The QR Code Sticker Scam: When Your Own Signage Phishes Your Customers
Bottom line up front
The FTC put out a consumer alert on 3 September about scammers pasting their own QR codes over the ones on parking meters. Read it as a business story instead of a consumer one and it says something uncomfortable: a two-dollar sticker on equipment you own can turn your own signage into a phishing page, and nothing in your security stack will ever see it. The detection is a person walking past and looking. That is not a joke about awareness training — in every case I could find this year, that is literally how it was caught.
Kelowna, British Columbia, the evening of 11 February. City security cameras record three people moving between pay stations at around 7pm. What they are doing is putting decals on the machines, directly over the tap readers, printed with something that looks close enough to the PayByPhone logo to pass. The next day a staff member notices one, and by that afternoon crews have pulled all seventy-five of them.
Seventy-five. In one small city, in one night, by three people with a printer.
The FTC alert published on 3 September is written for the driver, and it gives the driver reasonable advice: preview the link, keep the phone patched, use strong passwords. Fine. But the driver is not the one who owns the parking meter, the EV charger, the table tent, the donation box by the door, or the laminated sign in the window that says scan to pay. Somebody does own those, and this year that somebody has mostly found out about the problem from a customer.
The first hour after somebody reports a sticker
If you have public-facing QR codes and a customer tells you one of them took them somewhere strange, this is the order that works. It is short on purpose.
- Do not scan it to see where it goes. Photograph it, at an angle that shows the edges. Then remove it and keep it — it is evidence and it may carry a fingerprint or a print-shop tell.
- Check every other unit you own before you do anything else. Kelowna found seventy-five. Asheville found about twenty across four downtown streets. Nobody who has been hit by this found exactly one.
- Tell the payment provider whose logo was copied. This is the step most businesses skip and it is the one that scales. Kelowna notified PayByPhone, and PayByPhone got the fraudulent site blocked — faster than a registrar complaint from a city would have gone.
- Post the real payment methods, in the same physical place. Not on your website. On the machine, at the counter, on the door. The customer standing there with a phone is the only audience that matters.
- Report it. Local police for the tampering, ReportFraud.ftc.gov for the fraud, and BBB Scam Tracker so the pattern shows up somewhere other than your inbox.
- Write down what customers tell you. Which unit, what the page looked like, what the domain was, what got charged. You have no logs for this attack. Their account of it is the only telemetry that exists.
What physical QR tampering is
Physical QR tampering is quishing delivered by hand: an attacker covers a legitimate QR code on equipment or signage with a sticker of their own, so a customer scanning what looks like your payment code lands on a look-alike site that captures card details or credentials. Nothing touches the business network.
Eight months of this, before the FTC alert
The alert landed on 3 September, but the reports it is built on have been arriving all year, from cities that mostly announced the problem themselves after finding it themselves.
Raleigh first flagged it on New Year’s Eve, with stickers on downtown lots and street meters reading “Scan here to pay for parking.” The city’s own use of QR codes is narrow — violations and garage tickets, nothing on a meter — which is what made the fakes identifiable at all. Asked how many people had scanned them, a spokesperson said they had no idea, because the codes came down immediately. That is worth sitting with. The response that protects customers is also the response that destroys your only chance of measuring the damage.
Asheville followed on 24 February with roughly twenty stickers on Biltmore Avenue, Coxe Avenue, Pack Square and South Market Street, and a sentence any operator should copy verbatim: “The City does not use QR codes on parking meters, and parking customers should not scan any codes to pay for parking.” Then Kelowna in February, with the seventy-five decals and the security-camera footage. Similar decals turned up in Whistler; police in Penticton had warned about the same scheme the previous August.
None of this is new, exactly. Redondo Beach found counterfeit stickers on about 150 meters back in 2024, placed neatly alongside the genuine ParkMobile and PayByPhone labels rather than over them, which is arguably worse — a code sitting next to two real brand marks reads as a third legitimate option. The Identity Theft Resource Center covered it at the time, and the advice from ITRC’s Eva Velasquez has held up better than most: know the real web address of the payment service your city uses.
Stages assembled from the FTC consumer alert of 3 September 2026, City of Asheville (24 February 2026), Global News on the City of Kelowna (18 February 2026), WRAL on the City of Raleigh (17 January 2026), and BBB Scam Tracker reports. Compiled by ScamDrill, September 2026.
Nothing fires, nobody logs it, and that is the whole problem
Walk the attack from your side of the counter and count the places you would normally get a signal.
The sticker is applied — no alert, it is a physical act on a physical object. The customer scans it — no alert, their phone talks to a domain that has never been near your network. They land on a look-alike payment page — no alert, your web analytics never see a session that was never on your site. They enter a card — no alert, the money goes to the attacker’s processor, not to a declined transaction in your merchant dashboard. Your revenue for that space is simply, quietly, missing, and one absent parking payment looks exactly like one person who chose not to pay.
Four steps, zero telemetry. Compare that to a phishing email aimed at your staff, where at minimum you get a filter verdict, a click log, and a user who can report it.
