In 2024, the FBI’s Internet Crime Complaint Center (IC3) issued a public alert: criminals were sticking fake QR code stickers on parking meters in cities across the US, redirecting drivers to clone payment pages that siphoned card details. QR code phishing (“quishing”) is among the fastest-growing phishing categories of 2024-2026, with industry reports showing sharp year-over-year increases.
Why attackers love QR codes:
- Email security can’t see them — gateways treat QR codes as images, so the hidden URL bypasses spam filters.
- They look identical to the real thing — fake and real codes are pixel-for-pixel the same; no logo, no spelling, no hover-preview.
- User guard is low — you’ve been trained to scan reflexively.
QR codes were built for convenience, and scammers are experts at turning convenience into a trap. The two scenarios below are things you have almost certainly run into.
Scenario 1: The fake “scan to see the menu” sticker
You walk into a pub, a diner, or a chain restaurant and there’s a sticker on the table: “Scan to see the menu.” You scan without thinking. That one scan may have just sent your money to a scammer. Attackers target high-traffic, mid-priced restaurants — a meal is $30-80, the per-victim amount is small, and most people who notice a $20 overcharge won’t dispute it.
5 detail differences between a real and a fake menu code:
| Detail | Real code | Fake code |
|---|---|---|
| Print quality | Sharp edges, square pixels, laminated | Blurry, jagged, layered stickers |
| Location | Table corner, back of menu, host stand | Center of table, chair arm, side wall |
| Quantity | One code per table | Multiple codes, layered (real underneath) |
| Payee name | ”Joe’s Diner LLC” or the actual brand | ”Personal account,” odd nickname |
| Redirect URL | Short branded link (e.g. e.opentable.com) | Lookalike domain (wechat-pay-xxx.top) |
The 30-second, 3-step check before you scan:
- Check the print — freshly stuck on? Tear marks or bubbles? Real codes are a laminated card; fakes are a loose paper strip.
- Check the position — dead center on the table, covering an existing code? Fakes love the most visible spot.
- Check the payee — does the name look right? Search the restaurant’s full name and compare.
If even one is off, flag a server — “Hey, can I get a fresh menu QR code?” If the server brushes you off, that’s the warning sign.
Scenario 2: Fake charging kiosks and parking meter codes
The charging kiosk and parking meter are the second trap — they hit you at your most vulnerable moments: low battery, in a hurry, looking down.
3 scams on phone-charging kiosks:
- Inflated deposits — the scan takes you to a clone page, the deposit jumps from $5 to $15, and the money is gone before you notice.
- Phishing page — the page asks you to “activate” by entering your Apple ID or Google password, or an SMS code.
- Bluetooth permission abuse — the page pairs with your phone. Once granted, the attacker can pop up prompts and read your clipboard.
2 scams on parking meter codes:
- Sticker overlay on the meter post — the official code is on a small plaque. Scammers plaster a framed fake code in the middle of the meter head.
- “Pay your outstanding ticket” page — dressed up like a city portal, it asks for license plate, card number, and SMS code, and flashes “You have been added to the DMV no-pay list” to manufacture panic.
The action rule: only scan a charging-kiosk or parking-meter code in two cases:
- The code is physically part of the device — printed on the housing or etched into the screen.
- You opened the code from inside the official app (e.g. a “scan to charge” button inside the parking operator’s app).
Stickers, flyers, pop-up stands — don’t scan. The 30 seconds you spend opening the official app is cheaper than the 3 hours you’ll spend disputing charges later.
The universal mnemonic: 3 Looks, 3 Don’ts
Distill the two scenarios into something you can remember. Run this list in 30 seconds — it’ll catch roughly 90% of traps.
3 Looks:
- Look at the source — who put it there? Merchant? Official? Stranger? Can you reverse-verify by phone or the official app?
- Look at the print — blurry? Freshly stuck? Torn around the edges? In a strange spot?
- Look at the redirect — branded short link or a long, weird one? Is the domain right? Any extra junk parameters (
?redirect=...,?from=...)?
3 Don’ts:
- Don’t enter passwords on unfamiliar pages — any “activate,” “verify,” or “pay outstanding” page that asks for a password is a scam. No real service asks you to “re-verify” your bank or Apple ID password on a random page.
- Don’t install apps you don’t recognize — if the scan says “download the app to view,” it’s 99% a trap. Search the developer in the App Store first.
- Don’t grant Accessibility permission — on Android, this is one of the most dangerous permissions. Granting it lets the attacker read your screen, simulate taps, and run background actions as if they were you.
Quick-reference cheat sheet (screenshot this):
| If you see… | Do this immediately… |
|---|---|
| A blurry, freshly stuck, oddly placed QR code | Don’t scan. Ask a staff member. |
| A payee name that doesn’t match the merchant | Don’t pay. Verify the full name. |
Redirect to a weird domain (.top, .xyz, gibberish) | Close it. Don’t type anything. |
| ”Enter password / install app / grant permission” prompts | Close it. Report the link. |
| A popup asking for an SMS code | 100% scam. Never read the code out loud. |
| ”Your account is locked, contact XX” page | Screenshot for evidence, close it. |
That last one is worth repeating: anyone who asks you to “read me your 6-digit SMS code” is a scammer. That code is the digital key to your accounts.
Tool: Use Piick to decode suspicious QR codes
If a QR code comes from a stranger, a sticker, or anywhere you don’t feel right about it, don’t open your camera to scan it — most scanner apps auto-open the browser the moment they parse a URL.
A safer habit: use the Piick QR Code Scanner in your browser to decode it. Upload an image or take a photo; it runs fully on-device (the image never leaves your device), with no auto-open, no redirect, no download. You see the full URL / text / WiFi credentials first, then decide whether to act.
The pipeline is read-only: it does not execute instructions embedded in a QR code.
Already scanned it? The 4-step recovery plan
If you’ve already scanned the code and entered some information, don’t panic — the first hour is the golden window. The faster you cut the network and change passwords, the smaller the loss.
- Cut the network immediately — turn off WiFi and mobile data. If they’ve gained a control channel (e.g. Accessibility permission), killing the app alone won’t help — drop the network.
- Change passwords — your banking app, Venmo, PayPal, and Zelle come first (the money rails). Then email, social accounts, and any account that shared a password.
- Review statements + dispute — open your bank app, Venmo, PayPal, and Zelle, scan the last 24 hours, and contact support to freeze anything suspicious. Most platforms have a 24-hour fraud-freeze window.
- Report — if money is being stolen, call 911. File at reportfraud.ftc.gov and at ic3.gov. For UK readers, report to Action Fraud at actionfraud.police.uk and forward suspicious texts to 7726.
The order matters: cut network > change passwords > review statements > report.
Closing thought
QR codes aren’t going away, and neither are the scammers. Remember: pause a second, check once, ask once. Pause a second — for the “30 seconds before you scan” window. Check once — for flaws in the code itself. Ask once — to confirm with the merchant or platform. QR codes don’t expire, but your money can be gone in seconds.
Send this to the older relatives in your family — they are the highest-risk group for quishing. A younger victim knows to cut the network and change passwords; an older relative’s first reaction is often “don’t tell the kids,” and they don’t realize something is wrong until the scammer comes back (pretending to be “the police” demanding a transfer to “unfreeze”). Sharing this in the family group chat might be the highest-ROI thing you do this year.