The Federal Trade Commission is warning that scammers have started covering the legitimate QR codes on parking meters with fake codes of their own, sending anyone who scans them to a lookalike payment site built to steal money or personal information. The agency published the warning on September 3, 2026, describing reports of stickers placed directly over the real codes on meters used to pay for street parking. The scheme trades on the same convenience that made QR-code parking payment popular in the first place: a driver who expects to scan and pay in seconds has little reason to inspect the sticker underneath the code.
The notice, issued by the FTC’s Bureau of Consumer Protection staff, lays out a short checklist for avoiding the scam before scanning and a separate set of steps for anyone who has already tapped a bad link.
How Scammers Are Covering Legitimate Meter Codes
According to the FTC’s alert, the scheme depends on physically obscuring a working QR code with a near-identical sticker, so the meter itself still looks normal and still displays the payment instructions drivers expect. Because parking meters already train people to scan first and think second, the agency notes that a scammer’s sticker does not need to be sophisticated to work; it only needs to sit where the legitimate code used to be. The fraudulent code routes to a site designed to resemble a real municipal or app-based parking payment page, where drivers are prompted to enter a card number or account credentials that go straight to the scammer instead of the parking authority. Because the meter’s own signage, rates and location all look correct, the only broken link in the chain is the code itself, which is why the FTC treats the URL preview as the single most important habit to build.
Why the Fake Link Can Be Hard to Spot at a Glance
A QR code itself gives no visual clue about where it leads; only the underlying URL reveals whether the destination is legitimate. The FTC points out that many QR scanning apps display a preview of the destination link before opening it, and that this preview is where a fake page usually gives itself away, through misspellings, extra characters, or a domain that does not match the city or parking vendor. Drivers who skip that preview and tap through immediately lose the one built-in warning most phones already provide. A phone’s camera app or a dedicated scanner typically shows that preview automatically, without requiring extra software, which is part of why the agency frames the habit as a matter of pausing for a few seconds rather than installing new security tools.
The FTC’s Pre-Scan Checklist: Preview, Update, Passwords
Ahead of scanning any parking QR code, the agency recommends three specific habits: reading the previewed link closely for spelling mistakes or swapped letters, keeping a phone’s operating system and apps current so a malicious link is less likely to succeed even if it is tapped, and using strong, unique passwords together with multi-factor authentication on financial and email accounts. The FTC’s guidance treats an outdated phone or a reused password as a bigger risk factor than the code itself, since either one turns a single bad scan into access to multiple accounts.
A Tactic the FBI Has Tracked Since 2022
The physical-sticker version of this scam is not a new invention. The FBI’s Internet Crime Complaint Center first warned about cybercriminals tampering with QR codes in a January 2022 public service announcement, describing the same core method: replacing a legitimate physical code with a tampered one, often as simply as pasting a sticker on top of the original. That earlier alert traced a wave of fraudulent codes discovered on parking pay stations in Texas, where enforcement officers in Austin found tampered codes at more than two dozen pay stations, with similar fake stickers reported on meters in Houston and San Antonio around the same time. It recommended the same fix the FTC repeats now: check a scanned URL for typos or a misplaced letter before trusting it, and avoid completing a payment through a QR-code link at all when a known, trusted website is available instead. The 2026 alert shows the pattern persisting on meters years later, adapted to newer QR-based payment systems rather than fading out.
What Happens After Someone Scans a Bad Code
For anyone who has already scanned a fraudulent code, the FTC’s guidance shifts from prevention to containment. The agency advises against engaging with the site or anyone contacted through it, since further interaction gives a scammer more openings to extract money or data. Anyone who entered a password should change it on every account where the same password was reused, and anyone who entered payment information should review recent credit card and bank statements for transactions they do not recognize.
Reporting the Scam and Why the Timing Matters
The FTC directs anyone affected, or anyone who spots a suspicious sticker on a meter, to file a report, which the agency uses to track scam patterns across the country and share them with law enforcement. Because the scheme relies on a sticker that can be peeled off and moved to a new meter within days, the alert functions less as a one-time warning than as a standing reminder to check before scanning at any meter, not only ones already flagged as compromised.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview