Fake QR codes in the wild
A QR code is cheap to print and impossible to read by eye, which makes it a good place to hide a link, a trick often called quishing. The patterns below have been reported by police departments and consumer agencies; the defense is the same for all of them: see the address before it opens, and pay or sign in through the app or site you already trust.
Stickers on parking meters
On September 3, 2026, the United States Federal Trade Commission told drivers not to scan a code found on a parking meter without reading the address it opens, after scammers had covered legitimate codes with their own. The pattern is not new: in late 2021 and early 2022, the San Antonio police and the Austin Transportation Department in Texas warned that stickers with fraudulent QR codes had been placed on pay stations across both cities, 29 of about 900 in Austin, which led drivers to fake payment pages on a lookalike of the real vendor's address. A real pay station shows its instructions in print and takes payment through the city's own app or the machine itself; a sticker over the printed code is the tell.
Codes in email and on parcels
Phishing emails carry QR codes because a picture slips past filters that read links. The code leads to a sign-in page that imitates a bank, a mail provider or a delivery service. The Federal Trade Commission published a consumer alert on the pattern in December 2023, and the FBI's Internet Crime Complaint Center issued a public service announcement on tampered QR codes in January 2022. A code on a parcel you did not order, or a "missed delivery" note with a code to reschedule, belongs to the same family.
Menus, flyers and posters
A code on a menu or a flyer can be replaced with a sticker in seconds. The page it opens can look like the real one and ask for a card. Anywhere a code asks for money or a password, the question is not whether the page looks right but whether the address is the one you expected.
What to look at
- The address, all of it: paypa1 is not paypal, and a familiar name in the wrong place (paypal.com.example.net) is not the familiar site.
- A sticker over a printed code.
- A short link where a company would print its own.
- A page that asks for a password or a card straight from a scan.
- When in doubt, close it and open the service from its own app.
Verdetto shows the whole address before anything opens, flags lookalike names, follows short links to where they lead when online lookups are on, and compares the address with a warning list kept on the phone. It never says a code is safe; it says what it checked and what it found.
Found a code like this? The report page takes the link, and a person reviews every report.
Sources
- FBI Internet Crime Complaint Center, public service announcement I-011822-PSA, January 18, 2022: Cybercriminals Tampering with QR Codes to Steal Victim Funds
- Federal Trade Commission consumer alert, September 3, 2026: See a QR code parked somewhere? Don't scan it…yet!
- Federal Trade Commission consumer alert, Alvaro Puig, December 6, 2023: Scammers hide harmful links in QR codes to steal your information
- KVUE, January 2022: Fraudulent QR codes found on Downtown Austin parking pay stations
- KSAT, December 20, 2021: SAPD warns of QR code scam targeting public parking spots
Related: How to check a QR code link · Why not just use the camera app?