Morning Overview

Scammers are pasting fake QR codes over parking meters to hijack your phone and wallet

Drivers in New York City who scan a QR code on a parking meter to pay could end up handing their credit card details directly to criminals. The New York City Department of Transportation discovered that scammers affixed at least one fraudulent QR-code sticker to a ParkNYC meter, routing unsuspecting motorists to a third-party payment page designed to harvest financial information. The scheme, which has also surfaced in other cities, has drawn warnings from federal agencies including the FBI and the Federal Trade Commission.

How fake stickers on parking meters steal credit card data

The tactic is deceptively simple. Criminals print adhesive QR codes that mimic legitimate payment prompts and paste them directly over official signage on parking meters. When a driver scans the sticker with a phone camera, the code opens a website that looks like a real payment portal but is controlled by the scammer. Any credit card number, expiration date, or personal detail entered on that page goes straight to the fraudster rather than to the city’s parking system.

NYC DOT confirmed that it identified at least one such sticker on a ParkNYC meter and immediately notified law enforcement, according to the agency’s parking advisory. The city also began remediation steps to remove the fraudulent codes and alert the public. New York is not an isolated case. Sunny Isles Beach, Florida, discovered counterfeit QR codes on its PayByPhone signs and parking meters during routine inspections, and the city stated clearly that its official notice explains that its parking system does not use QR codes at all. That distinction gave inspectors an immediate way to flag the forgeries.

The FBI’s Internet Crime Complaint Center outlined the broader mechanism in a public service announcement: criminals replace legitimate QR codes, including through stickers, to redirect victims to malicious sites where they can steal login credentials, intercept payments, and in some cases deliver malware to the victim’s device. The FTC echoed those findings, explicitly warning that scammers have been covering parking-meter QR codes with their own codes to steal information. Both agencies emphasize that the visual appearance of a QR code reveals little about where it actually leads, making it easy for a counterfeit to pass as authentic.

Federal and city agencies tracing the same playbook

What makes this scam effective is how naturally it fits into a routine transaction. Millions of people already use mobile payment apps to feed parking meters, and scanning a QR code feels like a normal step. Scammers exploit that trust and the pressure of the moment. Drivers are often double-parked or standing on a busy curb, focused on avoiding a ticket rather than scrutinizing a web address.

The FBI’s IC3 alert laid out how the technique works across settings beyond parking: tampered QR codes can appear on restaurant menus, flyers, event posters, and even within emails. But parking meters present a particularly attractive target because the victim is almost guaranteed to be using a phone and a payment card within seconds of scanning. That combination of urgency and habit lowers the chance that someone will notice a slightly unfamiliar URL or an off-brand design on the payment page.

NYC DOT responded by setting up a formal reporting channel. The city’s 311 service page now instructs anyone who spots a suspicious QR code on a ParkNYC meter to contact ParkNYC support, helping the agency track the scope of the problem and remove fraudulent stickers before more drivers are victimized. In Sunny Isles Beach, officials directed residents to call the city hotline or the police non-emergency number to file reports, and reiterated that any QR code on a meter should be treated as a red flag.

The FTC’s consumer alert offered a practical verification step that applies regardless of city: before scanning any QR code in a public space, check whether the code appears to be a sticker placed over another code or sign. If it does, do not scan it. Instead, go directly to the official payment app or website by typing the URL manually or using a bookmarked link. Even if the code looks professionally printed, a slightly crooked placement, mismatched colors, or a different material from the surrounding sign can signal tampering.

Gaps in detection and what drivers should do first

Several questions remain open. Neither NYC DOT nor Sunny Isles Beach has disclosed how many drivers actually entered payment information on the fraudulent pages, so the financial damage is still unclear. Law enforcement has not publicly identified suspects or criminal networks behind the stickers. And because QR-code stickers can be printed cheaply and applied in seconds, the speed at which new fakes appear may outpace the pace of routine inspections.

There is also no centralized national tracking system for QR-code parking scams. The FBI’s IC3 collects cybercrime complaints, and the FTC fields consumer reports, but those databases rely on victims recognizing they were scammed and choosing to file a report. Many drivers may not realize their card was compromised until fraudulent charges appear on a statement days or weeks later, making it difficult to connect the theft to a specific parking meter or to a single city.

For anyone who parks on a metered street, the most direct protection is to avoid scanning QR codes on meters entirely unless the city’s official parking app or website confirms that QR codes are a legitimate payment method. In cities like Sunny Isles Beach, where the municipality has stated it does not use QR codes for parking payments, any code on a meter is by definition fraudulent. In New York, the ParkNYC app can be downloaded directly from an official app store, bypassing any need to scan a physical code on the street.

Drivers who suspect they may have entered card details on a fraudulent site should act quickly. The first step is to contact the card issuer or bank, explain that the information may have been exposed through a fake parking payment page, and ask the institution to monitor for unauthorized charges or issue a replacement card. Many banks can also add extra verification steps for online purchases, reducing the chance that stolen data can be used immediately.

It is also wise to review recent statements for small “test” charges, which criminals sometimes run before attempting larger transactions. Any unfamiliar transaction, even for a few dollars, should be disputed. Victims can then file a complaint with the FBI’s IC3 and report the incident to the FTC, which helps investigators see patterns across cities and spot emerging versions of the scam.

On the ground, drivers can take a few seconds at the meter to check for signs of tampering. If the QR code looks like a sticker, if there is residue around the edges, or if the design style does not match neighboring meters, it is safer to avoid scanning. Using the official app or paying at the meter with a card or coins may feel less convenient in the moment, but those options cut scammers out of the loop.

City agencies, for their part, are likely to face ongoing challenges as QR codes become more common in public infrastructure. Clear signage explaining official payment methods, regular inspections of meters and kiosks, and public-awareness campaigns can all reduce the pool of easy targets. But as long as a QR code can be printed at home and slapped onto a sign in seconds, drivers will remain the last line of defense-and the ones who must decide whether a quick scan is worth the risk.

More from Morning Overview

*This article was researched with the help of AI, with human editors creating the final content.