QR Code Scams in 2026: How to Check a Parking, Delivery, or Payment Code Before You Scan

Scammers are replacing real QR codes with lookalikes on parking meters and messages. Learn what to inspect before paying or signing in.

By ShantanuPublished Updated
  • 5 min read
  • 10 steps
View article illustration
QR Code Scams in 2026: How to Check a Parking, Delivery, or Payment Code Before You Scan

A QR code seems harmless because it is only a pattern of squares. But the phone treats the scanned result as an instruction—usually to open a website—and that website can be fraudulent. The US Federal Trade Commission warned again in September 2026 about fake QR labels placed over legitimate parking-meter codes.

The same trick can appear on restaurant tables, printed bills, delivery notices, posters, email attachments, and unsolicited packages. The immediate danger is rarely the camera scan itself. It is what happens after the scan: paying a fake merchant, entering a password on an imitation site, installing an unknown app, or approving an account login.

1. Inspect the physical code before pointing your phone at it

At a parking meter or payment stand, check whether the QR is a sticker placed over another printed label. Look for peeling edges, unusual fonts, a mismatched logo, or a printed address that differs from the venue's normal payment service.

A neat sticker is not proof of fraud, and a professionally printed poster can still be malicious. But visible tampering is an excellent reason to stop and use the official payment app or website instead. If the code is on public property, a staff member may be able to confirm the intended provider.

2. Read the destination address before opening it

Most phone cameras display a preview of the URL. Inspect the real domain, not merely the name used in the page title. A fake service might use a long hostname that includes a familiar brand as a subdomain or a misleading string.

For example, payments.example.com and payments.example.com.evil-site.test are not the same destination. The domain you should trust is the actual registered provider, not a brand name placed somewhere in a longer URL.

Shortened links hide the destination and deserve additional caution in unexpected payment or account-recovery situations.

3. A padlock does not mean the merchant is genuine

A phishing page can use HTTPS and show a secure-connection indicator. HTTPS helps protect traffic between your device and the website, but it does not certify that a parking payment page, delivery provider, or bank is legitimate.

Check the provider identity separately. If a QR page asks for unusual personal details, an unrelated login, or a card payment without normal merchant information, stop and verify through an independent channel.

4. Parking payment is an especially attractive target

Parking meters are public, stationary, and often used by people in a hurry. A scammer can place a new QR sticker where drivers already expect one. A rushed user sees the meter, scans the sticker, and believes the site is authorized because of where the label is located.

If the payment page seems unfamiliar, open the city's or parking operator's known app directly. Use a posted official domain you can independently verify, a payment terminal, or staff assistance. Do not assume the first QR you see belongs to the actual meter operator.

5. Delivery messages use the same pattern

An SMS may claim that your parcel requires an address correction, customs fee, or second delivery attempt. A QR image in a letter or message can route you to a fake courier page.

Open the shipping company's official app or type the known domain yourself, then check the tracking number. If you are not expecting a package, the message is even less persuasive. Fraudsters can send convincing branding and tracking-style references without having any real shipment information.

6. Beware QR codes that ask you to sign in

Some codes legitimately link devices, such as opening a web session for messaging or authentication. That makes fake account-linking codes dangerous: they may attempt to connect an attacker-controlled device to an account or send you to a counterfeit login page.

Read the exact app prompt before approving anything. If you are told to scan a QR to “fix” a password problem, “restore” two-factor authentication, or “unlock” a bank account, verify through the official service first. Never share login approval codes with someone who approached you unexpectedly.

7. Do not install an app merely because the QR page insists

A venue may offer a mobile app, but a QR redirect demanding that you install a file from an unknown site is a warning sign. On Android, sideloaded APKs require particular care; on any platform, configuration profiles, enterprise certificates, and accessibility permissions can be abused.

Prefer the official app store or an independently verified vendor website. Do not disable platform protections because a payment page says they are blocking your transaction.

8. What if you already scanned the code?

Scanning and previewing a URL does not automatically mean the scam succeeded. If you only saw the destination and closed it, there may be nothing further to do. If you opened a page but entered no information, close it and avoid interacting further.

If you entered a password, change it through the official site, review account activity, and make sure multifactor authentication remains active. If you entered payment information, contact your bank or card issuer promptly and monitor transactions. If you installed software, remove it and run appropriate device-security checks.

The response should match the action you took. A full factory reset is not the default fix for merely seeing a suspicious webpage.

9. If the scam code is in a public place

Tell the venue operator or local authority so the label can be checked and removed. Take a photo for reporting if it is safe and lawful to do so, without repeatedly opening the malicious site or sharing the bad link with friends who might click it.

For online scams, use the reporting route provided by the relevant service and local consumer-protection authorities. A single report may help prevent others from using the same false payment route.

10. Build a habit that does not slow you down much

Before scanning, ask three questions: Who placed this code? Where does it lead? What is it asking me to do? Use the official app for routine payments and logins. Treat public stickers and unexpected messages as untrusted until verified.

QR codes are a convenient way to enter an address, not a guarantee about who owns the address. Once you treat them as links from an unknown sender, the precautions become familiar and manageable.

Official references

FTC — QR codes on parking meters and payment scamsOfficial documentation checked 9 October 2026
Open full-size image (new tab)