The FTC just warned that scammers are placing fake QR stickers on parking meters. Here's how the scam works and how to spot a fake code before you scan.
Last week you might have driven past a parking meter, pulled out your phone, scanned the little black-and-white square taped to it, and paid without thinking twice. That's the whole point of QR codes they're supposed to save you time. But on September 3, 2026, the Federal Trade Commission put out a consumer alert about something that's been quietly happening in parking lots across the country: scammers are printing their own QR code stickers and pasting them directly over the real ones.
You can't tell the difference by looking. A sticker is a sticker. The one that's supposed to take you to the city's official parking payment page might actually take you to a cloned site built to grab your card number, or worse, log you into a fake portal that harvests your email and password. By the time you notice something's off, the scammer already has what they wanted.
This isn't a one-off story. It's part of a much bigger shift that's happened over the last two years, and most people scanning codes every day have no idea how fast it's moved.
The numbers behind this are bigger than most people realize
QR code phishing the security industry calls it "quishing" has gone from a niche curiosity to one of the fastest-growing attack methods out there. Microsoft's own threat intelligence team tracked QR-based phishing attempts climbing from 7.6 million in January 2026 to 18.7 million by March, a 146% jump in a single quarter, out of 8.3 billion phishing threats they analyzed overall. Keepnet Labs put quishing at roughly 12% of all phishing attacks globally in 2025, up from less than 1% back in 2021.
Here's the part that actually matters for anyone scanning a code in public: according to Uniqode's 2026 State of QR Codes report, 14% of consumers say they've already been targeted by a QR code scam at some point. And separately, a NordVPN-backed survey found 73% of Americans admit they scan codes without checking where the link actually goes first. That gap high trust, low verification is exactly what makes parking meters, restaurant table tents, and event posters such an easy target. Nobody expects a sticker on a parking meter to be malicious, so nobody checks.
Why parking meters specifically? Think about the conditions. They're outdoors, unattended most of the day, and printed with a plain adhesive label rather than anything tamper-proof. A scammer can print a near-identical sticker at home, walk down a row of meters in under ten minutes, and be gone before anyone notices. It's the same trick that was first reported on public meters in Austin, Texas, years ago — it just hasn't stopped, and the FTC's new alert confirms it's still active enough in 2026 to warrant a fresh warning.
What actually happens if you scan one
The FTC's alert lays out the mechanics plainly: the fake code sends you to a site that looks like a legitimate payment page. You enter your card details to "pay for parking," and that information goes straight to the scammer instead. In some versions, the page instead pushes you to download an app or "verify your identity" a tactic aimed at stealing login credentials rather than card numbers, which can then be reused against your email, banking, or other accounts if you've recycled a password.
None of this requires the scammer to break into anything. The code itself isn't hacked it's just replaced. That's what makes quishing so hard to catch with normal instincts. You're not clicking a suspicious link in an email you were already side-eyeing. You're standing next to your car, in a hurry, doing something you've done a hundred times before.
How to actually check a QR code before you scan it
The FTC's guidance is simple, and worth actually doing rather than just nodding along to:
- Look before you scan. Most phone cameras and QR readers show a preview of the destination URL before opening it. Read it. Look for misspellings, extra characters, or a domain that doesn't match the business or city you'd expect (a real parking authority won't route you through a random .xyz or .top domain).
- Check the sticker itself. A code that looks slightly crooked, printed on a different material than the rest of the sign, or peeling at one corner is worth a second look before you trust it.
- Never enter payment info on a page you reached by scanning something in public unless you've independently confirmed it's the real site — for parking specifically, most cities also let you pay through their official app or by calling a posted number instead.
- Keep your phone's OS and apps updated. A lot of the damage from a bad link depends on what vulnerabilities are sitting unpatched on the device that opens it.
- If you already scanned one and entered anything: change that password immediately (and anywhere else you reused it), check your bank and card statements for anything unfamiliar, and report it at ReportFraud.ftc.gov.
The other side of this: it's also a warning for anyone who uses QR codes to run a business
There's a flip side worth mentioning. If you're a business owner who relies on QR codes for menus, event check-ins, payment links, or marketing campaigns this same vulnerability applies to you. A static QR code printed once and left in a public spot can be physically covered by a scammer just as easily as a city's parking code can. It's one of the practical reasons more businesses have shifted toward dynamic QR codes that live behind a monitored, editable link rather than a code that, once printed, can be silently swapped or spoofed without your knowledge. It doesn't stop someone from putting a sticker over your sign, but it does mean you can track scan activity, add password protection to sensitive destinations, and catch unusual patterns faster than you would with a code you printed and forgot about.
Quishing isn't going away if anything, the growth curve over the past 18 months suggests it's still accelerating. The good news is the defense against it isn't complicated. It's the same three seconds of attention you'd give a suspicious link in a text message, just redirected toward a piece of paper taped to a meter.