Morning Overview

A QR code taped over a parking meter can send your payment straight to a scammer

A parking meter is one of the last places most drivers expect to be robbed, but a growing scam turns the meter itself into the bait. Thieves print a sticker bearing their own QR code and paste it over the legitimate code on a pay-by-phone sign or meter, so a driver who scans it to pay for parking is quietly routed to a fraudulent page instead of the real one. The payment never reaches the city, and the card details entered along the way land in a criminal’s hands.

The tactic, sometimes called quishing, works because QR codes are unreadable to the human eye. A person cannot tell a real code from a fake one by looking at it, and the surrounding signage looks entirely normal, so the deception hides in plain sight on a public fixture people already trust.

How a fake code hijacks a routine payment

The scam exploits the gap between scanning and seeing. When a driver points a phone camera at the tampered code, it opens a website engineered to mimic a parking-payment portal, complete with fields for a license plate, a duration, and a credit card. Federal regulators have warned about this exact substitution: the Federal Trade Commission’s guidance on malicious QR codes notes that scanning a scammer’s code can send a person to a phishing website built to steal personal information such as credit card numbers and login credentials, or push malware onto the device.

Because the fake page often mirrors a real payment flow, the victim may believe the transaction succeeded. In some versions the site signs the driver up for recurring charges rather than a single parking session, so the theft continues long after the car has left the space. The card number captured in the process can then be used or sold independently of the parking charge itself.

Cities are posting their own warnings on the meters

Local transportation agencies have started responding directly, in part because the fraud undermines confidence in legitimate pay-by-phone systems. New York City’s Department of Transportation issued a parking-meter scam advisory alerting drivers that its municipal meters do not accept payment through QR codes at all, meaning any code stuck to a city meter inviting a scan is by definition illegitimate. That detail is a powerful tell: where an agency never uses codes, the presence of one is the scam.

The advisory underscores a broader point that varies by city. Some municipalities do use official apps and codes while others rely only on card readers, coin slots, or a specific phone number, so the safest habit is to know how a given jurisdiction actually collects payment rather than trusting whatever sticker happens to be on the machine.

Why QR fraud has spread beyond parking

Parking meters are only one venue for a technique criminals are deploying wherever a scan can be inserted into a transaction. The FBI has documented related schemes, including a wave in which fraudsters mailed unsolicited packages containing QR codes used to initiate fraud, betting that curiosity would lead recipients to scan a code that opened a malicious site. The common thread is that the code offloads the deception onto a machine-readable link the target cannot vet.

Restaurants, event flyers, packages, and email attachments have all become vectors, which is why security guidance increasingly treats an unexpected or physically altered QR code the way it treats a suspicious link in a text message. A summary of the FBI’s smartphone-scam warnings places quishing alongside other phone-based fraud that leans on urgency and everyday convenience to bypass a target’s caution.

The habits that keep a scan from becoming a theft

A few simple checks defuse most of these attempts. Before scanning a code on a public fixture, it is worth inspecting the surface for a sticker sitting on top of the original, since the fraudulent code is often literally pasted over the real one and can sometimes be peeled at a corner. After scanning, the destination web address deserves a look: a misspelled domain, an unfamiliar payment processor, or a page that does not match the parking operator’s real site are all reasons to stop.

Skipping the code entirely is often the strongest move. Paying at the meter’s card reader, using a parking app downloaded directly from an official app store rather than from a code, or dialing a phone number printed and verified independently all remove the tampered sticker from the equation. Anyone who did enter card details on a suspect page should contact the card issuer immediately and report the incident, which regulators route through the FTC’s fraud portal and, where a cybercrime component exists, the FBI’s complaint center.

This article was researched and drafted with the assistance of AI and reviewed before publication.


More from Morning Overview