Stand Against Crime

Emerging Scams · QR Codes & Phishing

QR Code Scams (Quishing): How to Spot a Fake

A sticker on a parking meter. A code in an email. A slip on your door. Fake QR codes are one of the fastest-growing scams of 2026 — here’s how to catch one.

Updated Aug 2026 · 6 min read

You pull up to a parking meter, scan the QR code to pay, tap through a normal-looking payment page, and drive off. Minutes later, your card is charged by someone else entirely. The code you scanned wasn’t the city’s — it was a sticker a scammer pressed on top of the real one.

That’s quishing (QR + phishing): hiding a scam link inside a QR code so you can’t see where it really goes. It works because a QR code is unreadable to the human eye — you have to trust it. In the first quarter of 2026, quishing incidents jumped 146%, with nearly 18.7 million recorded in March alone, part of a 14-fold rise over five years.

Where fake QR codes hide

Parking meters & public signage

The classic. Scammers stick a fake QR code over the real one on a meter or sign. In 2026 alone, cities including Raleigh, Asheville, Denver, Austin, and Toronto warned of it — in some cases victims saw fraudulent card charges within minutes.

Phishing emails

A QR code in an email dodges link filters. “Scan to reset your password” or “verify your account” leads to a fake login page. Corporate quishing emails rose roughly fivefold in 2025.

Delivery & package notices

A slip on your door or a texted “redelivery / customs fee” with a QR that opens a convincing courier page asking for a small payment and your card details.

Restaurants, flyers & mailers

A sticker on a table tent, a too-good discount on a flyer, or a “parking fine” in the mail — each with a QR to a fake payment or login site.

How to spot a fake

Free tool · runs in your browser

Not sure about a link?

Paste the address a QR code opened into our checker. It flags impersonation, typo-squats, hidden destinations, and other phishing tricks — before you tap anything.

Open the QR & link checker →

Four habits that keep you safe

  1. Use the official app you installed yourself — a sticker can’t change an app already on your phone.
  2. At a parking meter, pay by card or coin at the machine; a fake sticker can’t redirect that.
  3. Preview the link before opening it (long-press the code or use your camera preview), and paste it into our checker if anything looks off.
  4. Never enter card or login details on a page you reached from a random QR code.

If you already scanned or paid

  1. Entered card details or paid? Call your bank or card issuer now, report the charge as fraud, and ask to freeze or reissue the card.
  2. Entered a password? Change it immediately — and anywhere you reused it — then turn on two-factor authentication.
  3. Report it to the FTC (reportfraud.ftc.gov) and the FBI’s IC3 (ic3.gov), and tell the venue (the city or parking operator) so they can remove the sticker.
  4. Watch your statements for the next few weeks for unexpected charges.

Frequently asked questions

Are QR codes themselves dangerous?

No — a QR code is just a shortcut to a web address. The danger is entirely in where it sends you. Treat a scanned link exactly like any link in a text or email: verify before you trust it.

How can I tell a fake QR sticker apart?

Look at the material. If the code is on a peel-and-stick sticker while the rest of the sign is printed, be suspicious — especially on parking meters. Feel for a sticker placed over another code.

Is it safe to scan a restaurant or menu QR?

Usually, but still check the domain it opens, and never enter card details on a page that looks off. When in doubt, ask staff for the real link or order another way.

I scanned a scam QR but didn't enter anything — am I hacked?

Almost certainly not. Simply opening the page rarely does harm; the risk is in what you do next. Close the tab and move on. If you entered card or login details, follow the steps below right away.

Sources: FBI IC3 and FTC consumer warnings; 2026 municipal alerts (Raleigh, Asheville, Denver, Austin, Toronto); industry quishing-trend reporting. Figures are drawn from public reporting and should be verified against primary sources.