QR Code Scams Are Exploding: How ‘Quishing’ Drains Bank Accounts at Parking Meters and Beyond – Reinvest Safe

QR Code Scams Are Exploding: How ‘Quishing’ Drains Bank Accounts at Parking Meters and Beyond

QR code scams, known as 'quishing,' are surging in 2026. Here's how fake codes at parking meters and menus work, and 8 habits that keep your phone and bank account safe.

You’re running late, you spot an open meter, and there’s a little sign taped to it: “Scan to pay for parking.” You point your camera, tap the link, and type in your card number. Thirty seconds, done. Except the sticker wasn’t from the city. It was glued on top of the real one, and the “payment page” just handed your card to a stranger.

That’s quishing (QR code phishing), and it’s not a rare fluke anymore. Microsoft Threat Intelligence reported that QR-code phishing emails jumped from 7.6 million in January 2026 to 18.7 million in March, making it the fastest-growing email attack vector of the quarter. The FTC issued a fresh warning in April 2026 about fake traffic-ticket texts that use QR codes instead of links. None of this is exotic hacking. It’s a sticker, a fake webpage, and someone counting on you to trust a black-and-white square you can’t actually read with your own eyes.

This guide walks through how quishing works, where it tends to show up, and the habits that make you a hard target. This article is for general information only and isn’t a substitute for advice from your bank, a licensed financial professional, or a government agency.

Close-up of a suspicious paper QR code sticker peeling off and layered on top of an official sign at a parking meter

Why QR Codes Are Such an Easy Target

A QR code is just a container. It can point to a menu, a Wi-Fi login, a payment form, or a malicious site, and there’s no way to tell which just by looking at the pattern of squares. You’re trusting the code’s placement (this one is on the city’s meter, that one is on the restaurant’s table) rather than the code itself.

Scammers exploit exactly that gap. They don’t need to hack anything. They just need to print a sticker, put it somewhere you already expect a QR code to be, and wait. Your phone does the rest, often auto-opening a browser before you’ve had a chance to think about it.

Email adds a second layer of the same trick. A phishing email with a plain text link can get caught by spam filters that scan for malicious URLs. Bury that same link inside a QR code image, though, and a lot of filters can’t read it. That’s part of why Microsoft’s researchers saw such a steep jump in QR-based phishing emails this year: it’s a filter-evasion technique as much as a consumer scam.

Where Fake QR Codes Actually Show Up

  • Parking meters. A sticker with a fake “scan to pay” code goes right over the meter’s real one, usually in a busy area where people are in a hurry. McAfee’s 2026 research flagged this as one of the most common physical setups.
  • Restaurant tables and menus. A fake QR sticker on a table tent, or a small paper flyer left near the register, sends you to a page that looks like it’s collecting a “loyalty signup” or payment when it’s actually harvesting your card or login details.
  • Parking tickets and “traffic violation” texts. The FTC’s April 2026 alert covers texts claiming you owe a toll or a citation, with a QR code standing in for a link so the message looks more official.
  • Fake package notices. An unexpected slip or postcard says a delivery is waiting and asks you to scan a code to “confirm details” or reschedule.
  • Posters and flyers in public spaces. Event posters, “free Wi-Fi” signs, and charity donation flyers are easy to tamper with because nobody’s watching them 24/7.
  • Phishing emails. Instead of a clickable link, the email embeds the malicious URL as a QR code image and asks you to scan it with your phone, moving the whole interaction off your (probably better-protected) work computer and onto your personal device.

Young adult carefully checking a smartphone screen before scanning a QR code menu card at a restaurant table

What Happens After You Scan

Most quishing attacks funnel you toward one of three outcomes:

  1. A spoofed payment page. It looks like a legitimate parking app or merchant checkout, but the card details you enter go straight to the scammer.
  2. A credential-harvesting login screen. Mimics your bank, a delivery carrier, or a well-known email provider, and captures your username and password the moment you type them in.
  3. A forced app or file download. Some codes skip the fake website step entirely and try to push a malicious app or file onto your phone, which can then read messages, log keystrokes, or dig for saved passwords.

The FTC notes that a scammer’s QR code can also lead to a site that’s designed purely to look convincing enough that you’ll hand over more information voluntarily, like your address, date of birth, or the last four digits of your Social Security number, none of which a legitimate parking payment or delivery confirmation needs.

The Eight-Second Habits That Actually Stop This

You don’t need special software to avoid quishing. You need a few seconds of friction before you scan or tap.

