.99 in the US version — because a small amount is psychologically easier to pay without thinking too hard about whether the fine is legitimate.
The CAPTCHA step is worth paying attention to as a tactic: it's not there to verify you're human. It's there to stop automated security research tools from scanning the site and flagging it as malicious. By requiring a human interaction step, the scammers slow down the time it takes for the phishing site to get blacklisted by security services.
The India version — it's already happening
For Indian smartphone users, this scam isn't a foreign story. The traffic fine QR code phishing template has a direct Indian equivalent: fake e-challan messages. India's Parivahan portal processes legitimate traffic challan notices, and Indian scammers have been exploiting the familiarity of that system for years. The QR code evolution of this scam makes it meaningfully more dangerous in the Indian context for several reasons.
First, India has significantly more QR code familiarity than most countries. UPI payments, restaurant menus, shop payments, public transit — Indian users scan QR codes constantly without a second thought. The conditioned reflex of "see QR code, scan it" is stronger in India than almost anywhere else in the world. Scammers exploiting QR codes in India are working with the grain of user behaviour rather than against it.
Second, the fake e-challan scam template is already well-established in India. Fraudulent SMS messages claiming unpaid traffic fines from regional transport offices, asking recipients to pay through links to fake Parivahan-lookalike sites, have been circulating for at least two years. The QR code version is simply the next evolution — harder to detect, harder to filter, using the same urgency psychology that has proven effective.
Third, the Indian version has higher stakes because of UPI integration. While the US phishing sites target credit card information, an Indian fake e-challan site can ask for UPI ID, UPI PIN, or redirect to a fake payment app screen. If a user enters their UPI credentials on a phishing site, the resulting access is to a payment system that processes transactions in seconds, with no chargeback mechanism like credit cards provide. Once UPI money is gone, recovering it requires a bank complaint process that has uncertain outcomes.
How to tell if a traffic fine message is real or fake
The single most reliable way to verify a traffic challan in India is to visit parivahan.gov.in/parivahan directly — by typing the URL yourself, not by clicking any link or scanning any QR code in a message. On the Parivahan portal, you can check outstanding challans by vehicle registration number. If you have an outstanding fine, it will appear there. If it doesn't appear there, the message you received is fraudulent regardless of how official it looks.
The key signals that a traffic fine message is a scam: it was sent as an unsolicited SMS or WhatsApp message rather than appearing on your registered vehicle's Parivahan account. It includes a QR code to scan rather than directing you to the official government portal. It creates urgency with language about court appearances, license suspension, or immediate consequences. The amount is suspiciously small — a few hundred rupees — which is calibrated to feel like something you'd pay without much thought. The website it leads to has a domain name that looks like a government site but has unusual extensions like .org, .life, or .net instead of .gov.in.
What to do if you've already scanned the QR code
If you scanned the QR code but didn't enter any information — just solved the CAPTCHA and looked at the site — close the browser, clear your browsing history, and don't interact with any follow-up messages. The damage at that stage is limited.
If you entered your name, address, phone number, or email but did not enter payment information — your contact details are now in a scammer's database. Expect follow-up phishing attempts via SMS, email, and possibly calls. Be more cautious about any unsolicited contact over the next few months. Consider flagging your email for phishing if you see suspicious messages related to the information you provided.
If you entered credit or debit card information — call your bank immediately and ask for the card to be blocked and reissued. File a complaint with your bank's fraud department. In India, also file a complaint on the National Cybercrime Reporting Portal at cybercrime.gov.in. Note the phone number the original message came from and the website domain it led to — these are useful for the complaint.
If you entered UPI credentials or completed a UPI payment — immediately call your bank's fraud helpline (most Indian banks have 24-hour numbers for this). File a cybercrime complaint at cybercrime.gov.in and include the UPI transaction ID. Alert your bank to hold any pending transactions if possible. Speed matters here — UPI fraud responses are time-sensitive.
TamilTech's take
The QR code traffic fine scam is effective because it layers multiple legitimate-looking elements together: an official-looking notice, a trusted scanning behaviour, a small payment amount that doesn't trigger alarm, and a website that mimics a real government portal. Each individual element looks plausible. The combination is designed to get you from receiving the message to entering your payment details in under two minutes, before skepticism kicks in. The defence is simple but requires a habit change: never scan a QR code in an unsolicited message to pay a government fine. Always go directly to parivahan.gov.in to check your vehicle's status. The extra 60 seconds that takes is worth considerably more than the time you'd spend recovering from a financial fraud.




Comments (0)
Be the first to comment!