There is a version of this argument I have made before about patient portal phishing, where an attacker borrows a health system’s brand to reach patients directly and the provider has no control surface at all. This is the same shape with one important difference, and the difference is in your favour: the attack has a physical component, and the physical component is on property you control. You cannot inspect somebody else’s inbox. You can absolutely inspect your own machine.
That is the whole opportunity here, and it is why I think this is a genuinely tractable problem rather than another thing to feel bad about. The control is a walk-round. It costs a few minutes.
The number everyone quotes is measuring the other channel
If you have read anything about QR phishing this year you have probably seen Microsoft’s figures. They are real and they are worth knowing. Microsoft Threat Intelligence detected roughly 8.3 billion email-based phishing threats in Q1 2026, and inside that, QR code phishing went from 7.6 million attacks in January to 18.7 million in March — a 146% jump in a quarter, the fastest-growing vector they tracked. Most of it arrived as PDF attachments, rising from 65% to 70% of QR attacks over the quarter, with codes pasted straight into the email body emerging late and surging 336% in March.
Every number in that paragraph describes email. Microsoft measures what passes through Microsoft’s mail infrastructure, which is a lot, and it is exactly the wrong instrument for a sticker on a lamppost. There is no comparable telemetry for physical tampering and, as far as I can tell, no national count of it at all. What we have instead is a scatter of municipal press releases, a BBB alert, an FTC consumer alert, and the number of stickers each city happened to peel off.
So when somebody tells you QR phishing grew 146%, the honest translation is: the measurable channel grew 146%, and the unmeasurable one is going on at a rate nobody knows. I would not assume the unmeasured one is smaller. Cheap, physical, deniable attacks tend to be underreported, and this one leaves no artifact at all once the sticker is gone.
The FBI, for what it is worth, treats the delivery method as beside the point. Its January 2026 FLASH on quishing — written about a North Korean group phishing think tanks, not about parking meters — defines the technique as forcing the victim to pivot from a corporate endpoint to a mobile device, “bypassing traditional email security controls,” and tells organisations to train staff on unsolicited QR codes “regardless of their source (email, letter, flyer, packaging).” Packaging. Flyers. The Bureau is already thinking about codes that arrive on paper.
It is not only parking meters
Parking is where the reporting is, because cities publish and journalists cover cities. The exposure is much broader, and it is a decent bet that the private-sector version is simply going unreported.
In March, Entergy warned New Orleans drivers that fake QR stickers had appeared on public EV chargers, telling people the utility does not use QR codes for payment at all. It runs roughly thirty Level 2 chargers across twenty-five sites — parks, libraries, attractions. High-traffic locations, which is the point for the operator and equally the point for whoever brought the stickers.
Run the same logic across a normal commercial street and the list gets long fast:
| Where the code lives | What the fake page asks for | How long it can sit there |
|---|---|---|
| Restaurant table tents and menu cards | Card details for a “pay at table” flow, or an account login for your loyalty app | Until a server notices. Table tents get wiped, rarely read. |
| EV chargers and parking equipment | Card details, or credentials for the charging network app | Unattended sites can go days between staff visits. |
| Gyms, salons, self-storage, laundromats | Recurring-payment signup, which is the back end BBB reports keep describing | Long. Nobody owns the poster by the door. |
| Donation boxes, church and nonprofit signage | A “donation” that is a straight card capture | Longest of all. Volunteers change weekly. |
| Event venues, festival signage, trade show booths | Ticket or badge payment, plus a full contact-details form | The event ends before anyone reconciles. |
| Delivery lockers, notices taped to a door | A redelivery fee, which is the toll-text scam wearing a different hat | Indefinite. It is a piece of paper. |
The BBB reports are the ones I find most instructive, because they show the back end is often not what people picture. Two consumers described paying for parking and then discovering the charge was a recurring subscription — one for $39.99, one for around $49.99, both to an unrelated company, one of them apparently a streaming service. That is not a smash-and-grab on a card number. It is a subscription-billing business with a customer acquisition channel made of stickers, and it is designed to survive the first statement review because $39.99 looks like something you might have signed up for.
If your customers do get taken this way, they will very reasonably describe it as getting scammed at your business. Whether that is fair is a separate conversation from whether it happens.
What Kelowna got right
I keep coming back to that one because the response was close to ideal and none of it required a security budget.
Their parking services manager said something that reads like a throwaway line and is actually the whole strategy: they do not use QR codes on their pay stations or anywhere near their equipment, precisely because they have had the occasional issue with codes being placed on their meters. They removed the attack surface. Any code on that machine is a fake by definition, which turns a judgement call into a rule that a summer student can apply.
Then: staff spotted it, staff reported it internally, crews cleared all seventy-five within hours, and the city contacted the payment brand whose logo had been copied so the fraudulent site could be blocked for everybody, not just for Kelowna. Officials believe nobody was taken. The RCMP got camera footage of three people applying decals.
Four moves. Eliminate, inspect, remove, notify the impersonated brand. That is the playbook, and it works at the scale of a coffee shop as well as a city.
Five controls, cheapest first
Controls derived from the City of Kelowna and City of Asheville responses (February 2026), FBI FLASH AC-000001-MW (8 January 2026), and FTC consumer guidance (3 September 2026). Compiled by ScamDrill, September 2026.
