A QR code looks the same whether it points somewhere safe or somewhere malicious — that’s the entire problem. A small sticker placed over a real one on a parking meter, a restaurant table, or a donation box costs almost nothing to print and can quietly redirect dozens of payments before anyone notices it’s not the original. Here’s how these swapped and fake QR codes are used, and how to check one before scanning.
How the Scam Works
Step 1: The Swapped or Overlaid QR Sticker
A fake QR code sticker is placed directly over a legitimate one in a public location — a parking meter, a restaurant table tent, a charity donation box — so anyone scanning it to pay is actually sending money to the scammer’s account instead of the real business or cause.
Step 2: “Scan to Verify” Prompts in Emails, Texts, and Social Posts
Rather than a clickable link, which some spam filters catch, a scam message includes a QR code image and asks the recipient to scan it to “verify an account,” “claim a refund,” or “confirm a delivery” — a technique sometimes called quishing, since QR codes bypass the link-scanning most people are used to doing.
Step 3: The Malicious Landing Page Disguised as a Payment Step
Scanning the code opens a page that looks like a normal payment or login screen, built to capture card details, bank credentials, or a one-time passcode the same way a fake link-based phishing page would — the QR code is just a different delivery method for the same destination.
Step 4: The Fake “Refund” or Peer-to-Payment QR Code
Some scams flip the expected direction of a QR code entirely — presenting a code that looks like it will send the victim a refund or payment, when scanning and confirming it actually authorizes a payment out of the victim’s own account.
A Composite Example (Illustrative, Not a Real Case)
Imagine someone parks their car and scans the QR code sticker on the meter to pay for parking, as they usually do. The payment page looks slightly different from the app they remember, but they enter their card details anyway. Weeks later, small unauthorized charges start appearing on that card. A city parking department later confirms several meters in that area were found with fraudulent stickers placed directly over the official ones. This scenario is a composite built from commonly reported patterns — it does not describe a real person, location, or event.
Red Flags That Get Missed
- A QR code sticker that looks slightly misaligned, a different texture, or peeling at the edges compared to the surface around it.
- An unsolicited message containing a QR code instead of a normal clickable link, especially from an unexpected sender.
- A payment or login page that opens after scanning and looks slightly different from the app or site normally used for that purpose.
- Being asked to scan a code to “receive” a refund or payment, which is not how legitimate refunds are typically delivered.
- No option to see the actual URL before the phone’s camera app opens it — some phones show a link preview before opening; ignoring that preview is a common misstep.
- Urgency paired with the QR code — a short deadline to “verify” or “claim” something before it expires.
How to Protect Yourself
- Check the link preview your phone shows before opening it, and compare it against the address you’d expect for that business or service.
- Use the official app for parking, transit, or a specific merchant instead of scanning a public sticker where that option exists, since it removes the sticker-swap risk entirely.
- Inspect a public QR code sticker for signs of tampering — a different texture, peeling edges, or a sticker sitting slightly off from where a code should be printed.
- Never scan a code to “receive” money — legitimate refunds and payments to you don’t require scanning anything on your end.
- Treat a QR-code-only message with the same suspicion as a suspicious link, since it’s often used specifically to dodge link-scanning security features.
- Report a suspicious or tampered public QR code to the business or authority it claims to represent, so it can be physically removed before more people scan it.
If You’ve Already Scanned a Malicious QR Code and Entered Details
Contact your bank or card issuer immediately to flag any potential unauthorized charges and consider freezing the card. If you entered login credentials, change that password immediately through the real app or site, and check for any unauthorized transactions or account changes.
If the code was a physical sticker in a public location, report it to the business, venue, or local authority responsible for that location so it can be removed. Report to your country’s official fraud authority:
- United States: FTC — reportfraud.ftc.gov, and the FBI Internet Crime Complaint Center (IC3) — ic3.gov
- United Kingdom: Action Fraud — actionfraud.police.uk or reportfraud.police.uk (0300 123 2040)
- Canada: Canadian Anti-Fraud Centre — antifraudcentre-centreantifraude.ca, report at reportcyberandfraud.canada.ca
- Australia: Scamwatch (National Anti-Scam Centre / ACCC) — scamwatch.gov.au, report at scamwatch.gov.au/report-a-scam
If you’re outside these countries, search for your national consumer protection agency or fraud reporting unit — most countries now have a dedicated online reporting channel.
Frequently Asked Questions
How can I tell if a public QR code sticker has been tampered with?
Look closely for a different texture, peeling edges, or a sticker sitting slightly off-center from where the original code should be printed — a swapped sticker rarely blends in perfectly on close inspection.
Why do scammers use QR codes instead of regular links?
QR codes bypass the link-preview scanning many people have learned to do with regular text or email links, and they work well on physical stickers in places a text message never could.
Is scanning a QR code itself dangerous, or only what happens after?
Scanning alone typically just opens a link — the actual risk comes from what you do on the page that opens afterward, so checking the destination before entering any information is the key protective step.
Can a QR code be used to take money from me without me entering anything?
Generally no on modern phones — scanning opens a link or a payment confirmation screen, and an actual transaction still requires some form of confirmation from you, which is why checking that confirmation screen carefully matters.
What should I do if I paid using a QR code that turned out to be fake?
Contact your bank or card issuer right away to flag the charge and ask about a dispute, and report the tampered code to the business or authority responsible for that location so it can be removed.
Browse more resources in our Scam Awareness category.
