The QR Code Sticker Scam: When Your Own Signage Phishes Your Customers

Cover graphic on a deep navy field reading 75 fake QR codes, zero alerts, beside a QR code with a counterfeit amber sticker pasted crookedly over its lower corner, tagged not your code.

Bottom line up front

The FTC put out a consumer alert on 3 September about scammers pasting their own QR codes over the ones on parking meters. Read it as a business story instead of a consumer one and it says something uncomfortable: a two-dollar sticker on equipment you own can turn your own signage into a phishing page, and nothing in your security stack will ever see it. The detection is a person walking past and looking. That is not a joke about awareness training — in every case I could find this year, that is literally how it was caught.

Kelowna, British Columbia, the evening of 11 February. City security cameras record three people moving between pay stations at around 7pm. What they are doing is putting decals on the machines, directly over the tap readers, printed with something that looks close enough to the PayByPhone logo to pass. The next day a staff member notices one, and by that afternoon crews have pulled all seventy-five of them.

Seventy-five. In one small city, in one night, by three people with a printer.

The FTC alert published on 3 September is written for the driver, and it gives the driver reasonable advice: preview the link, keep the phone patched, use strong passwords. Fine. But the driver is not the one who owns the parking meter, the EV charger, the table tent, the donation box by the door, or the laminated sign in the window that says scan to pay. Somebody does own those, and this year that somebody has mostly found out about the problem from a customer.

The first hour after somebody reports a sticker

If you have public-facing QR codes and a customer tells you one of them took them somewhere strange, this is the order that works. It is short on purpose.

  1. Do not scan it to see where it goes. Photograph it, at an angle that shows the edges. Then remove it and keep it — it is evidence and it may carry a fingerprint or a print-shop tell.
  2. Check every other unit you own before you do anything else. Kelowna found seventy-five. Asheville found about twenty across four downtown streets. Nobody who has been hit by this found exactly one.
  3. Tell the payment provider whose logo was copied. This is the step most businesses skip and it is the one that scales. Kelowna notified PayByPhone, and PayByPhone got the fraudulent site blocked — faster than a registrar complaint from a city would have gone.
  4. Post the real payment methods, in the same physical place. Not on your website. On the machine, at the counter, on the door. The customer standing there with a phone is the only audience that matters.
  5. Report it. Local police for the tampering, ReportFraud.ftc.gov for the fraud, and BBB Scam Tracker so the pattern shows up somewhere other than your inbox.
  6. Write down what customers tell you. Which unit, what the page looked like, what the domain was, what got charged. You have no logs for this attack. Their account of it is the only telemetry that exists.

What physical QR tampering is

Physical QR tampering is quishing delivered by hand: an attacker covers a legitimate QR code on equipment or signage with a sticker of their own, so a customer scanning what looks like your payment code lands on a look-alike site that captures card details or credentials. Nothing touches the business network.

Eight months of this, before the FTC alert

The alert landed on 3 September, but the reports it is built on have been arriving all year, from cities that mostly announced the problem themselves after finding it themselves.

Raleigh first flagged it on New Year’s Eve, with stickers on downtown lots and street meters reading “Scan here to pay for parking.” The city’s own use of QR codes is narrow — violations and garage tickets, nothing on a meter — which is what made the fakes identifiable at all. Asked how many people had scanned them, a spokesperson said they had no idea, because the codes came down immediately. That is worth sitting with. The response that protects customers is also the response that destroys your only chance of measuring the damage.

Asheville followed on 24 February with roughly twenty stickers on Biltmore Avenue, Coxe Avenue, Pack Square and South Market Street, and a sentence any operator should copy verbatim: “The City does not use QR codes on parking meters, and parking customers should not scan any codes to pay for parking.” Then Kelowna in February, with the seventy-five decals and the security-camera footage. Similar decals turned up in Whistler; police in Penticton had warned about the same scheme the previous August.

None of this is new, exactly. Redondo Beach found counterfeit stickers on about 150 meters back in 2024, placed neatly alongside the genuine ParkMobile and PayByPhone labels rather than over them, which is arguably worse — a code sitting next to two real brand marks reads as a third legitimate option. The Identity Theft Resource Center covered it at the time, and the advice from ITRC’s Eva Velasquez has held up better than most: know the real web address of the payment service your city uses.

