Tampered and unexpected codes that conceal harmful links.
A QR code hides its destination until a phone reads it. Scammers exploit that extra step by placing a sticker over a parking or payment code, or by sending an urgent code in an email or text about a package, account, or failed payment.
The code itself does not prove who created it. It can lead to a lookalike login page, a fraudulent payment destination, or an unwanted download. Preview the address, inspect physical codes for tampering, and use a known app or typed website for sensitive actions.
How the scam works
1
The code is placed or delivered
A malicious code appears on a sticker, sign, parking meter, flyer, email, or text where a legitimate code might be expected.
2
Urgency encourages the scan
A failed payment, delivery problem, security alert, or limited-time offer pushes you to open the hidden destination without checking.
3
The destination imitates trust
The browser opens a spoofed login or payment page whose branding looks familiar while the actual domain is different.
4
Credentials or money are redirected
Information entered goes to the scammer, a payment is sent to the wrong recipient, or the page tries to persuade you to install an app.
Red flags to watch for
!
A sticker covers another code
Raised edges, mismatched printing, or a code pasted over a meter or sign can indicate physical tampering.
!
An unexpected code demands action
Do not scan a code from an unsolicited message that claims your package, account, or payment needs immediate attention.
!
The previewed address is slightly wrong
Misspellings, switched letters, unfamiliar domains, and shortened links can conceal an imitation site.
!
The code is the only payment option
If a message says a failed payment can only be fixed by scanning, contact the business through a known channel instead.
!
A download starts outside an app store
The FBI advises against downloading an app through a QR code. Use the official app store and verify the publisher.
What to do
✓
Pause at the URL preview
Do not open an address you do not recognize. For a known organization, close the preview and navigate through its official app or a web address you type yourself.
✓
Leave a suspicious page
Do not sign in, pay, or download anything. Close the page and remove any file or app you did not intend to install.
✓
Change submitted credentials
If you entered a password, use the real service to change it, sign out other sessions, and enable multi-factor authentication. Change reused passwords too.
✓
Protect payments and devices
Report misdirected payments to the bank or payment provider immediately. Keep the phone updated and review installed apps and account activity if a download occurred.
✓
Report the code
Tell the location owner about a tampered physical code. Report related fraud at ReportFraud.ftc.gov and IC3.gov, preserving the destination URL when safe to do so.
Frequently asked questions
Is it dangerous just to scan a QR code?
Scanning usually reveals or opens a destination; the greater risk comes from opening a deceptive site, entering information, paying, or installing software. Still, inspect the preview before proceeding.
Do I need a separate QR-scanner app?
No. The FBI advises against downloading one because most phones already scan codes through the camera. An extra scanner creates another unnecessary software risk.
How do I safely pay at a parking meter with a QR code?
Inspect the code for an overlaid sticker, preview the domain, and compare it with the operator named on the meter. When available, use the official app or type the operator's known website instead.