Skip to main content

Morning Overview

A fake QR code stuck over a real one can lead straight to malware

A parking meter that looks perfectly ordinary can still be running a scam if someone has pasted a counterfeit QR code directly over the real one. The Federal Trade Commission says it has fielded reports of exactly that setup: a sticker carrying a fraudulent code laid over a city meter’s legitimate one, so a driver’s phone camera reads the wrong link entirely. Scanning it can send a payment to a stranger’s account instead of the parking authority, or open a page built to harvest whatever gets typed into it, including a saved card number.

The trick is not confined to meters. Federal investigators have tied the same swap to shipping notices, restaurant menus, and flyers pinned to community bulletin boards, anywhere a printed code can be covered without anyone noticing before the next person scans it. What makes the scheme durable is how little it costs to run: one sticker, one printed code, and a public surface that hundreds of strangers touch every day without a second thought. A phone camera cannot tell a forged sticker from a printed original, so the only real check happens after the scan, when a preview link either matches the business a person expected or does not.

Parking meters remain an easy mark

The FTC first documented the parking-meter version of the scheme in December 2023, warning that scammers had begun covering legitimate codes with counterfeit stickers of their own. The agency’s consumer protection staff repeated the same warning in a September 2026 alert, writing plainly that “people have reported scammers covering up legit QR codes on parking meters with a QR code of their own.” A meter offers everything a scammer needs — a public surface, a driver trying to pay quickly, and no easy way to tell a printed sticker from the city’s original code.

The financial risk goes beyond one wasted payment. A scammer’s landing page collects whatever card number a driver enters to “pay,” and that number can be resold or reused elsewhere long before a monthly statement shows the unauthorized charge.

Packages that arrive with a note instead of a name

A newer variation swaps the meter for the mailbox. The FTC’s January 2025 alert on unexpected packages describes boxes that show up with no return address and a note asking the recipient to scan a QR code to learn who sent it or how to send it back. It is a twist on the long-running “brushing” scheme, and under federal mail rules a recipient can legally keep an unsolicited package no matter what the note claims.

Federal investigators have logged versions that skip the mailbox step entirely. The FBI’s Internet Crime Complaint Center warned in 2022 that criminals were tampering with QR codes on both digital and physical surfaces to “redirect victims to malicious sites that steal login and financial information,” and the bureau flagged the unsolicited-package variant again in 2025, describing codes that push a recipient toward handing over personal and financial details or unknowingly installing software that pulls data off the phone.

What a scanned code can quietly install

The mechanics are simple once a phone reads the wrong link. A scammer’s code can open a spoofed website built to look nearly identical to a familiar one, and logging into that page hands over whatever gets typed there — a password, a card number, an account PIN. Some codes skip the fake login screen altogether and push a small program onto the device that starts pulling data before the phone’s owner notices anything wrong.

Quishing, as researchers have taken to calling QR-based phishing, rides on a much bigger wave of the same fraud. An HHS white paper on the tactic cites FBI complaint data showing phishing was the single most reported form of cybercrime in 2022, generating more than 300,000 complaints, and it put the average cost of a successful phishing attack the year before at $14.8 million across victims of every kind.

Reading the code before it reads back

The FTC’s own advice is mundane by design. Alvaro Puig, a consumer education specialist at the agency, recommends checking a scanned link for misspellings or swapped letters before opening it, especially when a code shows up somewhere unexpected, and reaching a company through a phone number looked up independently rather than one pulled from the code itself. Software updates and multi-factor authentication round out the same list, precautions that matter less for stopping a scan and more for limiting what a bad one can steal once a device or password has been exposed.

Both agencies keep their reporting instructions simple. Anyone who scans a bad code and enters a password should change it right away, and anyone who loses money to one can file a report with the FTC or with the FBI’s Internet Crime Complaint Center, the same channel that first cataloged the tampered-code scheme back in 2022.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview