Emerging Scams · QR Codes & Phishing
QR Code Scams (Quishing): How to Spot a Fake
A sticker on a parking meter. A code in an email. A slip on your door. Fake QR codes are one of the fastest-growing scams of 2026 — here’s how to catch one.
Updated Aug 2026 · 6 min read
You pull up to a parking meter, scan the QR code to pay, tap through a normal-looking payment page, and drive off. Minutes later, your card is charged by someone else entirely. The code you scanned wasn’t the city’s — it was a sticker a scammer pressed on top of the real one.
That’s quishing (QR + phishing): hiding a scam link inside a QR code so you can’t see where it really goes. It works because a QR code is unreadable to the human eye — you have to trust it. In the first quarter of 2026, quishing incidents jumped 146%, with nearly 18.7 million recorded in March alone, part of a 14-fold rise over five years.
Where fake QR codes hide
Parking meters & public signage
The classic. Scammers stick a fake QR code over the real one on a meter or sign. In 2026 alone, cities including Raleigh, Asheville, Denver, Austin, and Toronto warned of it — in some cases victims saw fraudulent card charges within minutes.
Phishing emails
A QR code in an email dodges link filters. “Scan to reset your password” or “verify your account” leads to a fake login page. Corporate quishing emails rose roughly fivefold in 2025.
Delivery & package notices
A slip on your door or a texted “redelivery / customs fee” with a QR that opens a convincing courier page asking for a small payment and your card details.
Restaurants, flyers & mailers
A sticker on a table tent, a too-good discount on a flyer, or a “parking fine” in the mail — each with a QR to a fake payment or login site.
How to spot a fake
- Is the QR code a sticker stuck on top of otherwise printed signage? That’s the single biggest tell — legitimate codes are usually printed as part of the sign.
- After scanning, read the full web address before you tap anything. Watch for lookalike domains — a fake “poybyphone” one letter off the real “paybyphone,” for example.
- Are you being asked to log in or pay when you didn’t expect to? Unexpected payment or password prompts are a red flag.
- No https, a strange domain ending, or a rushed “act now” tone all point to a scam.
Not sure about a link?
Paste the address a QR code opened into our checker. It flags impersonation, typo-squats, hidden destinations, and other phishing tricks — before you tap anything.
Open the QR & link checker →Four habits that keep you safe
- Use the official app you installed yourself — a sticker can’t change an app already on your phone.
- At a parking meter, pay by card or coin at the machine; a fake sticker can’t redirect that.
- Preview the link before opening it (long-press the code or use your camera preview), and paste it into our checker if anything looks off.
- Never enter card or login details on a page you reached from a random QR code.
If you already scanned or paid
- Entered card details or paid? Call your bank or card issuer now, report the charge as fraud, and ask to freeze or reissue the card.
- Entered a password? Change it immediately — and anywhere you reused it — then turn on two-factor authentication.
- Report it to the FTC (reportfraud.ftc.gov) and the FBI’s IC3 (ic3.gov), and tell the venue (the city or parking operator) so they can remove the sticker.
- Watch your statements for the next few weeks for unexpected charges.
Frequently asked questions
Are QR codes themselves dangerous?
No — a QR code is just a shortcut to a web address. The danger is entirely in where it sends you. Treat a scanned link exactly like any link in a text or email: verify before you trust it.
How can I tell a fake QR sticker apart?
Look at the material. If the code is on a peel-and-stick sticker while the rest of the sign is printed, be suspicious — especially on parking meters. Feel for a sticker placed over another code.
Is it safe to scan a restaurant or menu QR?
Usually, but still check the domain it opens, and never enter card details on a page that looks off. When in doubt, ask staff for the real link or order another way.
I scanned a scam QR but didn't enter anything — am I hacked?
Almost certainly not. Simply opening the page rarely does harm; the risk is in what you do next. Close the tab and move on. If you entered card or login details, follow the steps below right away.
Keep going: check a suspicious link, browse all our scam guides, or set up a family safe word.
Sources: FBI IC3 and FTC consumer warnings; 2026 municipal alerts (Raleigh, Asheville, Denver, Austin, Toronto); industry quishing-trend reporting. Figures are drawn from public reporting and should be verified against primary sources.