You park downtown, spot a QR code on the meter, scan it, and type in your card number to pay for two hours. Except the code was a sticker, pasted over the real one by someone who printed it at home, and your card number just went to a stranger. You even get a receipt. The parking ticket arrives anyway.

QR codes went from novelty to everywhere in about three years, on menus, meters, packages, TV screens and flyers, and scammers followed. The trick works because a QR code is a link you can’t read. Here’s how the scam operates, the checks that take five seconds, and what to do if you’ve already scanned the wrong square.
How the scam works
A QR code is just a web address wearing a disguise. When you scan one, you’re clicking a link, and everything you’ve learned about not clicking strange links applies, except your eyes can’t screen a QR code the way they can screen a suspicious URL.
The Federal Trade Commission has warned that scammers hide harmful links in QR codes and put them where people expect legitimate ones, including reports of fraudsters covering the real codes on parking meters with stickers of their own. The destination is typically a spoofed website, a convincing copy of a parking app, a bank login or a delivery page. Log in or enter a card number there, and the scammer has it. In other cases, the link tries to install malware that harvests information from the phone itself.
Where fake codes show up
Two habitats, roughly. The first is physical: stickers slapped on parking meters, light poles, restaurant tables, vending machines and flyers. Anywhere a printed code sits unattended in public, someone can paste a new one over it for pennies.
The second is your inbox and your text messages. The FTC’s alert describes the standard scripts: a package that supposedly couldn’t be delivered, a problem with your account, suspicious activity that requires you to change a password right away. The QR code arrives with a plausible story and a deadline. That urgency is the tell. It’s the same pressure play behind ordinary phishing emails and texts, with the link swapped for a square of pixels, partly because codes sail past spam filters that would have flagged the same link written out.
Five-second checks before you scan

Feel for the sticker. On a parking meter, kiosk or gas pump, a legitimate code is usually printed on the equipment or behind a laminate. If a code sits on a slightly raised sticker, or looks crooked, bubbled, or layered over another code, don’t scan it. Pay through the machine, the posted app, or the phone number on the official signage instead.
Preview the URL. Modern phone cameras show the web address before opening it. Read it. A city parking system shouldn’t resolve to a string of random words on an unfamiliar domain, and your bank’s site shouldn’t have a hyphenated look-alike name. Misspellings and switched letters are classic spoofing moves.
Never scan your way into a login. If a code from a text or email lands you on a page asking for a password, a card number or a Social Security number, stop. Reach the company through a channel you already trust, the app on your phone, the number on the back of your card, an address you type yourself.
Treat unexpected codes as unsolicited links. Because that’s what they are. A QR code you didn’t ask for deserves exactly the trust you’d give a link from a stranger: none, until verified.
Keep the phone updated. The FTC’s advice includes the unglamorous basics: keep your operating system current and protect accounts with strong passwords and multi-factor authentication, so one bad scan doesn’t cascade.
If you already scanned one
Move fast and don’t be embarrassed; the whole design of the scam is that careful people fall for it. If you entered a card number, call the card issuer, report it, and get the card reissued; while you’re at it, dispute any charge you didn’t make. If you entered a password, change it immediately on the real site, along with any other account where you reused it, and turn on two-factor authentication. If you entered your Social Security number, visit the FTC’s IdentityTheft.gov for a recovery plan, and consider freezing your credit with the three bureaus, which is free.
Watch your statements for small “test” charges over the following weeks. Scammers often probe with a dollar or two before going bigger.
Where to report it
Reports do more than vent. They feed the pattern-spotting that gets scam infrastructure taken down. Report the scam to the FTC at ReportFraud.ftc.gov, and if you lost money or the scam ran through the internet, file with the FBI’s Internet Crime Complaint Center at ic3.gov. If you found a sticker on a meter or city kiosk, tell the city too, since every driver behind you is about to face the same square.
None of this means QR codes are dangerous by nature. The one on your restaurant table is almost certainly fine. The rule is simpler than avoidance: a QR code is a link. Scan it with the same skepticism you’d give one, and the scam loses its costume.
This article was produced with AI assistance and reviewed by a human editor. Figures are linked to their primary sources; where a claim could not be verified from the public record, we say so.