Figure 01 · A sticker, and the four places nothing happens
1STEP 1 · THE STICKERApplied by hand, in about four secondsKelowna’s cameras caught three people tagging pay stations at 7pm.Seventy-five decals went on in one evening, placed over the tap readers.WHAT FIRES ON YOUR SIDE: NOTHING — IT IS A PHYSICAL ACT2STEP 2 · THE SCANA customer’s phone, a domain that is not yoursThe code resolves somewhere you have never heard of. Your network isnot involved and your analytics never see the session.WHAT FIRES: NOTHING — NO TRAFFIC REACHES YOU3STEP 3 · THE PAGEA payment screen wearing a borrowed logoKelowna’s fakes copied the PayByPhone mark. Others simply read “Scanhere to pay for parking” and look official enough.WHAT FIRES: NOTHING — IT IS NOT YOUR SITE4STEP 4 · THE CHARGEOften a subscription, not a single hitBBB reports describe $39.99 and roughly $49.99 recurring charges tounrelated companies — sized to survive a statement review.WHAT FIRES: NOTHING — THE MONEY NEVER TOUCHED YOU5STEP 5 · THE REPORTSomebody walks past and looksThis is the detection. In every 2026 case on record it was a staff memberor a customer noticing a sticker, not a security control.THE ONLY THING THAT FIRES IS A PERSON

Stages assembled from the FTC consumer alert of 3 September 2026, City of Asheville (24 February 2026), Global News on the City of Kelowna (18 February 2026), WRAL on the City of Raleigh (17 January 2026), and BBB Scam Tracker reports. Compiled by ScamDrill, September 2026.

Nothing fires, nobody logs it, and that is the whole problem

Walk the attack from your side of the counter and count the places you would normally get a signal.

The sticker is applied — no alert, it is a physical act on a physical object. The customer scans it — no alert, their phone talks to a domain that has never been near your network. They land on a look-alike payment page — no alert, your web analytics never see a session that was never on your site. They enter a card — no alert, the money goes to the attacker’s processor, not to a declined transaction in your merchant dashboard. Your revenue for that space is simply, quietly, missing, and one absent parking payment looks exactly like one person who chose not to pay.

Four steps, zero telemetry. Compare that to a phishing email aimed at your staff, where at minimum you get a filter verdict, a click log, and a user who can report it.

There is a version of this argument I have made before about patient portal phishing, where an attacker borrows a health system’s brand to reach patients directly and the provider has no control surface at all. This is the same shape with one important difference, and the difference is in your favour: the attack has a physical component, and the physical component is on property you control. You cannot inspect somebody else’s inbox. You can absolutely inspect your own machine.

That is the whole opportunity here, and it is why I think this is a genuinely tractable problem rather than another thing to feel bad about. The control is a walk-round. It costs a few minutes.

The number everyone quotes is measuring the other channel

If you have read anything about QR phishing this year you have probably seen Microsoft’s figures. They are real and they are worth knowing. Microsoft Threat Intelligence detected roughly 8.3 billion email-based phishing threats in Q1 2026, and inside that, QR code phishing went from 7.6 million attacks in January to 18.7 million in March — a 146% jump in a quarter, the fastest-growing vector they tracked. Most of it arrived as PDF attachments, rising from 65% to 70% of QR attacks over the quarter, with codes pasted straight into the email body emerging late and surging 336% in March.

7.6M → 18.7M Monthly QR code phishing attacks detected by Microsoft, January to March 2026 — a 146% rise in one quarter. Every one of them arrived by email. Microsoft Threat Intelligence, “Email threat landscape: Q1 2026 trends and insights,” 30 April 2026.

Every number in that paragraph describes email. Microsoft measures what passes through Microsoft’s mail infrastructure, which is a lot, and it is exactly the wrong instrument for a sticker on a lamppost. There is no comparable telemetry for physical tampering and, as far as I can tell, no national count of it at all. What we have instead is a scatter of municipal press releases, a BBB alert, an FTC consumer alert, and the number of stickers each city happened to peel off.

So when somebody tells you QR phishing grew 146%, the honest translation is: the measurable channel grew 146%, and the unmeasurable one is going on at a rate nobody knows. I would not assume the unmeasured one is smaller. Cheap, physical, deniable attacks tend to be underreported, and this one leaves no artifact at all once the sticker is gone.

The FBI, for what it is worth, treats the delivery method as beside the point. Its January 2026 FLASH on quishing — written about a North Korean group phishing think tanks, not about parking meters — defines the technique as forcing the victim to pivot from a corporate endpoint to a mobile device, “bypassing traditional email security controls,” and tells organisations to train staff on unsolicited QR codes “regardless of their source (email, letter, flyer, packaging).” Packaging. Flyers. The Bureau is already thinking about codes that arrive on paper.

It is not only parking meters

Parking is where the reporting is, because cities publish and journalists cover cities. The exposure is much broader, and it is a decent bet that the private-sector version is simply going unreported.

In March, Entergy warned New Orleans drivers that fake QR stickers had appeared on public EV chargers, telling people the utility does not use QR codes for payment at all. It runs roughly thirty Level 2 chargers across twenty-five sites — parks, libraries, attractions. High-traffic locations, which is the point for the operator and equally the point for whoever brought the stickers.

Run the same logic across a normal commercial street and the list gets long fast:

Where the code livesWhat the fake page asks forHow long it can sit there
Restaurant table tents and menu cardsCard details for a “pay at table” flow, or an account login for your loyalty appUntil a server notices. Table tents get wiped, rarely read.
EV chargers and parking equipmentCard details, or credentials for the charging network appUnattended sites can go days between staff visits.
Gyms, salons, self-storage, laundromatsRecurring-payment signup, which is the back end BBB reports keep describingLong. Nobody owns the poster by the door.
Donation boxes, church and nonprofit signageA “donation” that is a straight card captureLongest of all. Volunteers change weekly.
Event venues, festival signage, trade show boothsTicket or badge payment, plus a full contact-details formThe event ends before anyone reconciles.
Delivery lockers, notices taped to a doorA redelivery fee, which is the toll-text scam wearing a different hatIndefinite. It is a piece of paper.

The BBB reports are the ones I find most instructive, because they show the back end is often not what people picture. Two consumers described paying for parking and then discovering the charge was a recurring subscription — one for $39.99, one for around $49.99, both to an unrelated company, one of them apparently a streaming service. That is not a smash-and-grab on a card number. It is a subscription-billing business with a customer acquisition channel made of stickers, and it is designed to survive the first statement review because $39.99 looks like something you might have signed up for.

If your customers do get taken this way, they will very reasonably describe it as getting scammed at your business. Whether that is fair is a separate conversation from whether it happens.

What Kelowna got right

I keep coming back to that one because the response was close to ideal and none of it required a security budget.

Their parking services manager said something that reads like a throwaway line and is actually the whole strategy: they do not use QR codes on their pay stations or anywhere near their equipment, precisely because they have had the occasional issue with codes being placed on their meters. They removed the attack surface. Any code on that machine is a fake by definition, which turns a judgement call into a rule that a summer student can apply.

Then: staff spotted it, staff reported it internally, crews cleared all seventy-five within hours, and the city contacted the payment brand whose logo had been copied so the fraudulent site could be blocked for everybody, not just for Kelowna. Officials believe nobody was taken. The RCMP got camera footage of three people applying decals.

Four moves. Eliminate, inspect, remove, notify the impersonated brand. That is the playbook, and it works at the scale of a coffee shop as well as a city.

Five controls, cheapest first

Figure 02 · Five controls, cheapest first
1CONTROL 1 · FREEInventory every customer-facing codeWalk the building once and write the list down. An unfamiliar code is onlyobviously unfamiliar against a list of the familiar ones.2CONTROL 2 · FREEConsider not having a payment code at allKelowna keeps QR codes off its pay stations entirely, so any code on themachine is a fake by definition. That turns judgement into a rule.3CONTROL 3 · CHEAPMake tampering visiblePrint onto the equipment rather than applying a separate label, and usetamper-evident overlays. It shortens time-to-noticed, nothing more.4CONTROL 4 · FREE, AND THE ONE THAT WORKSTen seconds a code, in the opening checklistRaised edge, different white, lifting corner, covering something. Every casecaught this year was caught by a person looking.5CONTROL 5 · ONE-OFFUse a domain your customer can recognisePayment on a subdomain of your own name, printed in plain text besidethe code. A shortener teaches customers that strange domains arenormal.

