Skip to main content

Morning Overview

A sticker over a parking meter’s QR code can route your payment straight to a scammer, the FTC warns

Scammers are covering the genuine QR codes on parking meters with codes of their own, and a driver who scans the sticker to pay is sent to a counterfeit website built to steal money, personal information, or both. The Federal Trade Commission published the warning in a September 3, 2026 consumer alert, and local reports from Texas describe the same tactic on the street.

The sticker is the whole trick. Nothing about the meter is hacked, and nothing on the phone is compromised until the scan carries it somewhere.

A cheap sticker that changes where the money goes

A parking QR code is a promise that the square on the meter leads to the city’s payment page. Nobody can read a QR code with the naked eye, so the promise is enforced by nothing except the sticker’s position on the hardware. Scammers exploit that gap by printing their own code and pressing it over the real one, which is why the FTC’s alert, written by the agency’s Bureau of Consumer Protection staff, describes the fake code as leading to a site designed to steal money, personal information, or both.

The counterfeit page does not need to be clever. A driver in a hurry, already standing at the meter, expects to be asked for a plate number and a card, and that is exactly what the fake asks for.

Reporting from Texas puts a place name on the method. WUSA9 in Washington, D.C. described the stickers, which it calls quishing, as having surfaced in Austin, San Antonio and Houston, and quoted Parkmobile chief executive Jeff Perkins on how the fake pages give themselves away. According to that report, Perkins said the scammers often put up a dummy website meant to collect a driver’s details, and that a careful look at the page shows it does not really look legitimate. The D.C. Department of Transportation told the station that suspicious codes on District meters can be reported to 311 or the department’s call center for removal.

A related Houston fraud that uses paper instead of stickers

A second Texas scheme is worth keeping separate from the meter stickers, because the defense is different. Hoodline reported on September 27 that fake parking citations with QR codes are turning up on windshields in Houston. City officials told the outlet that Houston never uses QR codes to collect fines, that genuine tickets are printed on pink or red-and-white paper rather than plain white, and that real citations carry violation codes, enforcement agent names, badge numbers, dates, times and locations. Drivers can verify a citation number on the city’s own parking page instead of scanning anything.

The same story notes that the FBI warned in July 2025 about rising quishing schemes generally. Neither Houston’s officials nor the FTC tie the paper tickets to the meter stickers, and the shared element is only the QR code as a delivery vehicle.

The check the FTC says to make before tapping

The agency’s core advice takes seconds. Many QR readers show a preview of the link before opening it, and the alert tells readers to look at that preview for spelling mistakes or switched letters. A lookalike address, such as one with a swapped character in a parking company’s name, is the usual sign of a fake.

The preview is only as good as the eye reading it. A single transposed letter in a long address is easy to miss on a small screen in bright sun, and a driver who has to pay in the next two minutes is not in the best position to proofread. When the preview looks even slightly wrong, the safer move is to skip the sticker and pay by another route, such as the card reader on the meter itself or an app installed earlier from the official store.

The alert adds hygiene that limits the damage from any bad scan. It recommends updating the phone’s operating system and apps, using strong passwords with multi-factor authentication, and treating a strange payment page as a reason to close it rather than to interact with the people behind it.

Steps the FTC recommends once a code has been scanned

For a driver who has already scanned a suspect code, the FTC’s alert lists four moves: do not engage with the scammers through the fake site, change passwords immediately if any credentials were typed in, watch credit card and bank statements for charges nobody authorized, and file a report at ReportFraud.ftc.gov. The agency’s broader page on what to do after a scam points people who shared personal information toward IdentityTheft.gov and two-factor authentication.

The alert does not say how many meters have been tampered with or how much money drivers have lost, and none of the local coverage cited here gives a tally either. Reports filed at ReportFraud.ftc.gov are the FTC’s own route to building that count.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview