Phishing surge: cybercriminals now mimic court notices with qr codes
A new wave of sophisticated phishing attacks is targeting individuals worldwide, moving beyond the familiar WhatsApp spam and impersonation scams. Cybercriminals are now convincingly mimicking official court notices, leveraging QR codes to redirect victims to fraudulent payment portals—all without resorting to complex AI generation.
The escalation: from email to qr code deception
While smishing—phishing attacks delivered via SMS—has been a growing concern, this latest tactic represents a significant escalation. Initially observed in the United States, particularly in regions like New York, California, and Texas, these attacks manifest as false “Notice of Non-Compliance” alerts for traffic violations. The evolution is striking: early attempts relied on direct links, yet now, attackers are deploying a more elaborate phishing campaign featuring images that convincingly replicate physical court warnings or formal judicial notifications. A scanned image, presented as an official document, lends an air of legitimacy that’s proving remarkably effective.
The perpetrators are exploiting a subtle psychological trigger. Most victims report the requested payment is a seemingly innocuous $6.99 (approximately €6), a deliberately low amount intended to bypass scrutiny. But this seemingly trivial sum is merely the entry point. Once a user scans the QR code and inputs their payment details, the attacker gains access to a wealth of personal information, including credit card data. The consequence? Victims often find their bank accounts drained, left with a devastating zero balance.
What makes this attack particularly insidious is the use of QR codes to circumvent traditional security filters. The widespread nature of these attacks suggests a highly organized operation, netting criminals not just modest financial gains, but also a treasure trove of sensitive personal data.
Authorities across the globe are warning the public to remain vigilant. Official bodies, such as the DGT (Dirección General de Tráfico) in Spain, the Guardia Civil, and the Policía Nacional, never issue traffic violation notices via SMS or phone calls, let alone with embedded payment links. The clear recommendation is simple: if you receive such a message, ignore it. Verify any potential claims directly through official channels—in Spain, that means accessing the miDGT app or checking dgt.gob.es—before taking any action.
The sheer volume of these deceptive messages underscores a disturbing trend: the increasing sophistication of cybercrime and the erosion of trust in digital communications. The ease with which criminals can now mimic official entities demands a heightened level of skepticism and a proactive approach to online security. Complacency is no longer an option.

Beyond the initial scam: the data harvest
It's not just about the $6.99. The true value lies in the data harvested during the payment process. Attackers leverage the information provided on the fake payment page – names, addresses, credit card details – for identity theft and further fraudulent activities. The initial small sum is a loss leader, a means to an end: the acquisition of valuable personal data.
The current landscape illustrates a grim reality: technological advancement isn’t solely benefiting legitimate enterprises. Malicious actors are adeptly adapting and exploiting vulnerabilities, pushing the boundaries of deception. The onus now falls on individuals and institutions to bolster their defenses and remain perpetually alert to the evolving tactics of cybercriminals.
