Skip to main content

Morning Overview

A fake QR code slapped over a parking meter can quietly steal your card details

A small square sticker pressed over the real code on a parking meter or a restaurant table looks harmless enough that most people scan it without a second thought. That sticker is often the entire scam. A quick-response code cannot be read by the human eye, so nothing about a swapped one looks obviously wrong until a phone opens a payment page that was never affiliated with the meter, the restaurant, or the city at all, and by then a card number has already been typed in.

Why a Printed Square Became a Trusted Shortcut

Quick-response codes were originally developed in the automotive industry for tracking parts on assembly lines, and only later spread into restaurant menus, parking payments, event tickets, and package labels because they let a phone jump straight to a link without anyone typing a web address by hand. That convenience is exactly what makes the format easy to weaponize, since a scanned code can point anywhere its creator chooses and the actual destination stays invisible until after the tap.

A printed sticker with a fraudulent QR code costs almost nothing to produce and can be slapped over a legitimate code on public infrastructure in a matter of seconds, which is why the scam has spread fastest in places where people are already in a hurry, such as parking lots, transit stops, gas pumps, and curbside pickup signs where a code is expected and rarely inspected closely.

How the Redirect Actually Steals Card Information

Scanning a tampered code typically opens a webpage built to closely resemble a real payment portal, complete with a familiar logo, matching color scheme, and a form asking for a card number, expiration date, and billing zip code. Because the page loads inside a phone’s browser rather than a dedicated app, few of the visual cues people rely on to judge a website’s legitimacy, such as a padlock icon or a recognizable layout, are easy to check on a small screen while standing at a meter.

Security researchers have used the term quishing, a blend of QR and phishing, to describe this specific redirect-based version of the scam, distinguishing it from traditional email-based phishing attempts. The information typed into the fake form goes straight to the scammer rather than to any parking authority or business, and by the time a charge appears or a card gets used elsewhere, the sticker that started it all has often already been peeled off or covered by the next one.

Where the Codes Get Swapped Most Often

Parking meters and pay-by-app signage are common targets because drivers are often rushed and expect to be sent to a payment page anyway, so nothing about the flow feels unusual even when the destination has quietly changed. Outdoor advertising, transit stop notices, and even fake parking tickets left on windshields have also been used to plant a malicious code somewhere a driver is likely to scan without hesitating first.

Restaurants that switched to code-based digital menus during the broader shift away from printed paper menus present a similar opening, since a code taped to a table can be swapped without staff noticing for days at a time. Package delivery notices left at a door have carried fake tracking codes for the same reason: they arrive at a moment when someone is primed to scan first and think about the source only afterward, if at all.

Spotting a Code That Has Been Tampered With

A sticker that sits slightly raised, is a different shade of white than the surface around it, or is positioned imperfectly over a printed original are the physical tells that a code has been swapped rather than officially placed there by the meter’s operator or the restaurant. A code that redirects to a shortened or unfamiliar web address rather than a recognizable municipal or business domain is the digital equivalent of that same red flag, and most phones display that destination briefly before fully loading the page.

Typing a parking meter’s payment website directly into a browser instead of scanning the code, or using the meter’s official app if one exists, sidesteps the risk entirely, since both routes bypass whatever sticker might be covering the original code on the pole or display.

Why Cities and Businesses Struggle to Prevent It

Parking authorities and restaurants generally rely on periodic manual inspection to catch a swapped code, since there is no automated way for a sign or a meter to detect that a sticker covering part of its surface leads somewhere unintended. Some municipalities have responded by switching to codes embedded directly into the metal of the meter rather than printed on a removable label, or by adding a second verification step on the payment page itself, though both changes require budget and time that many local governments have been slow to allocate.

Signage warning the public to double-check a scanned destination before entering payment details has become more common in transit stations and parking structures, but that kind of warning depends entirely on someone noticing and reading it in the middle of an otherwise routine errand.

Protecting Payment Information After a Scan

Most phones now show a preview of a scanned code’s destination before actually opening it, and reading that preview before tapping through is the single most effective habit against the scam, since it costs nothing and takes only a second longer than scanning blindly. Declining to enter card details on any page reached through a scanned code, and instead navigating separately to a business or agency’s known website, closes off the trick almost entirely regardless of how convincing the fake page looks.

The same caution that protects contactless payment methods more broadly applies here: a payment request is only as trustworthy as the source that issued it, and a code stuck onto a public surface with tape or an adhesive sticker is not a source anyone actually verified before handing over a card number.

This article was produced with the assistance of AI and reviewed by Morning Overview editors.


More from Morning Overview