A small sticker slapped over the legitimate code on a parking meter can be all it takes to redirect a driver’s phone straight to a fake payment page built to steal a credit card number. QR code scams, sometimes called “quishing,” have spread well beyond email inboxes and into everyday physical spaces like parking meters, restaurant tables, and public flyers, exploiting the fact that a QR code gives no visual clue about where it actually leads until a phone has already opened the link.
Why QR Codes Are an Ideal Tool for Scammers
A QR code is simply a machine-readable pattern encoding a piece of data, most often a web address, that a smartphone camera can scan and open automatically. Unlike a typed web address, which a careful reader can inspect for obvious signs of a scam, such as a misspelled domain name or an unfamiliar extension, a QR code’s destination is invisible until the phone has already loaded it, stripping away one of the most basic habits people use to avoid suspicious links.
That opacity is precisely what makes quishing effective in physical settings. A scammer does not need to hack into a parking authority’s payment system or intercept anyone’s data directly; they only need to print a sticker with a fraudulent code and place it over the real one, counting on the fact that most people scan and proceed without a second thought about whether the code has been tampered with.
How the Parking Meter Version of the Scam Plays Out
Parking payment systems have increasingly moved toward QR codes as a quick alternative to coins, apps, or phone-based payment lines, which has made meters and pay stations an especially attractive target for this kind of tampering. A driver scans what looks like an official code, is taken to a page designed to closely resemble the real municipal parking payment site, and enters a credit card number to pay for a spot, unaware the form is capturing that information for the scammer rather than an actual parking authority.
Because the fake page is often a close visual copy of a legitimate payment portal, and because drivers are typically in a hurry to pay and move on, the scam frequently succeeds without the victim noticing anything unusual until unauthorized charges appear on a statement later. The same tampering approach has also shown up on restaurant table tents advertising a menu or promotion, flyers claiming to offer a discount, and other everyday public signage where a fraudulent sticker can blend in easily.
Why This Scam Is Hard to Spot in the Moment
Traditional phishing training has taught people to hover over links, check sender addresses, and look for spelling errors before clicking, none of which translates well to a QR code encountered in a parking lot. There is no sender to inspect and no visible link text to scan for typos, only a printed square of black-and-white pixels that could be entirely legitimate or a scammer’s replacement sticker placed moments earlier.
Fraudulent codes can also appear virtually identical to the genuine version at a glance, since both are simply patterns generated from underlying data rather than something that looks visually distinct based on its source. That makes physical tampering, rather than any flaw in the QR code technology itself, the actual vulnerability scammers are exploiting.
How to Avoid Falling for a Fake QR Code
Security guidance generally recommends checking whether a QR code appears to be a sticker placed over another code, since tampering often leaves a visible edge, bubble, or slightly different material from the surrounding sign. Before entering any payment information after scanning a code in a public place, reviewing the web address that loads for obvious signs it does not match the official domain of the business or agency involved is one of the few checks still available after the fact.
Many parking authorities and municipalities also offer alternative payment methods, such as a dedicated official app or a phone number to call directly, which sidesteps the QR code entirely and removes the opportunity for a tampered sticker to intercept payment. Treating an unfamiliar QR code with the same caution as an unsolicited link in a text message or email, rather than scanning reflexively, remains the most effective way to avoid the scam altogether.
Why Quishing Has Spread So Quickly Since the Pandemic
QR codes saw a dramatic surge in everyday use once businesses adopted them widely for contactless menus, check-ins, and payments, a shift that normalized scanning random codes in public spaces without a second thought. That widespread comfort with QR codes created exactly the conditions scammers needed: a population accustomed to scanning first and thinking later, spread across countless public locations that are often unmonitored for long stretches of time, like parking meters, community bulletin boards, and outdoor signage.
The scam’s low cost of entry has also helped it spread. Printing and placing a sticker over an existing code requires no technical hacking skill and very little money, making it accessible to a far wider range of opportunistic scammers than more sophisticated forms of digital fraud, and giving the tactic a foothold in cities well beyond any single early outbreak, resembling the same opportunistic logic behind any everyday confidence trick.
What to Do After Scanning a Suspicious Code
Anyone who realizes after the fact that they may have entered payment details into a fraudulent page has options beyond simply worrying about it. Contacting the card issuer to flag the transaction and request a replacement card is generally the fastest way to limit damage, since most card networks offer fraud protections that can reverse unauthorized charges when reported promptly. Reporting the tampered code itself to the parking authority, property manager, or local police can also help get it removed before more people fall for it, since a single fraudulent sticker can affect dozens of scans before anyone notices it does not belong.
This article was produced with the assistance of AI and reviewed by Morning Overview editors.
More from Morning Overview
- 9 pickup trucks with a reputation for falling apart after 100,000 miles
- A cargo jet crashed after an engine and pylon separated during takeoff
- The largest genetic study of fibromyalgia found new risk factors rooted in the nervous system
- Toyota grabbed six of the ten spots on Consumer Reports’ most-reliable-cars list