The FTC warns that scammers can cover legitimate QR codes on parking meters or similar locations with their own. Scanning the fake code can take you to phishing-style pages designed to capture sensitive information and/or money.

The FTC says consumers should pause before scanning any “parking/payment” QR code they didn’t expect to see, especially if the code appears to have been tampered with. In these attacks, criminals may place a counterfeit QR code over a real one so that your phone automatically directs you to a fraudulent web page instead of a legitimate payment or account portal. From there, scammers can attempt to steal personal data (such as login credentials) or trick you into making payments through deceptive forms. The FTC also highlights that QR-based scams work because they look convenient and official, and victims may assume the page is part of the parking/payment system. The alert encourages consumers to avoid scanning questionable codes, to verify the payment method using trusted channels (like official apps or signage), and to follow the FTC’s recommended steps if they believe they interacted with a scam page. Overall, the guidance targets a common tactic: using QR codes as a fast redirect into phishing and payment fraud.