A text arrives with an image that looks like an official traffic-court notice, complete with a state seal, a case number, a hearing date and a QR code to “pay now” and make the whole thing disappear. It is not a court, there is no violation, and the QR code is the trap. Federal regulators say this particular scheme has spread quickly across the country, riding the credibility that government-style paperwork lends to an otherwise obvious con.
The scam belongs to a fast-growing category of fraud that swaps a clickable link for a scannable code, a tactic sometimes called quishing. The switch matters because a QR code hides its destination, sliding past the instinct many people have learned to apply to suspicious web addresses.
What the fake traffic notice actually says
The message opens with a picture of what appears to be an official notice of a traffic hearing, and the Federal Trade Commission has reported a spike in complaints about it, the agency said. The notice typically carries a seal from whatever state it claims to represent, a fabricated case number, and a scheduled hearing date and time. It then offers two options designed to feel like a genuine legal choice: appear at the invented hearing, or settle the balance immediately by scanning the embedded code. To force a quick decision, the text lists consequences for inaction, including default judgments, additional fines and enforcement action.
Every element is manufactured. The urgency, the legal jargon and the official styling exist to short-circuit skepticism, pushing the recipient to scan before checking whether any of it is real.
Why the QR code is the dangerous part
Scanning the code does not open a court portal. It leads to a fraudulent site engineered to steal personal information such as a Social Security or credit card number, to install malware on the phone, or to take money outright. The FTC has documented how malicious software delivered this way can quietly compromise a device and the accounts accessed from it, the commission explains. Reports of the scheme describe a chain of decoy pages, often a fake identity check followed by a bogus payment screen requesting a small fee and full card details, and outlets covering the wave have noted texts hitting drivers across multiple states, and consumer reports describe the same multi-page trap.
How real traffic citations are handled
Legitimate courts and motor-vehicle agencies do not collect fines through a QR code texted to a phone, and they do not threaten immediate arrest or enforcement over an unpaid ticket via SMS. Genuine violations generate mailed paperwork or notices tied to an account a driver can verify through an official government website. The mismatch between how courts actually operate and how the scam text behaves is one of the clearest signals that the message is fraudulent, no matter how polished the image attached to it looks.
What to do with the message
The recommended response is straightforward: do not reply, and do not scan the code. Anyone who suspects a message might be legitimate should look up the relevant court independently and confirm case information through a phone number or website they know is genuine, never contact details supplied by the text itself. Unwanted messages can be reported by forwarding them to 7726, which spells SPAM, and by filing a complaint at ReportFraud.ftc.gov. For those who already scanned the code or entered payment details, the FTC lays out concrete recovery steps, from contacting the card issuer to watching for identity theft, in its guidance for people who were scammed.
A tactic built for a QR-code world
The traffic-ticket text works because QR codes have become ordinary. They appear on restaurant tables, parking meters and event tickets, and scanning one has stopped feeling risky. That familiarity is exactly what the scam exploits: a code carries no visible address to inspect, so the usual habit of hovering over a link to check where it goes does not apply. The defense is to treat any code that arrives with pressure and a demand for money the same way one would treat an unsolicited link, with suspicion first. A real obligation can always be confirmed through official channels; a scam only survives if the target acts before they check.
The decoy pages behind the code
The QR code is only the entrance. Descriptions of the scheme trace a chain of screens engineered to feel routine: a fake identity or security check that mimics the challenges people now see on legitimate sites, followed by a page requesting a small processing fee, and finally a form demanding full card and personal details to “resolve” the citation. Each step is designed to look like ordinary bureaucracy, lowering the target’s guard by the time the truly sensitive information is requested. The small fee serves a double purpose, capturing a live card number while making the transaction feel too minor to scrutinize.
Layering the theft this way also helps the operation evade suspicion. A single page baldly asking for a Social Security number would alarm many people, but a sequence that eases from a plausible checkpoint into a modest payment into a fuller form feels like a process rather than a heist. By the final screen, the target has already invested effort and begun to trust the flow, which is precisely the psychological state the design is meant to produce. Understanding that the entire journey is choreographed, from the official-looking image to the last form field, makes it easier to stop at the first step and never scan at all.
This article was produced with AI assistance and reviewed by Morning Overview editors.
More from Morning Overview