Morning Overview

Scam QR codes pasted over the real ones can send your payment straight to a thief

The black-and-white squares now printed on restaurant tables, parking meters and package labels have made everyday transactions faster, but they have also handed criminals a nearly invisible tool. Because a QR code reveals nothing about where it leads until a phone opens the link, scammers have learned to paste their own codes over legitimate ones or slip them into unexpected messages. A single careless scan can route a payment to a thief or open a spoofed page built to harvest logins and card numbers.

The trouble with a code that hides its destination

A QR code is simply a machine-readable link, and that is the heart of the problem: the human eye cannot tell a genuine code from a malicious one. When a phone’s camera decodes it, the device may jump to a website, launch a payment or prompt a download, often before the person has any chance to judge whether the destination is trustworthy.

The Federal Trade Commission has warned that scammers hide harmful links inside QR codes to steal personal information. Some criminals cover the real code on a parking meter or public sign with a sticker of their own, while others send codes by text or email, betting that curiosity or urgency will win out over caution.

Overlay stickers on meters and payment terminals

The overlay trick is deceptively simple. In places where consumers expect to scan to pay, such as parking kiosks, transit signs or tabletop menus, a scammer prints a counterfeit code on an adhesive label and presses it directly over the authentic one. The victim believes they are paying a legitimate operator, but the money and any entered card details flow to the fraudster instead.

Because the tampered sticker sits exactly where a real code belongs, the setup looks entirely normal. That is what makes physical overlays effective: nothing about the surrounding sign seems out of place, and the payment page the code opens can be crafted to mimic a familiar service down to its logo and layout.

Codes delivered by text, email and surprise packages

Not every malicious code is physical. Scammers also embed QR codes in emails and text messages, frequently wrapped in a story designed to create pressure. A message might claim a package could not be delivered and must be rescheduled, or that an account password needs changing because of suspicious activity, each nudging the recipient to scan without thinking.

The FTC has separately flagged a scheme in which a QR code arrives on an unexpected package, inviting the recipient to scan to identify the sender or claim the item. Scanning can lead to a phishing site or trigger a malware download, turning a small mystery on the doorstep into a doorway for identity theft.

Legitimate delivery carriers and financial institutions generally do not ask customers to resolve an urgent problem by scanning a code embedded in an unsolicited message, so an unexpected code paired with a countdown or a threat is itself a warning sign.

How a scanned code turns into stolen data

Once a phone follows a malicious code, two main dangers unfold. The link may land on a spoofed website that looks authentic but is not, and any username, password or payment information typed into that page is captured by the scammer. Alternatively, the code can prompt the installation of malware that quietly siphons personal information from the device.

Either path can compromise far more than a single transaction. Credentials stolen through a spoofed login can unlock email or banking accounts, and malware on a phone may reach contacts, messages and stored data. The efficiency of the attack, one scan to a full compromise, is precisely why authorities urge consumers to slow down before scanning.

The scale of the problem has grown alongside the technology’s popularity. As QR codes became routine during the shift to contactless menus and payments, many people grew accustomed to scanning without hesitation, and fraudsters have exploited exactly that reflex. Payments specialists note that the codes are especially dangerous because they collapse several steps, opening a page, entering data and authorizing a charge, into a single motion that leaves little room for second thoughts.

Habits that keep a scan from becoming a scam

A few precautions sharply reduce the risk. Consumers should inspect any QR code found in an unexpected place, and at payment terminals check whether a sticker has been applied over the original. When a phone previews the underlying web address after a scan, it is worth pausing to read it, watching for misspellings, switched letters or a domain that does not match the expected company before proceeding.

At a physical terminal, favoring an operator’s printed instructions or an official app over a loose code adds protection, and if a code appears altered, curling at the edges or slightly misaligned, it is safer to report it to the business than to scan it.

Skepticism toward unsolicited codes is equally important. The FTC advises against scanning a QR code in an email or text that was not expected, especially one that urges immediate action, and suggests reaching the company through a known website or phone number rather than the link provided. Keeping a phone’s software current adds a further layer, since updates patch the vulnerabilities that malware from a rogue code might try to exploit.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview