Scanned a QR Code at a Parking Meter or Restaurant? Here's How to Tell If It Was Fake

You're back at the car, meter's about to expire, and there's a sticker with a QR code stuck right on the pole where the payment instructions used to be. You scan it, a payment page loads, you type your card number and hit pay. Somewhere in a parked car a few blocks away, a stranger just watched your card details land in a spreadsheet, and your meter is still expired.
Fake QR code stickers on parking meters have been found in Redondo Beach, New York City, and Fort Lauderdale, and the same technique works on restaurant menus. Before you scan, check whether the sticker sits flush or slightly raised, read the web address that pops up before you tap, and type the payment app's name into your own browser instead. If you already scanned and paid, call your card issuer immediately, change any reused password, and report it at reportfraud.ftc.gov.
Before You Scan: The 10-Second Check
Do this before your thumb touches the code, not after. A fake sticker is designed to survive a glance, not a close look, so the whole defense is slowing down for ten seconds.
- Look at the sticker's edge. A raised bump, a slightly crooked angle, or a different paper finish than the sign around it means something was stuck on top of the original.
- Check whether the code covers printed text, a barcode, or another QR code underneath it. Official signage does not print a code on top of other information.
- Wait for the link preview before you tap. Most phone cameras show the destination web address for a second before opening it. Read it.
- Compare that address to the payment brand printed on the meter or sign, such as ParkMobile, PayByPhone, or RingGo. A near-miss spelling or an unfamiliar domain ending is the tell.
- Open your own browser and type the app or website name from memory instead of tapping the link the code gave you.
- When in doubt, skip the code and pay at the meter's own keypad, or download the official app from your phone's app store directly.
That last habit is the one that actually stops the scam, because it removes the sticker from the transaction entirely. The Better Business Bureau's July 2024 alert puts it plainly: "Scammers may try to confuse you by placing QR code stickers where they should not belong. They may even place them on top of legitimate QR codes."
AARP's fraud guidance frames the same habit as "consider the source": a code printed in a magazine you subscribe to or on a website you already trust is a different risk level than one glued to a pole or table you've never seen before. Their March 2025 guide is aimed at a general audience, not just travelers, but the underlying test works anywhere: did you seek out this code, or did it show up somewhere you happened to be standing.
Already Tapped Pay? Do These Five Things Right Now
If you already scanned a suspicious code and entered payment information, the next ten minutes matter more than anything you read after this section. Work through this list in order.
- Close the browser tab now. Do not enter any more information on that page, even if it asks for a confirmation code.
- Call the number on the back of your card. Tell the issuer you entered your card details on an unverified site. Most banks can freeze the card and issue a new number within minutes. Traveling outside your home country? Use the international number printed on the card back, not the toll-free line, which often will not connect from overseas, and ask about your card network's zero-liability policy (Visa, Mastercard).
- Change any reused password. If you reused a password on that fake page, change it everywhere else you use it, and turn on two-factor authentication for that account.
- Screenshot the evidence. Capture the sticker's location and the fake payment page before anyone removes it. It is what a police report or bank dispute will ask for.
- Pull a free credit report. Check Equifax, Experian, or TransUnion if the page also asked for your name, birthdate, or ID details, per FBI IC3 guidance on QR-based fraud.
File a report at reportfraud.ftc.gov or identitytheft.gov in the US, and separately notify the parking authority or venue so they can pull the sticker before the next person scans it. In the UK, report to Action Fraud. Scammed somewhere else? Europol's report-a-crime page redirects to your own country's cybercrime portal, and a local police report is usually what your travel insurer will ask for before covering the loss. Travelers over 60 can also call the Department of Justice's National Elder Fraud Hotline at 1-833-372-8311 (833-FRAUD-11).
This is general safety guidance, not legal or financial advice. Your card issuer's dispute terms and local reporting requirements vary.
If the fake page also asked you to scan or photograph a document, such as a driver's license to "verify" the payment, treat that as a separate incident from the card charge. Our travel document checklist covers which documents to lock down and re-secure after any exposure, on top of the card and password steps above.
This Is Not a Hypothetical: Three US Cities Already Found Fake Stickers
This has already happened in multiple US cities in the past two years, not as a one-off prank but as an organized placement of stickers across dozens of meters at once. Each case followed the same shape: someone printed enough stickers to cover a whole neighborhood's meters in one visit, and it took a wave of confused drivers or a police tip before anyone noticed. Here is what got caught.
In Redondo Beach, California, police reported in August 2024 that scammers had placed fake QR stickers on 150 parking meters in the Esplanade and Riviera Village areas, sitting right next to the legitimate ParkMobile and PayByPhone labels. The fake code routed to a lookalike site, poybyphone.online, one letter off from the real payment provider. Officers removed the stickers and the case remains open; anyone who scanned one can call Redondo Beach police at (310) 379-2477.
New York City's Department of Transportation issued a citywide advisory in June 2025 after at least one fraudulent sticker turned up on a ParkNYC meter, redirecting to a third-party site asking for a credit card number. DOT Commissioner Ydanis Rodriguez put it directly in the department's warning, reported by NY1: "Consumers beware: Scammers are targeting parking meters, and we want you to be vigilant. If you see a QR code on a parking meter, do not scan it and please report it."
The only way to pay for metered parking in New York City is through the official ParkNYC app or on a physical ParkNYC parking meter.
NYC Department of Transportation, June 2025
Fort Lauderdale, Florida found fake stickers at seven parking locations in mid-November 2024, but with a twist: the codes were placed on signage at coin-operated machines and EV charging stations, not stuck directly on the meters themselves. City spokeswoman Christine Portela told CBS News Miami: "We urge anyone using city parking to pay only through the official parking meters or by downloading the official payment app marked on the official City signage, NOT the sticker." The lesson from Fort Lauderdale is that "check the meter" is not the whole rule. Check every surface that carries a code, including nearby signs and charger kiosks.
If you want the wider picture on scams that specifically target people away from home, our regional breakdown of tourist scams covers the tricks that show up most often by continent.
Restaurant Menus Carry the Same Risk, Even Without a Headline Yet
Every QR code menu you scan works through the same mechanism as a parking meter sticker: a code, a redirect, and a form asking for information. The difference is that no single dated restaurant incident has made headlines the way the parking cases have. That does not mean it is not a live risk. It means the exploit is documented as a method rather than tied to one splashy case so far, and a restaurant table may be an easier target than a meter, since a laminated card is far cheaper to swap out than a coin-operated machine.
The FTC already describes QR code tampering as a general attack pattern that applies anywhere a code is posted in public and unattended, which includes a table tent at a restaurant just as much as a parking pole. The FBI's Internet Crime Complaint Center has separately warned about a related vector, QR codes mailed in unsolicited packages, which confirms the same tactic (a scan-and-redirect trap) works through more than one delivery method, not just meters and mailers. A menu QR code that opens a generic web form asking for a card number before showing you any food is behaving like a payment scam, not a menu.
Treating a restaurant table's QR code as automatically safe because it is indoors and "someone would notice" a tampered sticker. A table tent gets replaced or reprinted constantly, and a fake sticker on laminated cardstock is easy to miss between diners.
The practical fix is the same one that works at the meter. If a menu code opens straight into a payment or account-login screen instead of a menu, close it and ask staff for a physical menu or type the restaurant's name into a search engine yourself. If the fake page goes further and asks you to "confirm" through a text message link or a chat prompt, that overlaps with the messaging-based tricks in our guide to protecting yourself from AI travel scams, which walks through how scammers use a similar urgency-plus-official-looking-link combination over text and chat.
Why This Trick Works Even on People Who Think They'd Never Fall for It
The common assumption is that QR scams only catch people who are careless or unfamiliar with technology. The opposite is closer to true: the scam is built around a moment when you are moving fast and trust the physical setting, not around a lack of tech savvy.
A parking meter is a government-owned object bolted to a sidewalk. A restaurant table tent is handed to you by staff. Both carry an assumption of legitimacy that a random text message or email never gets, which is exactly why scammers moved the attack into the physical world instead of your inbox. You are not evaluating whether to trust a stranger online. You are reacting to a familiar object in a place you already trust, under a small time pressure (an expiring meter, a hungry table) that discourages a close look.
Don't become more suspicious of everything. Narrow your trust to one specific test: does the destination match the brand printed on the sign, checked before you enter anything. That single test catches the scam regardless of how convincing the sticker looks, because a scammer can copy a logo perfectly but cannot make poybyphone.online read as paybyphone.com. This is the same before-and-after principle behind our breakdown of the rental car damage scam, where the defense is a checklist you run through in order, not general vigilance you're supposed to maintain the whole trip.
It also explains why these cases keep surfacing in tourist-heavy or transient spots: a Riviera Village parking strip, a car park near an event, a restaurant with a lot of one-time visitors. Locals who park in the same spot every week are more likely to notice a sticker that wasn't there yesterday. Someone visiting for the first time has no baseline to compare against, which is exactly the gap this article is meant to close before you're standing there.
How to Actually Spot a Tampered Sticker
A fake QR sticker has to physically sit on top of, or right next to, the real one, and that leaves signs a legitimate code never has. Use this table the next time you are standing in front of one.
| Signal | Legitimate code | Likely fake sticker |
|---|---|---|
| Surface | Printed flush into the meter's panel or the menu itself | Raised edge, bubble, or slightly crooked placement |
| Domain | Matches the payment brand named on the sign (paybyphone.com, parkmobile.io) | Close but altered spelling, or an unfamiliar ending like .online |
| Position | Part of the original printed signage | Covers other text, a barcode, or a second code underneath |
| What it opens | The official app, or a checkout screen matching the brand's usual design | A generic web form asking for a card number with no app branding |
None of these checks require an app or a subscription. They require slowing down for the few seconds it takes to look at the sticker instead of the screen.
The same table applies away from parking meters and restaurants, too. Bike-share docks, museum ticket kiosks, event check-in signs, and tourist information boards all rely on the same unattended, publicly reachable sticker or printout, and none of them have staff standing there to notice a swap. If a code shows up somewhere that surprises you, such as a "scan for a discount" flyer taped to a lamppost near a landmark, run it through the same check before you tap through.
What Quishing Actually Costs When It Works
Security researchers call QR code phishing "quishing," and the financial and legal system has started tracking it as its own scam category, separate from the email phishing it grew out of.
The average consumer loss to quishing scams was $1,225 per victim in 2025, according to CNBC's analysis of FBI, FTC, and state agency data. In the United Kingdom, reports of quishing rose from 100 in 2019 to 1,386 in the year up to April 2025, more than doubling between 2023 and 2024, per Action Fraud data reported by Tech Digest.
Katherine Hart of the UK's Chartered Trading Standards Institute described the scale of individual losses to Tech Digest as a different order of damage than a single overcharged parking session.
Losses are "huge," with victims losing their life savings. Those funds subsequently finance criminal activities.
Katherine Hart, Chartered Trading Standards Institute, April 2025
That gap between an inconvenience and losing everything is exactly why the ten-second check at the top of this article is worth the friction.
Car parks keep coming up as the setting UK local authorities warn about most. The Royal Borough of Kensington and Chelsea issued its own alert in January 2025 after finding "QR codes stuck to parking payment signage in at least six locations in the borough," and pointed drivers back to the PayByPhone app, phone line, text service, or PayPoint locations instead. The pattern holds across countries: unattended public payment points, whether a parking meter or a restaurant table, are the easiest place to slap a sticker without anyone stopping you.
The security industry also tracks quishing as a fast-growing share of phishing overall, not just a niche parking-lot trick. That growth is what pushed FBI IC3, the FTC, and the BBB to each publish standalone guidance on QR codes specifically, rather than folding the warning into general phishing advice, which is a signal worth taking seriously even before you look at any single dollar figure.
Apps that build personalized destination guides, tools like TripProf among them, have started building this kind of scam pattern into a dedicated Scam Awareness section under Emergency and Safety, alongside embassy contacts and a security brief for wherever you are traveling. It will not stop a sticker from being printed, but it puts the pattern you just read in front of you before you are standing at an unfamiliar meter in a country where you cannot easily verify a domain name.
Frequently Asked Questions
How can I tell if a QR code has been tampered with?
Look for a raised edge, bubble, or crooked placement compared to the surrounding sign, and check whether it sits on top of other printed text or a second code. A tampered sticker is physically stuck over the original rather than part of the printed surface.
Is it safe to scan a QR code on a restaurant menu?
It is generally safe if the code opens a menu, but treat it the same as a parking meter code if it opens a payment form or asks you to log into an account. The FTC describes QR tampering as a general method that applies to any unattended public code, menus included; the FBI has separately warned about the same scan-and-redirect tactic delivered through mailed QR codes.
What should I do if I already scanned a fake QR code but did not enter information?
Close the browser tab without entering anything, and avoid downloading anything the page prompts. Scanning alone does not compromise you; entering data or installing an app from that page is where the risk starts.
What should I do if I entered my card details on a fake QR code payment page?
Call your card issuer immediately and ask for the card to be frozen and reissued. Then file a report at reportfraud.ftc.gov and, if personal ID information was also entered, at identitytheft.gov.
Can a QR code install malware on my phone just from scanning it?
Scanning alone typically just opens a link, but that link can prompt you to download a file or app, or push you to a fake login page instead. The FBI's July 2025 advisory warns against scanning codes from unknown origins for exactly this reason, and recommends reviewing app permissions before granting a new app access to anything.
How do I preview a QR code's URL before opening it?
Point your camera at the code without tapping the link that appears. Most phone camera apps show the destination web address for a moment before you open it, which is your chance to check it for misspellings against the brand it claims to be, the same way you'd glance at a browser address bar before typing in a password.
Where do I report a QR code scam?
In the US, report to reportfraud.ftc.gov, the FBI's IC3, or BBB Scam Tracker. In the UK, report to Action Fraud. Also tell the venue or parking authority directly, in person or by phone, so the physical sticker gets removed before the next person scans it.
Key Takeaways
- Check the sticker's edge before you check the screen. A raised bump, crooked angle, or code sitting over other printed text is the physical tell that something was added later.
- Read the link preview before you tap it. Compare the domain to the payment brand's real name and watch for a near-miss spelling like poybyphone.online instead of paybyphone.com.
- Type the app name yourself instead of tapping the code's link. This single habit removes the sticker from the transaction entirely.
- If you already paid on a fake page, call your card issuer before you do anything else. A frozen card beats a police report every time.
- Restaurant menus carry the identical risk, just without a headline case yet. A code that opens a payment or login form instead of a menu should be treated exactly like a meter scam.
- This has already hit real cities, not hypothetical ones. Redondo Beach, New York City, and Fort Lauderdale all found fake stickers between August 2024 and June 2025, and personalized guides like TripProf's Scam Awareness section now track patterns like this by destination. The ten-second check works whether or not you've ever heard of the place.
Sources
- CBS News Los Angeles: Redondo Beach police warn of scammers placing fake QR codes on parking meters (August 2024)
- NY1: NYC DOT advisory on fake QR codes at parking meters (June 2025)
- CBS News Miami: Fort Lauderdale warns about fake QR code stickers at city parking garages (November 2024)
- Better Business Bureau: Double check that QR code before you pay for parking (July 2024)
- FTC Consumer Advice: Scammers hide harmful links in QR codes to steal your information (December 2023)
- FBI Internet Crime Complaint Center: Public Service Announcement I-073125-PSA (July 2025)
- Tech Digest: UK sees surge in QR code quishing scams, Action Fraud reports (April 2025)
- Royal Borough of Kensington and Chelsea: Warning to drivers of QR code parking scam (January 2025)
- CNBC: Cybersecurity scams, quishing, and QR code consumer risks (July 2025)
- AARP: Beware of fake QR code scams (updated March 2025)
- AARP Fraud Watch Network Helpline
- FTC: Report Fraud
- FTC: IdentityTheft.gov
- BBB Scam Tracker
Keep Reading
More travel tips and guides picked for you

Unpaid Toll Text After Renting a Car? Here's How to Tell If It's Real or a Scam
A text says you owe an overdue toll from your rental car and threatens a penalty if you don't pay now. Here's the 10-second check that tells you if it's real, plus what to do if you already paid.

Is That Airbnb Listing Fake? How to Spot a Cloned Listing Before You Book
Scammers copy real photos and reviews onto a fake listing, undercut the price, and push you to pay outside the app. Here is the 60-second check that catches most cloned listings, plus what to do if you already paid.

The Best Countries for American Travelers in 2027, and Why the Entry Rules Just Flipped
The entry-rule map for Americans flipped in 2026. We ranked 17 destinations by actual friction, cost, and paperwork, not scenery, so you know which trips to book now and which need six weeks of lead time.