Morning Overview

A surge in QR-code phishing is hitting parking meters and mailers, and the FBI says to look twice

A form of fraud known as “quishing” is spreading through everyday public spaces, with criminals slapping counterfeit QR codes over legitimate ones on parking meters and mailing fake codes to households disguised as official notices. Because a QR code is just an unreadable block of squares to the human eye, a malicious one is easy to disguise and hard to spot, and a single scan can route a phone to a fraudulent website built to harvest payment details or login credentials. Federal law-enforcement and consumer-protection agencies are urging the public to slow down and look twice before pointing a camera at any posted code.

Why parking meters and mailers became targets

Quishing works because it exploits the moment of convenience QR codes were designed for. On parking meters, scammers apply a sticker bearing their own code directly over the city’s official one. A driver in a hurry scans it, lands on a convincing but fake payment page, and enters a card number that goes straight to the fraudster rather than to the municipality. Cities including Austin, Houston, and San Antonio have reported such sticker overlays, prompting local warnings to pay through official apps or the meter’s card reader instead.

Physical mail has become a parallel channel. Fraudsters send letters and postcards printed with QR codes and framed as delivery notices, toll balances, account alerts, or government correspondence, counting on the printed format to lend an air of authenticity. The Federal Trade Commission has cautioned that scammers frequently hide harmful links inside QR codes that appear on parking meters, in unexpected packages, and in text messages posing as failed-delivery notifications.

What a scanned code can do

Following a malicious QR code can trigger several outcomes. The most common is a spoofed login or payment page designed to steal credentials or card data. Others prompt the download of malware, or open a pre-filled message or payment request. Because the destination address is hidden until the code is scanned, the usual advice to inspect a link before clicking is harder to apply, which is exactly what makes the technique effective. The core of the scam is a classic phishing playbook wrapped in a new delivery method, and the FTC’s general guidance on how to recognize and avoid phishing scams applies directly: unexpected requests for personal or financial information should be treated with suspicion regardless of how they arrive.

The FBI’s role and the scale of the problem

The FBI has folded QR-code fraud into its broader consumer warnings and collects reports through its Internet Crime Complaint Center. The bureau’s IC3 portal serves as the central intake point for victims and a source of alerts about emerging online schemes, and the agency has specifically flagged malicious QR codes as a tactic used across both financially motivated and state-linked operations. Security researchers tracking the trend have reported steep increases in quishing attempts, underscoring that the technique is scaling quickly rather than fading.

Coverage from outlets such as Fox News has documented how the same method has been adopted in more sophisticated intrusion campaigns, illustrating that QR abuse ranges from opportunistic street-level theft to targeted espionage. The common thread is that a code offers no visible clue about where it leads.

How to scan more safely

Investigators recommend a few consistent habits. Before scanning a code in public, a person can check for a sticker layered over the original surface, a hallmark of the parking-meter scam. When a phone previews the destination address after scanning, that address should be examined for misspellings or a domain that does not match the expected agency or company. The safest approach for payments is to type a known web address or use an official app rather than relying on a posted code at all. Codes arriving unsolicited by mail, text, or email deserve particular skepticism, since legitimate organizations rarely require a scan to resolve an urgent account or delivery issue.

Anyone who suspects they have scanned a fraudulent code and entered information is advised to contact their bank promptly, monitor accounts for unauthorized charges, and file a report with the FBI’s Internet Crime Complaint Center. The recurring guidance from federal agencies is that a QR code deserves the same scrutiny as a link in a suspicious email, because functionally that is exactly what it is.

Businesses and cities respond

Municipalities and companies have started adjusting how they use QR codes in response to the fraud. Some cities have removed codes from parking meters altogether or added tamper-evident features, while security teams at businesses warn staff that codes arriving by email deserve the same suspicion as any unexpected attachment. Payment processors and app makers have added preview screens that display a code’s destination before a browser opens it, giving people a chance to catch a mismatched address. None of these measures fully closes the gap, because the technology depends on people scanning codes they encounter in the wild, but together they chip away at the ease that made quishing attractive to criminals in the first place.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview