Zimbabwe Scam Watch · 8 min read
Fake QR Code Scam in Zimbabwe: Check the Merchant Before You Pay
A QR code can look perfect and still send you to the wrong destination. Zimbabwe’s growing QR-payment environment makes merchant verification more important than sticker design.
A QR code feels safer than a random link because it is physical, compact and increasingly associated with real payments. That visual familiarity is exactly what makes QR phishing useful to criminals.
The source video uses a parking-meter example: a professional-looking sticker is placed over the genuine payment code. The victim scans it, lands on a fake payment page and enters card details.
Zimbabwe does not need identical parking infrastructure for the attack to work. The same logic can be applied to a merchant counter, event poster, delivery invoice, school-fee notice, restaurant table, till point or a QR image forwarded on WhatsApp.
Why a QR Code Can Look Completely Legitimate
You cannot inspect a QR code with your eyes and know which domain, account or payment instruction it contains. A fake code can be printed cleanly and placed over a real one in seconds.
The FBI has warned about QR-code fraud that sends users to sites designed to capture personal and financial information or install malicious software. Zimbabwe’s Reserve Bank also publishes specific guidance for QR-code payments, which is another reason consumers and merchants should treat QR destination integrity as a payment-security issue—not merely a design issue.
The Zimbabwe Version to Expect
A realistic local attack could be a sticker placed over a real merchant QR, a QR code inside a fake quotation or invoice, a WhatsApp image claiming to be an updated payment code, a fake event-ticket or registration page, a ‘scan to receive a refund’ message, or a code that opens a cloned bank or delivery page.
The important question is not ‘Does the poster look professional?’ It is ‘Where is this code actually taking me, and who will receive the money or credentials?’
The Payment Check That Matters
Before approving a QR payment:
- Inspect the destination displayed by the phone or payment app.
- Confirm the merchant or beneficiary name, not just the amount.
- If a web page opens, check the domain character by character.
- Be suspicious if a normal merchant payment suddenly asks for an email password, banking password, card PIN or unrelated identity details.
- If the code is physically stuck onto equipment or signage, check whether it looks layered, damaged or recently replaced.
- For a material payment, confirm with staff or the supplier using a contact you already trust.
A clean QR code is not evidence. The payment destination is the evidence.
What Businesses Should Do
Zimbabwean SMEs that accept QR payments should print the merchant name beside the code, use tamper-evident placement where possible, inspect physical codes regularly, keep approved QR artwork in a controlled source file, and prohibit staff from replacing payment codes from unverified WhatsApp attachments.
For emailed invoices, provide a second verification route for any bank-detail or payment-code change. Once customers hear about fake QR codes, every merchant suffers a trust penalty; businesses that make verification easy gain an advantage.
Frequently Asked Questions
Is scanning a QR code itself enough to lose money?
Not usually. The main risk is what the code makes you do next: approve a payment, enter credentials, download software or grant permissions.
How do I know a merchant QR is genuine?
Verify the merchant or beneficiary name displayed by the payment app and confirm unexpected changes through a trusted contact.
Should businesses stop using QR payments?
No. The better response is controlled issuance, visible merchant identity, regular inspection and clear verification procedures.
Sources & further reading
- New Scams That Look Completely Real Now — Chill Dude Explains
- Guidelines, Directives and Circulars — including Guidelines for QR Code Payments in Zimbabwe — Reserve Bank of Zimbabwe
- Unsolicited Packages Containing QR Codes Used to Initiate Fraud Schemes — Federal Bureau of Investigation