Controls derived from the City of Kelowna and City of Asheville responses (February 2026), FBI FLASH AC-000001-MW (8 January 2026), and FTC consumer guidance (3 September 2026). Compiled by ScamDrill, September 2026.

1. Know exactly where your codes are, and post the list

Most businesses cannot answer “how many customer-facing QR codes do we have and where are they” without walking the building. Walk it once and write it down. The inventory is what makes an unfamiliar code obviously unfamiliar, and it is what lets you tell a customer with confidence that the code they scanned was not yours.

2. Consider not having one

The Kelowna move. If a tap reader, a card slot, or a short URL a person can type does the job, a QR code buys you convenience and sells the attacker a delivery channel. That trade is worth re-examining for payment specifically. Menus and Wi-Fi are a different risk; a code that asks for a card is the one worth being precious about.

3. Make tampering visible

Print codes onto the equipment or the laminate rather than applying them as a separate label, so a sticker sits on top of something rather than blending into a row of stickers. Tamper-evident overlays are cheap. A hairline border in a colour a photocopier struggles with helps. None of this stops a determined person; all of it shortens the time from application to noticed.

4. Put it in the opening checklist

This is the one that actually works and it is free. Whoever opens looks at every customer-facing code — is it raised, is it a different white, is the corner lifting, does it cover something. Ten seconds a code. Every reported case this year was found by a person looking, and in Kelowna that person was on staff, which is why the damage was zero.

5. Use a domain a customer can recognise

If your real payment link is a URL shortener or some processor subdomain nobody has heard of, you have taught your own customers that a strange domain is normal, and you have thrown away their best defence. BBB flags shortened links as a red flag for exactly this reason. Put payment on a subdomain of your own name, print that address next to the code in plain text, and the fake becomes checkable without any expertise at all.

Your team’s real skill is spotting a look-alike domain

Every version of this attack ends on a page that is almost your page. ScamDrill runs realistic email phishing drills for small teams, so the person who has to make that call has already made it before, in a situation where being wrong was free.

See how drills work for teams →

What the person at the counter should say

Whoever answers is going to have this conversation cold, probably with someone upset, possibly with someone who is out $39.99 and blames you. Give them four lines.

They saySay thisNot this
“I scanned the code and it charged me.” “That code isn’t ours. Our only payment methods here are [X and Y]. Call your card issuer using the number on the back of the card and tell them it was a fraudulent charge — the sooner the better.” “Let me look into it and call you back.” The card call is time-sensitive; do not be the delay.
“Was your system hacked?” “No. Somebody physically put a sticker on our equipment. Nothing of ours was accessed. We’ve removed it and we’re checking the rest.” “We’re investigating.” Technically safe, and it reads as a yes.
“I gave them my card number. What now?” “Call your issuer and ask them to watch for recurring charges, not just one. These often set up a subscription rather than a single charge.” “Just keep an eye on your statement.” The recurring pattern is the specific thing to warn about.
“There’s a weird sticker on that machine.” “Thank you — don’t scan it. I’ll get a photo and take it off, and I’ll check the others.” Scanning it yourself to see where it goes.

If it helps to give somebody something concrete, our link checker is free and needs no account, so a customer standing at your counter can paste in whatever they landed on and get a read.

When a customer says they already paid

Be careful here, and be honest. You cannot get their money back and you should not suggest you can. What you can do is compress the time between the charge and the phone call to their bank, because that window is most of what determines whether a dispute goes anywhere.

Tell them to call the issuer directly using the number printed on the card — never a number from the site they just used — and to ask specifically about recurring authorisations, not only the single charge they noticed. If they entered a password rather than a card, the password is the bigger problem, and it needs changing anywhere they reused it. Point them at ReportFraud.ftc.gov, which is the FTC’s own instruction in the 3 September alert.

