Morning Overview

A stranger’s QR sticker slapped over a parking meter can hijack your payment

Paying for street parking with a phone has become second nature in many cities, and a small square of black-and-white code is often all it takes. That convenience has opened a low-tech opening for fraud: a criminal can print a fake code, peel a sticker, and paste it directly over the real one on a meter, quietly rerouting every scan to a page they control.

The trick requires no hacking and no special equipment. It exploits a simple fact about QR codes, which is that a human cannot read one by looking at it. A tampered code and a legitimate one appear identical to the eye, so a driver in a hurry has no obvious way to tell that a scan is about to lead somewhere dangerous.

How a sticker turns into a trap

The scheme unfolds in a few seconds of ordinary behavior. A person scans the code on the meter, is sent to what looks like a parking-payment site, and enters a card number to cover an hour of parking. Instead of paying the city, the details flow to a fraudster. The Federal Trade Commission warns in a consumer alert that scammers hide harmful links in QR codes to steal information, and covering a real code with a fake one is among the tactics it describes.

Beyond a single bogus charge, the counterfeit page can enroll a victim in recurring payments or simply bank the card number for later use. Some fake pages also ask for extra details such as a home address or phone number, widening the haul from a single scan.

Where the fake codes turn up

Parking meters are a favorite target because they sit unattended in public and invite quick, low-value payments. The same approach has surfaced on electric-vehicle charging stations, gas pumps, and other self-service terminals where a code is the expected way to pay. Reports of altered meter codes have prompted transportation departments in several cities to inspect their equipment and post warnings.

The broader FTC scam resources group this with other QR-based cons, including codes sent by email or text and codes placed in unexpected spots, all built on the same weakness of a scannable link that hides its true destination.

Spotting a tampered code

A close look often reveals the tampering. A sticker placed on top of a printed code may show a raised edge, a slight misalignment, or a different finish from the surrounding surface. Peeling corners, a code that sits crookedly, or a second code layered over another are all reasons for suspicion.

The destination itself is another checkpoint. After a scan, most phones display the web address before opening it, and an official municipal payment site will usually carry a recognizable government or vendor domain rather than a random string of characters. A mismatch there is a strong cue to stop before entering any card information.

Safer ways to feed the meter

Officials suggest treating any on-device code with a measure of caution and favoring payment paths that do not depend on a sticker at all. Many cities support an official parking app downloaded from a trusted app store, a phone number printed on the meter, or coins and cards accepted directly by the machine. Those routes bypass the pasted-on code entirely.

When a scan is used, pausing to read the previewed link before tapping through catches most fakes. Typing a known parking-payment address by hand, rather than trusting the code on the pole, removes the risk that a stranger’s sticker is standing between a driver and the real payment system.

Why this scam is hard to stamp out

The appeal for criminals is that the method costs almost nothing and can be redeployed instantly. A stack of printed stickers is cheap, applying one takes moments, and a removed fake can be replaced the next day. Enforcement is difficult because the physical evidence is easily peeled away and the fraudulent page can be hosted anywhere.

That durability is why consumer regulators keep the guidance simple and repeat it often. The specific locations shift from meters to chargers to pumps, but the core defense stays the same: verify where a QR code actually leads, and never assume that the square on a public terminal is the one that was supposed to be there.

How businesses can reduce the risk

The burden does not fall on the public alone. Cities and private operators that rely on scannable codes have been urged to inspect their equipment regularly, use tamper-evident materials, and print codes directly onto durable surfaces rather than on easily swapped stickers. Some agencies have added engraved or protected codes that are harder to cover without leaving obvious damage.

Clear signage also helps, including posted notices that list the official payment website and warn that no legitimate code will ever be an add-on sticker. When operators make the real payment path obvious and easy to verify, a fraudulent overlay has a harder time blending in, which shrinks the window in which a pasted-on code can quietly collect card details.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview