Drivers pulling into a metered lot increasingly encounter a small square sticker promising a fast, contactless way to pay. The convenience is genuine, but so is the danger: a printed code is trivial to forge and easy to paste directly over a legitimate one. What looks like a shortcut to a parking payment can instead hand a stranger the keys to a bank account.
The tactic has a nickname among security researchers, “quishing,” a blend of QR and phishing, and it exploits an obvious blind spot. A person cannot read a QR code by eye, so there is no way to distinguish a genuine payment link from a malicious clone until a phone has already loaded whatever destination the pattern encodes.
How the sticker swap works
The mechanics are low-tech and cheap. Scammers print a batch of counterfeit codes and place them over the real ones on meters, pay stations, and posted signs. In one widely reported case in Redondo Beach, California, fake codes turned up on roughly 150 meters, glued alongside legitimate labels so that they blended in with official branding, according to reporting compiled by ABC7. Because the stickers sit exactly where a driver expects to find a payment prompt, few people look twice.
Once scanned, a rigged code routes the phone to a lookalike website built to imitate a real parking service. The address is often a near-miss on a legitimate one, swapping or dropping a single letter so that a brand such as PayByPhone becomes something like “poybyphone.” The page then asks for a location, a license plate, and a credit card number, capturing everything a criminal needs to run charges or resell the details.
Why the payoff is so large for scammers
A single successful scan can produce more than one fraudulent transaction. Some fake pages sign the victim up for recurring payments rather than a one-time parking fee, so the losses continue quietly for weeks. Others go further and attempt to install malware, which can turn a phone into a tool for stealing passwords or lock the device until a ransom is paid. The Better Business Bureau warns that these parking-lot codes are especially effective because drivers are usually in a hurry and primed to pay quickly, a point it lays out in its consumer scam alert.
The economics favor the criminal. Printing stickers costs almost nothing, the codes can be deployed across an entire city block in minutes, and each one keeps working until someone notices and peels it off. That combination of low cost and long shelf life is why the approach has spread from parking meters to restaurant tables, package-delivery notices, and flyers stapled to public poles.
The tells that give a fake code away
Several warning signs separate a legitimate code from a trap. A sticker layered on top of another sticker is a red flag, as is any code that peels at the edges or appears freshly applied over faded official signage. After scanning, the destination address deserves a careful read, because misspellings, extra words, and unfamiliar domains are the clearest sign of a spoof. A payment page that demands more information than a parking transaction should need, such as a full home address or a Social Security number, is another signal to close the browser immediately.
The FBI has cautioned that tampered codes are among the simplest ways for criminals to redirect victims to malicious sites, and it urges people to inspect both the physical code and the web address it opens before entering anything, guidance echoed in a public service announcement from its Internet Crime Complaint Center. Treating every posted code as unverified until proven otherwise is the safest default.
Safer ways to pay and report a fake
The most reliable defense is to bypass the sticker entirely. Many parking systems can be reached by typing the operator’s known web address directly into a browser or by opening the company’s official app, both of which avoid the code altogether. Calling the phone number printed on the meter itself, rather than one shown on a scanned page, offers another route that a counterfeit code cannot intercept.
Federal consumer regulators recommend confirming the website a code leads to before acting, watching for the switched or missing letters that mark an impostor domain, according to the Federal Trade Commission’s consumer alert on the subject. Anyone who spots a suspicious code can report it to the operator so the sticker gets removed quickly, and a victim who has already entered payment details should contact the card issuer to dispute charges and watch for recurring ones. Reporting the incident to authorities also helps investigators connect scattered stickers to the larger operations behind them.
The broader lesson is that a QR code is not inherently trustworthy simply because it appears in an official-looking spot. The pattern is only a link in disguise, and links posted in public places carry the same risks as any unsolicited message. A few seconds of skepticism, spent checking the address on the screen and the sticker on the meter, is enough to keep a routine parking stop from turning into a fraud report.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview