← Back to all tech guides
🔳 Scam Safety Guide

QR Code Scams — Parking Meters, Menus & Fake Stickers

Last verified: August 2026

The Danger Is the StickerCrooks stick a fake code over the real one.Parking meterreal codeFAKEstickerstuck on topSends you to afake payment siteOn a meter or sign, feel for a sticker placed over the print.Illustration — a general example; the trick works on menus too.
How a fake QR sticker placed over a real code leads to a scam site.
Your Phone Shows the Link FirstRead the address before you tap to open it.Your phoneopens this link?bills-pay-now.coRead it before you tap.Odd address? Don't open.A weird or unfamiliar address is your cue to stop.Illustration — the address shown is a made-up example.
Your phone previews the link so you can judge it before opening.

QR codes aren't dangerous — fake stickers are. How the "quishing" scam works, the parking-meter sticker trick real cities have warned about, why scammers put QR codes in emails and mystery packages, and the 5-second check your phone already makes possible.

The scam's name
"Quishing" — QR phishing
The real danger
Typing into the fake site, not scanning
Official warnings
FTC & FBI alerts, city parking notices
Bill's hotline
(330) 200-8042

The code isn't the danger. The sticker is.

QR codes went from novelty to everywhere in a few short years — restaurant menus, parking meters, boarding passes, church bulletins. Scammers noticed, and their trick is almost insultingly simple: print a fake code on a sticker, slap it over a real one on a parking meter, and wait for someone in a hurry to scan it and type a card number into a look-alike payment page. Police in Redondo Beach, California found fake stickers on roughly 150 parking meters; Fort Lauderdale and Denver have issued their own warnings. The FTC and FBI have both put out alerts about the same trick arriving by email and even inside mystery packages.

Here's the calm part, and it's the heart of the whole guide: a QR code is just a web address printed as squares. Looking at one does nothing. Scanning one does almost nothing — your phone shows you the address and waits for you to tap. The danger only starts if you open a crooked website and type something into it. Which means a couple of small habits protect you almost completely, without giving up QR codes at all.

Where the fake codes actually show up

  • Parking meters and pay stations. A sticker over (or next to) the real code leads to a fake payment page. You lose the card details and can still get the parking ticket, because the city never got paid.
  • Unexpected emails. "Your password expires — scan to keep your account." Spam filters read text and links, but a QR code is just a picture, so it sails through. A real company would simply give you a link — an emailed QR code that wants a login is a scam until proven otherwise.
  • Mystery packages. A "gift" you never ordered, with a card that says scan to see who sent it. Both the FTC (January 2025) and the FBI (July 2025) issued alerts on this one. Don't scan; the mystery IS the trick.
  • Texts and letters. Fake tolls, traffic tickets, and delivery fees — the same con as the toll-text scam, with a code instead of a link. Forward scam texts to 7726 and delete.

Your phone already shows you the link first

Point an iPhone's Camera app at any QR code and a small yellow banner pops up showing the website address — nothing opens until you tap it. Android phones (Samsung, Pixel, Motorola) do the same through the camera or Google Lens, though some only preview the beginning of a long address, so on Android it pays to re-read the full address in Chrome's bar before typing anything. Either way, reading that preview costs five seconds and commits you to nothing. That pause is the whole defense.

How to judge the address in five seconds

The only part that matters is the name right before the first slash. paybyphone.com/pay is PayByPhone. "poybyphone" — one letter off — was the actual fake used on California parking meters. paybyphone.secure-pay4u.com really belongs to secure-pay4u.com, with the trusted name pasted on the front as decoration. And a shortened link (bit.ly and friends) hides the name entirely — fine for a recipe, never for a payment or a login. When in doubt, close it and type the company's address yourself. The front door is always open; the QR code was only ever a side door.

The 10-second sticker check

  • Is the code a glossy sticker sitting on top of the sign, with edges you can catch with a fingernail? Official codes are usually printed into the sign or menu itself.
  • Is another code peeking out underneath? That's as close to proof as this gets.
  • Does it match the rest of the sign — same fade, same material, straight placement?
  • Paying for parking? Skip the code entirely: use the meter's own keypad, coins, or the official app you installed from the app store.

If you already scanned one

  1. Scanned but never tapped the banner? Nothing happened at all. Truly.
  2. Tapped and looked, but typed nothing? Almost certainly fine — close the tab and run your phone's software update tonight.
  3. Typed a password? Change it now on the real site (email password first if it's shared anywhere), and turn on two-factor authentication.
  4. Typed a card number? Call the number on the back of the card — they'll replace it and reverse anything crooked.
  5. Report it at ReportFraud.ftc.gov and ic3.gov — and tell the business or parking office so the sticker comes down today.

When QR codes are perfectly fine

Most QR codes are honest shortcuts: the menu printed on your table, your boarding pass, the church bulletin, the museum placard, the codes on my own printed handouts that point to this site. The pattern behind the safe ones — you sought them out, in a place you chose, from a source you know, and they don't ask for money or a password. The one-question test: did I come to this code, or did it come to me? The second kind is the kind to skip.

What's in the printable PDF

  • What a QR code actually is — and what it can and cannot do to your phone.
  • When QR codes are normal and fine (menus, boarding passes, tickets) — the one-question test.
  • How "quishing" works, and the real one-letter-off fake parking site.
  • The FTC and FBI alerts, dated and summarized in plain English.
  • The parking-meter sticker trick — real cases from Redondo Beach, Fort Lauderdale, and Denver.
  • QR codes in emails, mystery packages, texts, and official-looking letters.
  • What your iPhone's yellow banner shows you — and Android's honest weak spot.
  • Judging a web address in five seconds, with a table of real examples.
  • The 10-second sticker check and Bill's five QR rules.
  • A calm triage page: what actually happened when you scanned, step by step.
  • The cleanup checklist if you typed anything in, plus where to report.
  • A cut-out wallet card, a fridge cheat sheet, and every help number you'd want.

Why I wrote this

I bring printed guides to senior-center talks, and QR codes come up every single time — usually as "should I just never scan those things?" The honest answer is no. The codes are fine; the fake stickers and surprise emails are the problem, and the defense is a five-second reading habit, not a lifestyle change. I wrote this one so you could stop worrying about every square of black-and-white dots and start recognizing the three or four situations that actually deserve suspicion. — Bill

Want a scam-check visit?

I'll come to your kitchen table for $99 flat — we'll practice scanning codes we trust so you see exactly what your phone shows, update the phone, turn on two-factor for email and bank, and walk this guide's checklist together. 30-day follow-up included. And a "is this a scam?" phone call is always free.

📞 Call (330) 200-8042 📅 Book a $99 Visit

This guide is yours, free.

No sign-up, no email, no catch — it's free the way it looks free. Print it, save it, or share it with family. And if you'd rather hand the job off, Bill's two choices are right above: a $99 flat in-home visit or $49 remote help, often same day.

✍️ Every guide written by Bill — your local Portage County tech, not a content farm.