Drivers paying for street parking increasingly rely on a quick phone scan instead of coins or a card swipe, and criminals have noticed the opening that convenience creates. Federal regulators are warning that fraud rings are pasting counterfeit QR code stickers directly over the legitimate codes bolted to parking meters and signposts, quietly rerouting a routine payment into a scam. The trick works precisely because nobody thinks twice about scanning a code stuck to equipment they already trust.
How a Sticker Turns a Meter Into a Trap
The scheme described by the Federal Trade Commission is mechanically simple: someone prints a QR code that looks identical to the city’s official parking code, then physically covers the real one with it. A driver scans what appears to be the meter’s standard payment link, and instead lands on a page built to look like a municipal parking portal. From there, the fake site can collect a card number, a login, or a one-time payment that never reaches the parking authority at all. Because the sticker sits on real municipal hardware, in a location the driver did not choose and has no reason to distrust, the visual cues people normally rely on to spot fraud are absent.
The tactic is not limited to any one city or meter brand, which is part of what makes it hard to shut down. A single sheet of adhesive vinyl and a printed code are all it takes to convert a trusted piece of public infrastructure into bait, and a scammer can move to a new block, or a new city, as soon as a batch of stickers gets noticed and peeled off.
The Web Address Is the Giveaway, Not the Code Itself
Because a QR code is unreadable to the human eye until it is scanned, the only real check happens after the phone has already decoded it. Regulators recommend using the link preview most phone cameras and QR readers show before opening a page, and reading that address carefully for anything off: a misspelled city name, an extra word, a domain that ends somewhere other than where a city government site normally would. Scam pages are frequently built to imitate the real payment portal closely enough that a rushed glance will not catch the difference, which is why the preview step matters more than trusting the meter itself.
Keeping a phone’s operating system and payment or browser apps current is the other piece of that defense, since outdated software is more likely to let a malicious link actually execute something harmful rather than simply display a convincing but harmless-looking page.
Catching a Bad Charge After the Scan
For anyone who has already paid through a parking QR code, the recommended follow-up is to check the transaction that actually posted. A legitimate parking payment should show up as a charge from the city, the meter operator, or a recognized parking app, not from an unfamiliar merchant name or a round-number charge that does not match what was owed. A mismatch is a signal to contact the card issuer quickly, since disputing an unauthorized charge gets harder the longer it sits on a statement.
People who encounter one of these stickers, or who realize after the fact that they paid a fake code, are directed to file a report with the FTC, which feeds into the same database investigators use to track scam patterns across the country. Reporting a spotted sticker to the parking authority itself can also stop the next driver in line from scanning the same trap.
Why Physical Tampering Is Harder to Police Than Online Fraud
What sets this scam apart from most digital fraud is that it requires no hacking, no data breach and no phishing email; it only requires a printer and a few minutes of unsupervised access to a public meter. That low barrier makes it attractive to opportunistic actors who might not have the skills to run a more technical scam, and it means the fix largely falls on drivers checking links themselves rather than on a company patching a vulnerability. Cities can swap out meters or add tamper-evident seals over time, but until that hardware turns over, the sticker itself remains nearly impossible to distinguish from the real thing without pausing to read where it actually leads.
Why QR Payment Scams Keep Spreading Beyond Parking
Parking meters are only the latest venue for this style of fraud. The same sticker-over-code tactic has shown up on toll payment signs, gym check-in kiosks, restaurant tables that use QR codes for menus and bill splitting, and flyers posted in public spaces promising a discount or a giveaway. What ties those targets together is that each one trains people to scan first and think second, because the legitimate version of the experience is built to be frictionless. Fraud investigators say the parking-meter variation has proven especially effective because a driver worried about getting a ticket is under more time pressure than someone scanning a code at leisure, and time pressure is exactly what makes a person skip the verification step that would otherwise catch the fake.
That pattern is also why regulators keep issuing versions of the same warning across different settings rather than one blanket alert: the technical exploit barely changes from one venue to the next, but the psychological pressure that makes each version work depends heavily on the specific situation a person finds themselves in when they pull out their phone to scan.
This article was produced with AI assistance and edited by Morning Overview staff.
More from Morning Overview