untrappable.Check

Quishing: the QR code scam on meters, menus, and mail

Yes — this is a scam. A QR code can hide a destination until you scan it. Quishing uses codes to send you to a fraudulent page.

Exhibit · Browser pop-up

meterpay-parking[.]info/session/8842
Pay for parking

Zone 8842 — your vehicle is not registered for this zone. Enter your card details to start your parking session and avoid a citation. meterpay-parking[.]info/pay

Pay $2.50 now

Do not close this window · Error # 0x80072F8F

Other versions you might get: A sticker over a restaurant menu's real code, a QR in a mailed letter about an “unpaid toll” or “undelivered package,” a code on a fake parking ticket under your wiper, or one in an email pretending to be a document. The paper changes; the fake page behind it doesn't.

What to do right now

  1. Preview the link before you open it. The FTC says many QR readers show the URL first. Look for spelling mistakes or switched letters, and close it if the domain isn't the city or parking app you already use.
  2. Stop before you type. After any scan, read the address bar. If the domain isn't the organization's known site, close the page.
  3. Pay another way: use the official app (the real ParkMobile, the city's own portal) or type the address printed on the meter's permanent signage — not the sticker.
  4. If you entered card or login details: call your bank, freeze or replace the card, and dispute the charge and anything that follows. The FTC says to change any password you typed, including on other accounts where you reused it, and review your card and bank statements for charges you didn't make.
  5. Don't contact anyone through the page you think is fake. The FTC says reaching out there can lead to more money or information requests.
  6. Look at the physical code: a sticker sitting on top of another code, or misaligned with the sign, is evidence — photograph it and tell the venue or city.
  7. Report it at reportfraud.ftc.gov.

Reduce the risk of another scam

Some readers preview a QR code before opening it. Do not open an unverified destination or enter information there. If you opened it, update your device and check for unexpected downloads or changes; if you entered details or paid, follow scam recovery steps.

● Public service · free steps first

Take the free protection steps first

A suspicious message does not tell us how someone found your details. If you shared personal information, start with the official recovery guidance. You can also freeze your credit for free.

Decide what protection you need

Start with the free controls above. Compare what a paid service would add only after deciding which problem remains.

Frequently asked

Can scanning a QR code hack my phone?
A reader may only preview the content, but some codes open websites or other actions. The risk depends on what opened and what you did. Do not enter details or download anything from an unverified destination. Keep your device updated and investigate unexpected downloads or security warnings.
How do I know if a parking meter QR code is fake?
Check the physical code first: the FTC says people have reported stickers covering the real meter code. Look for a label sitting on top of another, misaligned with the meter's printed signage. If your QR reader previews the URL, inspect it for spelling mistakes or switched letters before opening it. Then skip the sticker and pay in the official app or at the address printed on the permanent sign.
I entered my card on a page a QR code opened — what now?
Call your bank, freeze or replace the card, and dispute the charge plus anything that follows. The FTC says to change any username or password you typed, including on other accounts where you reused it, review your card and bank statements, and do not contact anyone through the page you think is fake. Photograph the QR sticker if you can, and report at reportfraud.ftc.gov.
Are QR codes in emails and letters safe to scan?
Treat them as suspect. Legitimate businesses rarely need you to scan a code from an email — that trick usually exists to slip past spam filters that would catch a phishing link. A mailed letter with a QR demanding toll, package, or fine payment is the paper version of a smishing text. Go to the organization's site by typing it yourself instead.

Sources

  1. 01See a QR code parked somewhere? Don’t scan it…yet!— Federal Trade Commission
  2. 02Scammers hide harmful links in QR codes to steal your information— Federal Trade Commission
  3. 03How to recognize and avoid phishing scams— Federal Trade Commission

Pass it on

Help protect someone else

If this could have fooled you, it can fool someone you know — a parent, a friend, the family group chat. It's safe to forward, and stands on its own as a record for a bank or the police.