1. Know exactly where your codes are, and post the list
Most businesses cannot answer “how many customer-facing QR codes do we have and where are they” without walking the building. Walk it once and write it down. The inventory is what makes an unfamiliar code obviously unfamiliar, and it is what lets you tell a customer with confidence that the code they scanned was not yours.
2. Consider not having one
The Kelowna move. If a tap reader, a card slot, or a short URL a person can type does the job, a QR code buys you convenience and sells the attacker a delivery channel. That trade is worth re-examining for payment specifically. Menus and Wi-Fi are a different risk; a code that asks for a card is the one worth being precious about.
3. Make tampering visible
Print codes onto the equipment or the laminate rather than applying them as a separate label, so a sticker sits on top of something rather than blending into a row of stickers. Tamper-evident overlays are cheap. A hairline border in a colour a photocopier struggles with helps. None of this stops a determined person; all of it shortens the time from application to noticed.
4. Put it in the opening checklist
This is the one that actually works and it is free. Whoever opens looks at every customer-facing code — is it raised, is it a different white, is the corner lifting, does it cover something. Ten seconds a code. Every reported case this year was found by a person looking, and in Kelowna that person was on staff, which is why the damage was zero.
5. Use a domain a customer can recognise
If your real payment link is a URL shortener or some processor subdomain nobody has heard of, you have taught your own customers that a strange domain is normal, and you have thrown away their best defence. BBB flags shortened links as a red flag for exactly this reason. Put payment on a subdomain of your own name, print that address next to the code in plain text, and the fake becomes checkable without any expertise at all.
Your team’s real skill is spotting a look-alike domain
Every version of this attack ends on a page that is almost your page. ScamDrill runs realistic email phishing drills for small teams, so the person who has to make that call has already made it before, in a situation where being wrong was free.
See how drills work for teams →What the person at the counter should say
Whoever answers is going to have this conversation cold, probably with someone upset, possibly with someone who is out $39.99 and blames you. Give them four lines.
| They say | Say this | Not this |
|---|---|---|
| “I scanned the code and it charged me.” | “That code isn’t ours. Our only payment methods here are [X and Y]. Call your card issuer using the number on the back of the card and tell them it was a fraudulent charge — the sooner the better.” | “Let me look into it and call you back.” The card call is time-sensitive; do not be the delay. |
| “Was your system hacked?” | “No. Somebody physically put a sticker on our equipment. Nothing of ours was accessed. We’ve removed it and we’re checking the rest.” | “We’re investigating.” Technically safe, and it reads as a yes. |
| “I gave them my card number. What now?” | “Call your issuer and ask them to watch for recurring charges, not just one. These often set up a subscription rather than a single charge.” | “Just keep an eye on your statement.” The recurring pattern is the specific thing to warn about. |
| “There’s a weird sticker on that machine.” | “Thank you — don’t scan it. I’ll get a photo and take it off, and I’ll check the others.” | Scanning it yourself to see where it goes. |
If it helps to give somebody something concrete, our link checker is free and needs no account, so a customer standing at your counter can paste in whatever they landed on and get a read.
When a customer says they already paid
Be careful here, and be honest. You cannot get their money back and you should not suggest you can. What you can do is compress the time between the charge and the phone call to their bank, because that window is most of what determines whether a dispute goes anywhere.
Tell them to call the issuer directly using the number printed on the card — never a number from the site they just used — and to ask specifically about recurring authorisations, not only the single charge they noticed. If they entered a password rather than a card, the password is the bigger problem, and it needs changing anywhere they reused it. Point them at ReportFraud.ftc.gov, which is the FTC’s own instruction in the 3 September alert.
One thing worth saying out loud
Whether a business carries any legal exposure when a customer is defrauded by a sticker on its property is not a settled question, and it will depend on jurisdiction, on the contract with your payment provider, and on what you knew. I am not a lawyer and this is not legal advice. What I would say plainly is that “we had no way to know” is a much weaker position after the FTC has published a national alert about it than it was the week before it.
The part that lasts
This particular wave will move on. Cities will pull the stickers, one payment brand will get better at takedowns, and the crews will go find something else to put a sticker on.
What stays is the structural thing. A QR code is a link you cannot read, printed on an object anyone can reach, pointing at a destination you never see. We spent five years training the public to scan those without thinking, and we did it because it was convenient, and the convenience was real. The bill for it is a category of attack where the delivery mechanism is a printer and a roll of adhesive, and where the only detection that exists is somebody noticing.
So the useful question is not how to defend against QR phishing in the abstract. It is narrower and much more answerable: which codes on my property ask a customer for money, and when did anybody last look at them. If you run a small team, our small business overview covers where drills sit next to controls like these, and the incident response guide covers the wider “something just happened” sequence. For the version of quishing that arrives in a mailbox rather than on a lamppost, there is the QR card in an unordered package, and for the one that reaches a teenager’s phone, the quishing guide.
Go look at your codes. It takes ten minutes and you will probably find nothing, which is the correct and boring outcome.