One thing worth saying out loud

Whether a business carries any legal exposure when a customer is defrauded by a sticker on its property is not a settled question, and it will depend on jurisdiction, on the contract with your payment provider, and on what you knew. I am not a lawyer and this is not legal advice. What I would say plainly is that “we had no way to know” is a much weaker position after the FTC has published a national alert about it than it was the week before it.

The part that lasts

This particular wave will move on. Cities will pull the stickers, one payment brand will get better at takedowns, and the crews will go find something else to put a sticker on.

What stays is the structural thing. A QR code is a link you cannot read, printed on an object anyone can reach, pointing at a destination you never see. We spent five years training the public to scan those without thinking, and we did it because it was convenient, and the convenience was real. The bill for it is a category of attack where the delivery mechanism is a printer and a roll of adhesive, and where the only detection that exists is somebody noticing.

So the useful question is not how to defend against QR phishing in the abstract. It is narrower and much more answerable: which codes on my property ask a customer for money, and when did anybody last look at them. If you run a small team, our small business overview covers where drills sit next to controls like these, and the incident response guide covers the wider “something just happened” sequence. For the version of quishing that arrives in a mailbox rather than on a lamppost, there is the QR card in an unordered package, and for the one that reaches a teenager’s phone, the quishing guide.

Go look at your codes. It takes ten minutes and you will probably find nothing, which is the correct and boring outcome.

Frequently asked questions

If someone puts a fake QR sticker on our property, are we liable?

That is not a settled question and it will turn on your jurisdiction, your merchant agreement, and what you knew. I am not a lawyer and this is not legal advice. What I would say practically is that the defence of “we had no way to know this was a thing” got weaker on 3 September 2026, when the FTC published a national consumer alert about it. If you have customer-facing payment codes, it is worth a short conversation with whoever handles your contracts, and worth being able to show that you inspect them.

How do we prove to a customer that our QR code is the real one?

Print the destination in plain text next to the code and make that destination recognisable — a subdomain of your own name rather than a link shortener or an unfamiliar processor domain. Then a customer can compare what their phone previews against what is printed on the sign, without needing to know anything about security. If your genuine link is already something opaque, you have trained your own customers that strange addresses are normal, which is the condition the attacker needs.

Should we just get rid of our payment QR codes?

For payment specifically, it is worth asking. Kelowna keeps QR codes off its pay stations and away from the equipment entirely, which means any code on the machine is a fake by definition — a rule a new employee can apply on day one rather than a judgement call. If a tap reader, a card slot, or a short typed URL does the job for your customers, the code is buying convenience and selling a delivery channel. Menus and Wi-Fi codes are a much lower-stakes question.

How often should we actually be checking?

Put it in the opening routine and check every customer-facing code, every day. It is about ten seconds per code: is it raised, is the white a different shade, is a corner lifting, is it covering something. Unattended sites — chargers, lockers, a lot in another part of town — need a scheduled walk instead, because those are the ones that can sit compromised for days. Kelowna's seventy-five decals were found by a staff member the day after they went up, and the damage was believed to be zero.

A customer says they were charged after scanning. What do we tell them?

Tell them the code was not yours, name your real payment methods, and get them calling their card issuer immediately using the number printed on the card rather than any number from the site they just used. Ask them to check for recurring authorisations, not only the single charge — BBB Scam Tracker reports on this scam describe charges around $39.99 and $49.99 that turned out to be subscriptions to unrelated companies. Point them at ReportFraud.ftc.gov. Do not suggest the money can be recovered; that is between them and their bank, and it depends on how fast they move.

Does any of our security tooling help with this at all?

Not really, and it is worth being clear-eyed about it. Your mail filter never sees the message because there is no message. Your web filter never sees the site because the customer's phone is not on your network. Your merchant dashboard never sees the transaction because the money went somewhere else. The tooling that does help is adjacent rather than direct: look-alike domain monitoring will sometimes catch the registration, and staff who have been drilled on look-alike sign-in pages recognise the same trick faster when a customer describes it to them.