  1. Check for a sticker on a sticker. Before scanning a code on a meter, sign, or table tent, look at the edges. A peeling corner, a slightly different paper stock, or a code that looks glued rather than printed on the original material is a red flag worth a second look.
  2. Preview the link before you open it. Most phone cameras show you the destination URL before opening a browser. Read it. Watch for misspelled brand names, extra words, or a domain that doesn’t match who you’d expect (a parking meter’s code should point to your city’s actual parking authority, not a generic-looking link).
  3. Never enter payment or login info you didn’t seek out yourself. If a QR code leads to a page asking for a card number or password, stop and go directly to the official app or website instead of continuing from the scanned link.
  4. Use the official app for anything recurring. Parking, tolls, and food ordering all have real apps. If you already know you’ll be paying for parking regularly, it’s worth setting up the city’s official app once rather than scanning a code every time.
  5. Don’t scan codes from unsolicited texts or emails. A legitimate government agency, bank, or delivery company generally won’t ask you to resolve an urgent matter exclusively through a scanned code. When in doubt, go to the organization’s site by typing the address yourself.
  6. Keep your phone’s operating system updated. Security patches close some of the vulnerabilities that malicious downloads try to exploit, so postponing updates leaves a wider door open.
  7. Watch for urgency and pressure. “Pay now or your car gets towed,” “verify immediately or lose access,” and similar lines are designed to make you skip the checks above. A real deadline can survive you taking thirty extra seconds to look closely.
  8. Report what you find. If you spot a suspicious sticker on public property, tell the property owner, meter operator, or local authority so they can remove it before someone else scans it.

If You Already Scanned a Bad Code

Mistakes happen, and acting quickly limits the damage.

  • Close the page and don’t enter anything else. If you haven’t typed in any information yet, you’re likely fine, just don’t proceed.
  • If you entered card details, call your card issuer or bank right away to flag the transaction and discuss freezing or replacing the card.
  • If you entered a password, change it immediately on the real site or app, and turn on two-factor authentication if you haven’t already.
  • Run a security scan on your phone if you think a file or app may have downloaded without your clear consent.
  • Report the scam to the FTC at ReportFraud.ftc.gov, and to your local police department if it involved tampered public property like a parking meter or transit sign.
  • Watch your statements for a few billing cycles afterward. Unauthorized charges are easier to dispute the sooner you catch them.

Compliance and Safety Note

This article explains a common fraud pattern for general awareness. It doesn’t constitute legal, financial, or cybersecurity advice, and outcomes after a scam can vary depending on your bank’s policies, your state’s laws, and the specifics of what was compromised. For anything involving unauthorized charges or account access, contact your financial institution and, when appropriate, agencies like the FTC or your state attorney general.

Frequently Asked Questions

What is quishing?

Quishing is short for “QR phishing.” It’s the practice of using a QR code, instead of a text link, to lure someone to a fraudulent website or trigger a malicious download. The tactic works because most people can’t tell where a QR code leads just by looking at it.

How do you know if a QR code is legit?

Look at where it’s physically located and whether it appears to be layered over something else (a peeling edge or mismatched paper is a warning sign). Before opening the link, check the URL preview your phone shows you, and be wary of anything that doesn’t match the organization you expect. When a code is tied to a payment or account login, it’s safest to go directly to the official app or website instead.

Can someone get your information from a QR code?

Not from the code’s pattern itself, but from what it leads to. Scanning a malicious code can take you to a spoofed page designed to collect your card number, password, or personal details, or in some cases prompt a harmful file download. The risk comes from what happens after the scan, not the QR image itself.

What should I do if I scanned a QR code and it looks suspicious?

Close the page without entering any information. If you already typed in a password, change it right away on the legitimate site. If you entered card details, contact your card issuer or bank immediately. It’s also worth running a security scan on your phone and reporting the incident to the FTC.

How can I scan QR codes safely in everyday situations?

Preview the destination link before opening it, avoid scanning codes from unsolicited texts or emails, use official apps for recurring payments like parking or tolls, and take an extra look at any code posted in a public place for signs it’s been tampered with, like a sticker placed over the original.

What other scams should I watch for besides fake QR codes?

Quishing often overlaps with other current scams, including imposter texts about traffic tickets or package deliveries, phishing emails that mimic banks or well-known brands, and payment-app fraud on services like Zelle or Venmo. The common thread is urgency paired with a request to click, scan, or pay quickly.


Related reading:

Sources: Federal Trade Commission (consumer.ftc.gov), Microsoft Threat Intelligence (Q1 2026 reporting), NBC News, McAfee.