Skip to main content

Morning Overview

The FTC says scammers are pasting fake QR codes over real ones on parking meters

A sticker pressed over the printed code on a parking meter is enough to reroute a driver’s card details to a stranger. The Federal Trade Commission put the tactic in front of consumers this month, warning that the code a driver scans to pay for a spot may not be the one the city installed.

In a September 3 consumer alert written by the staff of its Bureau of Consumer Protection, the agency reported that “people have reported scammers covering up legit QR codes on parking meters with a QR code of their own.” Scanning the substitute sends a phone to a fake website built to collect money and personal information, the alert says, and the page is now one of the FTC’s standing warnings about phishing.

A sticker over a sticker

The scheme depends on how ordinary the request already is. Many cities have added “scan to pay” prompts to meters and pay stations, so a code on a meter looks routine, and a driver in a hurry has little reason to question one.

Local officials have been describing the same pattern for months. Raleigh, North Carolina, told residents in January that counterfeit QR stickers had turned up on downtown meters and lots, and that the city only uses QR codes for parking violations and SkiData tickets in garages, according to WRAL’s report on the warning. A city spokesperson said crews removed the stickers quickly, which is also why the city could not say how many people had scanned one. Reader’s Digest, in a roundup of the FTC alert, cited a New Westminster, British Columbia, resident who lost $2,000 after entering card details on a fake payment page in August.

The trick is older than the parking version. The FBI’s Internet Crime Complaint Center warned in a public service announcement dated January 18, 2022 that “cybercriminals are tampering with QR codes to redirect victims to malicious sites that steal login and financial information,” and told readers to check whether a physical code has been covered by a sticker.

FTC checks for drivers at the meter

The FTC alert begins with advice to look at the destination before trusting it. Many QR readers show a preview of the destination link before opening it, the FTC noted, and drivers are told to confirm there are no misspellings or swapped letters in the address. A payment page that does not match the name of the city or its parking vendor is a reason to stop and pay another way, at the meter itself or through an app or website the driver has opened independently.

The physical code deserves the same scrutiny as the link. The FBI’s 2022 notice told readers to check whether a code has been covered with a sticker, and the Reader’s Digest roundup of the FTC alert likewise advised inspecting stickers for signs they were pasted over an existing code. Cities that do not accept QR payments at all give drivers the simplest test: Asheville, North Carolina, reportedly found about 20 fraudulent stickers on downtown meters in February, and because the city does not use QR codes for parking, any code on a meter there was an immediate red flag.

The agency also asks people to keep phones current. The alert links to Apple’s instructions for updating an iPhone or iPad and Google’s steps for checking and updating an Android version, and it recommends strong passwords paired with multi-factor authentication on accounts that could be reached through a fake login page.

If a code was already scanned

Scanning alone is not the point of no return; entering information is, since a fake payment page has nothing to work with until someone types a card number or a password into it. For anyone who did submit details, the FTC lists a short sequence: do not contact the scammer through the fake site, change the password right away if login credentials were typed in, and go through credit card and bank statements for charges that were not authorized.

Anyone who has been targeted can file a report at ReportFraud.ftc.gov, the FTC’s reporting portal, which the alert names as the place to send the incident. Those reports are how the agency and local authorities learn which cities are being hit and how many meters carry overlays.

The alternatives are familiar. Raleigh, for one, tells residents that its meters accept cards and coins and that its Passport Parking app is a legitimate way to pay, and it asks anyone who spots a suspicious sticker to report it to Raleigh Parking. A city’s own website, typed in by hand or reached through a search, is a safer route to an online payment page than any code stuck to a pole, and the same logic applies to the app a city names on its signs and receipts.

The FTC alert does not give a count of affected meters, a total for losses, or a list of cities, so the scale of the problem beyond individual local warnings is still unmeasured. For now, the agency’s own guidance amounts to a habit change: read the address the phone shows before paying anything.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview