QR code scams

Also called: quishing · QR phishing · malicious QR code · QR sticker scam

A QR code scam replaces or imitates a legitimate code so that scanning it leads to a fraudulent site. Because the destination is an image rather than readable text, none of the usual checks on links apply. The most common physical version is a sticker placed over the genuine code on a parking meter or charger.

Key facts

Category
Identity theft
First documented
2018
Typical loss
$20–$5k USD, per victim
Main channels
physical sticker, email, printed letter, poster, restaurant table, parcel locker
Who is targeted
Anyone paying for parking, charging or transport by phone; Restaurant and hospitality customers, where table codes are routine; Employees receiving invoices or MFA-enrolment requests by email; People expecting a delivery, for the parcel-locker variant
Documented origins
China, Russia, United States, United Kingdom, Nigeria
Main targets
United States, United Kingdom, Canada, Australia, Ireland, New Zealand, Germany, Singapore
Case files
3 documented cases
Last reviewed
2026-09-06
Anatomy of a QR code scamAnatomy of a QR code scam. A QR code is a URL you cannot read. Every check you were taught depends on reading it. 1. A code where one is expected: A parking meter, an EV charger, a restaurant table, a parcel locker, an invoice. 2. A sticker over the real one: No hacking required. The operator's system is untouched; only the image changed. 3. The destination is invisible: There is no link text to inspect and no domain to hover over. Filters see an image. 4. A page that fits the context: A parking payment form, a menu, a delivery redirect. Nothing looks out of place. 5. A small, unremarkable charge: A few pounds or dollars. Low enough that nobody checks, which is the point. 6. The card is the product: The payment was a test. The details are used or resold afterwards. The diagram marks stage 2 as the point where the scheme can still be stopped: Look at the code before you scan it. A sticker placed over another code — a raised edge, a mismatched finish, a slightly wrong colour — is the most reliable tell available, and it is a physical check rather than a digital one. Prefer the operator's own app or the number printed on the machine.Anatomy of a QR code scamA QR code is a URL you cannot read. Every check you were taught depends on reading it.1A code where one isexpectedA parking meter, an EVcharger, a restauranttable, a parcel locker, aninvoice.Seconds2A sticker over thereal oneNo hacking required. Theoperator's system isuntouched; only the imagechanged.Seconds3The destination isinvisibleThere is no link text toinspect and no domain tohover over. Filters see animage.Instant4A page that fits thecontextA parking payment form, amenu, a delivery redirect.Nothing looks out of place.Seconds5A small, unremarkablechargeA few pounds or dollars.Low enough that nobodychecks, which is the point.Seconds6The card is theproductThe payment was a test. Thedetails are used or resoldafterwards.DaysWhere it can still be stopped — stage 2Look at the code before you scan it. A sticker placed over another code — a raised edge, a mismatched finish, a slightly wrong colour — is the most reliabletell available, and it is a physical check rather than a digital one. Prefer the operator's own app or the number printed on the machine.Stages documented in the US Federal Trade Commission consumer alert of 3 September 2026 on QR codes placed over parking meters.howscamswork.com
The stages of the scheme, in order, with the point where it can still be stopped.

What it is

Quishing is phishing delivered as a QR code, and its entire advantage comes from one property: a QR code is a URL you cannot read.

Every defence people have been taught about links assumes you can inspect the destination. Hover over it. Check the domain. Look at the ending. None of that is available when the link is a pattern of black squares, and on a phone the page opens before you have had a chance to think about it.

There are two families. The digital version puts a code in an email or a letter — effective in organisations because security filters see an image, with nothing to scan or rewrite, and because it moves the victim from a managed work computer to a personal phone.

The physical version is more direct and, in some ways, more alarming. Somebody prints a sticker and puts it over the real code. In September 2026 the FTC warned that people had reported exactly this on parking meters: scan the substituted code and you reach a fake site built to take your money, your personal information, or both. No system was compromised. Someone used a printer.

How it actually works

  1. A code where one is expected

    A parking meter, an EV charger, a restaurant table, a parcel locker, a poster, an invoice. The context supplies all the legitimacy the attack needs.

  2. The substitution, or the send

    Physically, a sticker over the genuine code. Digitally, a code embedded in an email or a letter that a filter cannot inspect.

    Where it could have stopped

    Look at the code before scanning. A sticker placed over another one usually has a raised edge you can feel, a mismatched finish, or a slight colour difference. This is a physical check rather than a digital one, and it is the most reliable defence available — followed by preferring the operator’s own app or the number printed on the machine.

  3. The destination stays invisible

    No link text, no domain to hover over, no preview unless your camera offers one and you read it.

  4. A page that fits the context

    A parking payment form, a menu, a delivery redirect, a login. Nothing looks wrong because the page was built for the exact situation you are standing in.

  5. A small, unremarkable charge

    A few pounds or dollars for parking, a redelivery fee, a service charge. Low enough that nobody queries it — which is precisely why that amount was chosen.

  6. The card is the product

    The payment was a test. The details are what gets used and resold, sometimes weeks later and far from the original charge.

Why it works

It removes the only check most people know. “Check the link before you click” is the single most widely taught piece of security advice, and this format makes it impossible to follow.

The context is genuinely legitimate. You are standing at a real parking meter, in a real restaurant, at a real charger. Nothing about the situation is suspicious, because the situation is not the fake part.

Nobody filters a sticker. Email providers and mobile networks have become effective at blocking phishing links. Physical space has no filter at all, which is exactly why the crime moved there.

Phones make everything faster and less inspectable. Scanning opens the page immediately, the URL is truncated, and the person doing it is usually mid-task and mildly hurried.

The amounts are trivially small. A £2.40 parking charge is beneath the threshold at which anyone investigates. That is the design: the charge is not the theft, it is the collection mechanism.

And in organisations, it moves the target sideways. A QR code in an email gets an employee off a managed computer and onto a personal phone, outside every corporate control that would otherwise apply.

Where it comes from

QR phishing has no meaningful geography in its digital form — it is a delivery format, used by whoever is already running phishing, and the same kits that produce cloned login pages produce these.

The physical variant is necessarily local. Somebody has to be standing at the parking meter with a sticker. That makes it one of very few scams on this site with a domestic footprint by construction, and, like the courier collections in government impersonation and family emergency scams, it is the point at which the crime becomes reachable by ordinary policing.

The reason it exists at all is displacement. As email and SMS filtering improved, the schemes that depended on delivering a link needed a channel that filters do not cover. A printed square is that channel.

Real cases

A sticker over the parking meter's QR code

2026 US Ongoing

On 3 September 2026 the FTC warned consumers that people have reported scammers covering up legitimate QR codes on parking meters with codes of their own. Scanning the substituted code leads to a fake site built to take payment details, personal information, or both. It is the physical version of a phishing link, and it defeats every habit people have learned about checking where a link goes.

Read the case file · 2 sources

Consent phishing: access that a password change does not revoke

2026 US Ongoing

In September 2026 the FBI warned about OAuth consent phishing — a technique that obtains lasting access to an account without ever taking a password. The victim is sent a link that asks them to approve an application, and the resulting token cannot be cancelled by changing the password. Since late 2025 the FBI has observed actors impersonating government officials, media figures and event organisers on messaging apps to deliver these requests.

Read the case file · 1 source

Phishing reports fell while losses rose elevenfold

2025 US · AU Ongoing $215.8m

US phishing and spoofing complaints fell from 298,878 in 2023 to 191,561 in 2025, while reported losses rose from $18.7 million to $215.8 million — roughly eleven times. Australia saw the same divergence in a single year: Scamwatch phishing reports fell 33.2%, while combined national phishing losses rose 15.5%. Phishing is becoming a smaller, far more expensive crime.

Read the case file · 2 sources

Red flags

  • A QR code stuck on top of another one. Feel the edge. This is the clearest tell there is.
  • A code that looks newer, glossier or differently printed from the surface around it.
  • A URL preview showing a link shortener, or a domain unrelated to the operator or city.
  • A payment page asking for more than the payment needs — a full address, a date of birth, an account login.
  • A QR code in an unexpected letter or invoice, particularly for a utility, tax or parking bill.
  • A QR code in an email asking you to re-authenticate, set up MFA, or view a document.
  • A code on a poster or flyer offering a prize, a survey or a discount.
  • A code where the operator also lists an app or a phone number. Use those instead.

If it’s happening to you

If you scanned but entered nothing. You are almost certainly fine — scanning alone does not compromise a phone. Close the page and do not return to it.

If you entered card details.

  1. Call your bank and cancel the card now. Do not wait to see whether a charge appears; the details are the theft.
  2. Watch for a follow-up call. A “fraud team” ringing about the transaction you just made is a common sequence, and it leads to the safe account script.
  3. Report it. See where to report. If the code was physical, tell the operator — parking authorities and charger networks can remove the sticker and warn others.

If you entered a work login. Tell your IT or security team immediately, change the password, revoke sessions, and check the account’s connected applications — a QR code can lead to an OAuth consent screen rather than a login form, and that kind of access survives a password change.

Using QR codes safely. Order of preference: the operator’s own app, then a card reader, then the phone number printed on the machine, then the QR code. When you do use a code, look at the sticker, read the URL preview before opening it, and stop if anything about the domain is unfamiliar. If a payment page wants more information than the payment requires, that is your answer.

Where the money goes

The immediate charge is small and goes to a payment processor that will be abandoned quickly. It is not really the objective.

The card details are. They get tested with a small transaction, then used for larger purchases or bundled and sold. Where the page harvested a login rather than a card, the credential goes into the same market as any other phished credential — sold on, and used by someone who was not involved in placing the sticker.

That separation between collection and use is why a trivial fraudulent charge deserves the same response as a large one: the charge is the receipt for a theft that has not been spent yet.

The other half of this story

Our sibling site Clean on Paper explains what happens to harvested card details — how stolen card data is tested, resold and converted into goods that can be moved.

By the numbers

No agency publishes a line item for most of the schemes on this site, so these charts show the official categories that contain this scheme. Each series is labelled with the agency's own category name. See how the mapping works.

Reported losses over timeLine chart of reported losses from 2021 to 2025 for the agency categories that cover this scheme: Phishing/Spoofing (US); Phishing (AU); Phishing scams (AU); Phishing (CA).Reported losses over timeEach line is one agency category that covers this scheme. Agency categories are usually broader than the scheme itself.$0$50m$100m$150m$200mPhishing/Spoofing (US), 2023: $19mPhishing/Spoofing (US), 2024: $70mPhishing/Spoofing (US), 2025: $216mPhishing (AU), 2024: $56mPhishing (AU), 2025: $63mPhishing scams (AU), 2025: $20mPhishing (CA), 2021: $0Phishing (CA), 2022: $0Phishing (CA), 2023: $0Phishing (CA), 2024: $0Phishing (CA), 2025: $020212022202320242025Phishing/Spoofing (US)Phishing (AU)Phishing scams (AU)Phishing (CA)Categories are the publishers’ own and are broader than this scheme, so these lines bound it rather than measure it exactly. Lines are notcomparable to each other: different countries, different reporting systems.Reported losses only. Every agency here says most fraud is never reported to it, so treat these as a floor, not a total.Sources: Canadian Anti-Fraud Centre / RCMP; FBI Internet Crime Complaint Center (IC3); National Anti-Scam Centre (ACCC), Australia(transcribed from the published report). Pulled 2026-09-06.
Full dataset, methodology and downloads

Sources

Every factual claim above traces to one of these. Statistics are reported losses; see methodology for what that does and does not measure.

  1. See a QR code parked somewhere? Don't scan it…yet!. US Federal Trade Commission, Consumer Alerts. Accessed 2026-09-06. Supports: The parking-meter sticker technique and the FTC's warning about fake payment sites.
  2. 2025 Internet Crime Report. FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: Phishing and spoofing complaint and loss totals, the category under which QR phishing is recorded.
  3. Malicious Cyber Actors Gain Access to Victim Accounts Through Consent Phishing. FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: Delivery of malicious links through messaging applications and the persistence of token-based access.
  4. Targeting scams: report of the National Anti-Scam Centre on scams data and activity 2025. National Anti-Scam Centre (ACCC), Australia. Accessed 2026-09-06. Supports: Australian phishing category losses and the shift toward online contact methods.
  5. Consumer Sentinel Network Data Book 2024. US Federal Trade Commission. Accessed 2026-09-06. Supports: Contact-method distribution for reported US fraud, and payment-method losses.

Common questions

Can a QR code itself infect my phone?

Practically never. A QR code is just an encoded string, almost always a web address. The risk is where it takes you and what you do there, not the scanning itself. Treat it exactly as you would treat a link from a stranger.

How do I check a code before scanning?

Look at it physically first — a sticker over another code often has a raised edge, a different finish or a slight colour mismatch. Then let your camera show the URL preview before opening it: a link shortener, or a domain unrelated to the operator or city, is where to stop.

Why is email QR phishing effective against companies?

Because a security filter sees an image rather than a link, so there is nothing to scan or rewrite. It also moves the victim from a managed work computer to a personal phone, where corporate protections do not apply.

Is paying by QR code ever safe?

Often, but it should be your last choice rather than your first. The operator's own app, a card reader, or the phone number printed on the machine all put you in control of the destination. Reserve the QR code for when there is no alternative, and check the sticker.

I scanned one and entered my card. What now?

Call your bank and cancel the card immediately. The small charge is not the loss — the details are. Assume they will be tested and resold, and watch for a follow-up call claiming to be your bank's fraud team about the transaction.

Are QR codes in letters and invoices risky too?

Yes, and increasingly so. Fraudulent letters carrying a QR code for payment have been reported against utility, tax and parking bills. Never pay from a code in an unexpected letter; go to the organisation's own site or use a bill reference you already had.

Where a scanned code leadsWhere a scanned code leads. The small charge is not the objective. It is the test that proves the card works. Where a scanned code leadsThe small charge is not the objective. It is the test that proves the card works.Card details or aloginThe immediate chargeis small and goessomewhere disposableA processor soonabandonedA live card is worthmore than the amounttaken from itTested with a smallchargeUsed for largerpurchases, or sold tosomeone who neverplaced the stickerBundled and sold onReversibilityStolen details cannot be recalled at all. Assume they have been sold and will be used later by someone else, and act on the account rather than on the charge.What happens to harvested card details — Clean on Paper, our sibling sitehttps://cleanonpaper.site/techniques/money-mules/The separation between collection and use is why a trivial fraudulent charge deserves the same response as a large one.howscamswork.com
Where the money goes after it leaves, and where it becomes hard to recover.

Report it

Reporting is what produces the enforcement data on this page. Find the right agency and phone number for your country on the report page. If money moved in the last few hours, call your bank first.