A QR code is simply a link in disguise, and that is exactly why scammers have adopted it. A fraudulent code pasted over a real one on a parking meter, printed on a mailed notice, or dropped into an unexpected email routes the scanner to a page that looks legitimate but exists only to capture logins and payment details. The Federal Trade Commission treats the tactic as a growing threat because a single scan can hand over enough information to drain a bank account, and the person doing the scanning usually has no way to see where the code actually leads until the page has already loaded.
A sticker over a real code is all it takes
The mechanics are low-tech and effective. The FTC has documented scammers covering QR codes on parking meters with codes of their own, and sending codes by text or email with a manufactured reason to scan them right away. The physical world offers endless cover for the swap, since a small square sticker on a meter, a sign, or a flyer draws no suspicion and can sit in place for days before anyone notices the tampering or reports it to the business that owns the machine.
Once scanned, the code does its work quietly. It can open a spoofed site that mirrors a real login page and records whatever credentials the visitor enters, or it can trigger a download that installs malware capable of harvesting information before the target senses that anything is wrong. The scan itself feels routine, no different from paying for parking or pulling up a menu, and that ordinariness is what allows the theft to proceed without the hesitation that a suspicious link buried in an email might otherwise provoke.
The tactic has spread into everyday payments. The FTC has warned about codes and barcodes that pose as a convenient way to pay a utility company, routing the money to a scammer instead of the biller and leaving the real balance unpaid. Dressing the fraud up as an ordinary bill payment lowers the guard of anyone already accustomed to scanning a code to settle an account, and the victim may not discover the diversion until a shut-off notice arrives weeks later.
Free retirement updates: One number can cost or save hundreds a month in retirement. The free Retirement Shield newsletter surfaces the ones worth knowing. Sign up free.
Unexpected packages and notices carry codes too
Mail and deliveries have become another delivery vehicle for the scam. The FTC has flagged QR codes arriving on an unexpected package, printed on a slip that invites the recipient to scan for tracking information or to report a supposed delivery error. The code leads to a phishing site rather than a carrier, and the simple surprise of an unordered parcel on the doorstep supplies exactly the curiosity the scheme is built to exploit.
Fake notices work along the same lines. A letter claiming an unpaid toll, a missed delivery, or a problem with an account will pair its urgent message with a code framed as the fastest way to resolve everything, and the pressure to act immediately discourages the pause that would expose the fraud. The design goal is consistent across every variant, to convert a jolt of alarm into a scan before careful judgment has a chance to catch up with the impulse.
The reason a single scan can be so costly is what waits on the other side of it. A spoofed banking login captures the credentials needed to move money directly, while a captured card number feeds ordinary payment fraud that can run for weeks. Because the destination page can be built to look identical to a familiar bank or retailer, down to the logo and layout, the visitor often enters sensitive details in full confidence that the real institution is on the receiving end.
Verifying a code before trusting it
The defense is to treat the destination, not the code, as the thing to check. The FTC advises inspecting the URL a code resolves to before acting on it, watching for misspellings or a single switched letter that signals a spoofed address, and declining to scan any code that arrives unexpectedly or demands immediate action. When a message appears to come from a real company, contacting that company through a phone number or website already known to be genuine sidesteps the code entirely and removes any risk that the square itself was altered.
Physical codes call for physical skepticism. A code on a public meter or kiosk deserves a quick look for a sticker layered over the original, and an official app or a payment number posted by the operator is safer than a scanned link when settling a charge in person. The small friction of typing a known web address instead of scanning a convenient square is precisely the step the scam is engineered to eliminate, and restoring it costs only a few seconds.
QR codes earned their place in daily life because they remove effort, and that same frictionlessness is what fraud has learned to turn against the user. The unresolved tension for anyone standing at a meter or holding an unexpected notice is that the technology gives no visible cue about where a code leads until the page has already loaded and, in some versions, already done its damage. Rebuilding a habit of verifying the address behind the square is the only thing standing between a routine scan and an emptied account.
This article was researched and drafted with the assistance of artificial intelligence.
More Financial Reading