Skip to main content

Morning Overview

Scammers are pasting fake QR stickers over parking meters to hijack your payment

A driver pulls into a metered spot, glances at the small QR code posted on the meter, and scans it the way thousands of cities now encourage people to pay for parking. Nothing about the sticker looks out of place, because it was designed not to. Federal regulators say that in a growing number of cases, that code is not the city’s at all; it is a counterfeit sticker pasted directly over the real one, sending the payment and the driver’s card details to a scammer instead of the municipal parking system.

The tactic has surfaced in multiple cities over recent weeks, prompting a nationwide consumer warning.

How a Sticker Swap Fools a Careful Driver

The mechanics of the scam are deliberately simple. Someone prints a QR code that visually matches a city’s official parking code, then physically covers the real sticker on the meter or nearby signage with the counterfeit one. According to a Federal Trade Commission alert, a driver who scans the altered code lands on a page built to resemble the city’s actual parking portal, complete with familiar branding and a payment form, but the page exists solely to collect card numbers rather than process a legitimate parking charge. Because the fake sticker sits in the exact spot a legitimate code would occupy, the scam does not rely on a suspicious link or a strange location, just a driver’s routine trust that the meter in front of them is what it appears to be.

Spreading From Big Cities to Smaller Ones

The pattern was first documented in larger metro areas with widespread QR-based parking payment systems, but local news coverage has tracked the scam moving into smaller cities as well, according to a report on the expanding warning. That spread mirrors how quickly a low-cost scam can scale once it proves effective: printing and placing a counterfeit sticker costs little, and a scammer can target dozens of meters across a city, or across several cities, in a single outing. The FTC’s alert did not limit its warning to any specific metro area, treating the risk as one that applies anywhere a municipality uses QR codes for parking payment rather than as a problem confined to one region.

Checking the Sticker Before Scanning It

Investigators point to a handful of physical warning signs that can distinguish a counterfeit sticker from an official one, starting with the sticker’s edges and placement: a code that appears layered on top of another sticker, sits slightly crooked, or looks like it was added after the meter was installed is worth treating with suspicion. Most smartphone camera and QR scanning apps display a preview of the destination web address before opening it, and checking that preview for a mismatched domain, an unusual spelling, or a switched letter can catch a fraudulent link before any payment information is entered. When in doubt, drivers can skip the code entirely and either pay directly at the meter’s keypad or open the city’s official parking app or website independently rather than following a link generated by scanning anything posted on-site.

Hardening the Phone Itself, Not Just the Habit

The FTC’s alert pairs its scanning advice with a device-level recommendation that is easy to overlook: keeping a phone’s operating system and apps current, since security patches close exactly the kind of vulnerabilities a malicious QR-code link is built to exploit. Apple and Google both publish standing guidance on installing these updates automatically rather than waiting for a periodic manual check, and the FTC alert links directly to both companies’ instructions. That guidance matters because a sticker-swap scam does not need a sophisticated exploit to work; it only needs a driver to scan a code and land on a page willing to accept whatever the phone’s browser and login defaults allow.

The agency’s second recommendation is standard account hygiene applied to a new context: using strong, unique passwords across financial and shopping accounts and turning on multi-factor authentication wherever it is offered, so a captured password alone is not enough for a scammer to get into an account. Multi-factor authentication requires a second proof of identity, typically a code sent to a phone or generated by an app, before a login succeeds, meaning a driver who reused a password on the fake parking page still has a second layer of defense if that password is later tried against a banking or email account.

What to Do After Scanning a Fraudulent Code

Anyone who has already entered payment information into one of these fake portals is advised to contact their card issuer to flag the charge and watch for follow-up fraudulent activity on the same account, since a captured card number can be reused or resold well beyond the initial parking charge. Reporting the incident through the FTC’s fraud reporting system feeds the details into a shared database that helps investigators identify clusters of similar reports tied to the same scammer or region. Notifying the city’s parking authority directly is also useful, since municipal staff can physically inspect and remove a counterfeit sticker once alerted, something the FTC has limited ability to do on its own beyond issuing public warnings.

A Broader Pattern in QR-Based Payment Fraud

Parking meters are only one setting where a physical QR code has become a target for tampering; security researchers tracking so-called “quishing” attacks have documented similar sticker-swap tactics on restaurant tables, event flyers, and public transit kiosks, anywhere a code is displayed in a fixed public location long enough for a scammer to alter it undetected. The common thread across these cases is that the fraud depends entirely on the code being trusted by default because of where it is posted, which is exactly why security guidance keeps returning to the same basic habit: treating a public QR code as something to verify, not something to scan automatically.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview