Also called: quishing · QR phishing · malicious QR code · QR sticker scam
A QR code scam replaces or imitates a legitimate code so that scanning it leads to a fraudulent site. Because the destination is an image rather than readable text, none of the usual checks on links apply. The most common physical version is a sticker placed over the genuine code on a parking meter or charger.
Anyone paying for parking, charging or transport by phone; Restaurant and hospitality customers, where table codes are routine; Employees receiving invoices or MFA-enrolment requests by email; People expecting a delivery, for the parcel-locker variant
Documented origins
China, Russia, United States, United Kingdom, Nigeria
Main targets
United States, United Kingdom, Canada, Australia, Ireland, New Zealand, Germany, Singapore
Case files
3 documented cases
Last reviewed
2026-09-06
The stages of the scheme, in order, with the point where it can still be stopped.
What it is
Quishing is phishing delivered as a QR code, and its entire advantage comes from one property: a QR
code is a URL you cannot read.
Every defence people have been taught about links assumes you can inspect the destination. Hover over
it. Check the domain. Look at the ending. None of that is available when the link is a pattern of black
squares, and on a phone the page opens before you have had a chance to think about it.
There are two families. The digital version puts a code in an email or a letter — effective in
organisations because security filters see an image, with nothing to scan or rewrite, and because it
moves the victim from a managed work computer to a personal phone.
The physical version is more direct and, in some ways, more alarming. Somebody prints a sticker and
puts it over the real code. In September 2026 the FTC warned that people had reported exactly this on
parking meters: scan the substituted code and you reach a fake site built to take your money, your
personal information, or both. No system was compromised. Someone used a printer.
How it actually works
A code where one is expected
A parking meter, an EV charger, a restaurant table, a parcel locker, a poster, an invoice. The
context supplies all the legitimacy the attack needs.
The substitution, or the send
Physically, a sticker over the genuine code. Digitally, a code embedded in an email or a letter
that a filter cannot inspect.
Where it could have stopped
Look at the code before scanning. A sticker placed over another one usually has a raised edge you can feel, a mismatched finish, or a slight colour difference. This is a physical check rather than a digital one, and it is the most reliable defence available — followed by preferring the operator’s own app or the number printed on the machine.
The destination stays invisible
No link text, no domain to hover over, no preview unless your camera offers one and you read it.
A page that fits the context
A parking payment form, a menu, a delivery redirect, a login. Nothing looks wrong because the page
was built for the exact situation you are standing in.
A small, unremarkable charge
A few pounds or dollars for parking, a redelivery fee, a service charge. Low enough that nobody
queries it — which is precisely why that amount was chosen.
The card is the product
The payment was a test. The details are what gets used and resold, sometimes weeks later and far
from the original charge.
Why it works
It removes the only check most people know. “Check the link before you click” is the single most
widely taught piece of security advice, and this format makes it impossible to follow.
The context is genuinely legitimate. You are standing at a real parking meter, in a real
restaurant, at a real charger. Nothing about the situation is suspicious, because the situation is not
the fake part.
Nobody filters a sticker. Email providers and mobile networks have become effective at blocking
phishing links. Physical space has no filter at all, which is exactly why the crime moved there.
Phones make everything faster and less inspectable. Scanning opens the page immediately, the URL is
truncated, and the person doing it is usually mid-task and mildly hurried.
The amounts are trivially small. A £2.40 parking charge is beneath the threshold at which anyone
investigates. That is the design: the charge is not the theft, it is the collection mechanism.
And in organisations, it moves the target sideways. A QR code in an email gets an employee off a
managed computer and onto a personal phone, outside every corporate control that would otherwise apply.
Where it comes from
QR phishing has no meaningful geography in its digital form — it is a delivery format, used by whoever
is already running phishing, and the same kits that produce cloned login pages produce these.
The physical variant is necessarily local. Somebody has to be standing at the parking meter with a
sticker. That makes it one of very few scams on this site with a domestic footprint by construction,
and, like the courier collections in
government impersonation and
family emergency scams, it is the point at which the
crime becomes reachable by ordinary policing.
The reason it exists at all is displacement. As email and SMS filtering improved, the schemes that
depended on delivering a link needed a channel that filters do not cover. A printed square is that
channel.
On 3 September 2026 the FTC warned consumers that people have reported scammers covering up legitimate QR codes on parking meters with codes of their own. Scanning the substituted code leads to a fake site built to take payment details, personal information, or both. It is the physical version of a phishing link, and it defeats every habit people have learned about checking where a link goes.
In September 2026 the FBI warned about OAuth consent phishing — a technique that obtains lasting access to an account without ever taking a password. The victim is sent a link that asks them to approve an application, and the resulting token cannot be cancelled by changing the password. Since late 2025 the FBI has observed actors impersonating government officials, media figures and event organisers on messaging apps to deliver these requests.
US phishing and spoofing complaints fell from 298,878 in 2023 to 191,561 in 2025, while reported losses rose from $18.7 million to $215.8 million — roughly eleven times. Australia saw the same divergence in a single year: Scamwatch phishing reports fell 33.2%, while combined national phishing losses rose 15.5%. Phishing is becoming a smaller, far more expensive crime.
A QR code stuck on top of another one. Feel the edge. This is the clearest tell there is.
A code that looks newer, glossier or differently printed from the surface around it.
A URL preview showing a link shortener, or a domain unrelated to the operator or city.
A payment page asking for more than the payment needs — a full address, a date of birth, an account login.
A QR code in an unexpected letter or invoice, particularly for a utility, tax or parking bill.
A QR code in an email asking you to re-authenticate, set up MFA, or view a document.
A code on a poster or flyer offering a prize, a survey or a discount.
A code where the operator also lists an app or a phone number. Use those instead.
If it’s happening to you
If you scanned but entered nothing. You are almost certainly fine — scanning alone does not
compromise a phone. Close the page and do not return to it.
If you entered card details.
Call your bank and cancel the card now. Do not wait to see whether a charge appears; the details
are the theft.
Watch for a follow-up call. A “fraud team” ringing about the transaction you just made is a
common sequence, and it leads to the
safe account script.
Report it. See where to report. If the code was physical, tell the
operator — parking authorities and charger networks can remove the sticker and warn others.
If you entered a work login. Tell your IT or security team immediately, change the password, revoke
sessions, and check the account’s connected applications — a QR code can lead to an OAuth consent
screen rather than a login form, and that kind of access survives a password change.
Using QR codes safely. Order of preference: the operator’s own app, then a card reader, then the
phone number printed on the machine, then the QR code. When you do use a code, look at the sticker,
read the URL preview before opening it, and stop if anything about the domain is unfamiliar. If a
payment page wants more information than the payment requires, that is your answer.
Where the money goes
The immediate charge is small and goes to a payment processor that will be abandoned quickly. It is
not really the objective.
The card details are. They get tested with a small transaction, then used for larger purchases or
bundled and sold. Where the page harvested a login rather than a card, the credential goes into the
same market as any other phished credential — sold on, and used by someone who was not involved in
placing the sticker.
That separation between collection and use is why a trivial fraudulent charge deserves the same
response as a large one: the charge is the receipt for a theft that has not been spent yet.
No agency publishes a line item for most of the schemes on this site, so these charts show the
official categories that contain this scheme. Each series is labelled with the agency's
own category name. See how the mapping works.
Every factual claim above traces to one of these. Statistics are reported losses; see
methodology for what that does and does not measure.
See a QR code parked somewhere? Don't scan it…yet!.
US Federal Trade Commission, Consumer Alerts. Accessed 2026-09-06. Supports: The parking-meter sticker technique and the FTC's warning about fake payment sites.
2025 Internet Crime Report.
FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: Phishing and spoofing complaint and loss totals, the category under which QR phishing is recorded.
Consumer Sentinel Network Data Book 2024.
US Federal Trade Commission. Accessed 2026-09-06. Supports: Contact-method distribution for reported US fraud, and payment-method losses.
Common questions
Can a QR code itself infect my phone?
Practically never. A QR code is just an encoded string, almost always a web address. The risk is where it takes you and what you do there, not the scanning itself. Treat it exactly as you would treat a link from a stranger.
How do I check a code before scanning?
Look at it physically first — a sticker over another code often has a raised edge, a different finish or a slight colour mismatch. Then let your camera show the URL preview before opening it: a link shortener, or a domain unrelated to the operator or city, is where to stop.
Why is email QR phishing effective against companies?
Because a security filter sees an image rather than a link, so there is nothing to scan or rewrite. It also moves the victim from a managed work computer to a personal phone, where corporate protections do not apply.
Is paying by QR code ever safe?
Often, but it should be your last choice rather than your first. The operator's own app, a card reader, or the phone number printed on the machine all put you in control of the destination. Reserve the QR code for when there is no alternative, and check the sticker.
I scanned one and entered my card. What now?
Call your bank and cancel the card immediately. The small charge is not the loss — the details are. Assume they will be tested and resold, and watch for a follow-up call claiming to be your bank's fraud team about the transaction.
Are QR codes in letters and invoices risky too?
Yes, and increasingly so. Fraudulent letters carrying a QR code for payment have been reported against utility, tax and parking bills. Never pay from a code in an unexpected letter; go to the organisation's own site or use a bill reference you already had.
Where the money goes after it leaves, and where it becomes hard to recover.
Reporting is what produces the enforcement data on this page. Find the right agency and phone
number for your country on the report page. If money moved in the last
few hours, call your bank first.