A QR code taped over a real one — on a parking meter or a “past-due” letter — can steal your bank login

A white car parked next to a parking meter

A small square of black-and-white dots has become one of the easiest tools a thief can use to reach into a bank account. Scammers print their own QR codes and paste them over genuine ones — on parking meters, storefront flyers, and letters dressed up to look like overdue bills — so a single scan sends a phone to a counterfeit page built to capture a login or a card number. For older Americans who increasingly pay bills and check balances by phone, that quiet swap can turn a routine errand into an account takeover.

How a pasted-over code hijacks a payment

The trick works because a QR code hides where it leads. A person scanning one cannot read the underlying web address the way they could read a printed link, so a fraudulent code and a real one look identical to the eye. Security researchers have taken to calling the tactic “quishing” — phishing carried inside a QR code rather than an email attachment.

The pattern is consistent across settings. The FTC has documented scammers who cover a legitimate QR code with one of their own and send codes by text or mail with a made-up reason to scan. The counterfeit destination often mimics a bank sign-in screen or a payment portal, capturing the username, password, and card details a person types in the belief they are settling a real charge.


Free retirement updates: Scam calls targeting retirees change every week. Our free Retirement Shield newsletter flags the ones going around and the one tell that stops each. Sign up free.

Why the counterfeit page fools careful people

Speed and context do the scammer’s work. A code on a meter carries the implied authority of the city; a “past-due” letter arrives with a logo and an account-looking number; a text invents a deadline. Each pushes for an immediate scan before the target pauses to question it, and because a phone’s browser opens the moment the camera reads the code, there is almost no friction between scanning and handing over credentials.

Some fake codes go a step further and prompt a download that installs malware capable of logging keystrokes or reading data already on the device. The FBI, which catalogs the most common fraud schemes reported nationwide, urges the public to treat unexpected messages that demand quick action as suspect, whatever the medium. A QR code is simply a newer wrapper on the same pressure tactics that have long driven phone and email fraud.

Where the fake codes turn up

The everyday places matter because they lower a person’s guard. Parking meters and pay-to-park lots are common targets, since drivers expect to pay a stranger’s machine quickly and move on. So are mailed notices claiming a bill, a toll, or a tax matter is past due, along with flyers taped to shop windows, menus left on restaurant tables, and stickers slapped onto electric-vehicle chargers. In each case the criminal is betting that a familiar-looking setting will make the code feel official enough to scan without a second thought.

Simple habits that defeat a swapped code

The defense costs nothing. Rather than scan a code printed on a meter or mailed in a notice, a person can type the known web address for the city, utility, or bank directly into a browser, or pay through an official app installed from a verified app store. Before scanning any code, it helps to check whether a sticker has been placed over the original and to preview the web address the code resolves to, watching for misspellings or a domain that does not match the company.

Unexpected codes deserve the most suspicion. A meter that has always taken coins or cards does not suddenly require a phone scan, and a legitimate bill can be paid through channels the account holder already uses. When a message claims a package could not be delivered or a small toll went unpaid, the safer move is to reach the company through a number or website looked up independently. It also helps to slow down at the moment of payment: a genuine bank or government portal shows a secure web address that matches the organization’s real domain, while a spoofed page often leans on a look-alike name, extra words, or a country code that does not belong.

Undoing the damage after a scan

Speed matters once a suspect link has been opened. A person who entered banking credentials on a page reached through a questionable code can change that password right away, turn on two-factor sign-in where the bank offers it, and call the institution on a trusted number to flag the account and watch for unauthorized transfers. Reviewing recent statements and setting alerts for new charges catches theft early, when a bank is most able to reverse it, and placing a free credit freeze blocks a thief from opening new accounts with stolen details. If the code prompted an app or file download, running the phone’s built-in security scan and deleting anything unfamiliar limits what malware can reach.

Keeping the evidence turns a private loss into something investigators can use. Photographing the tampered code, saving the fake notice, and noting where the sticker appeared gives the FTC and local authorities concrete leads, and reporting the incident adds to the record that helps regulators track how these schemes spread. The FTC’s core guidance holds across every version of the scam: inspect the destination before acting, and when a code arrives out of the blue, do not scan it at all.

This article was researched and drafted with AI assistance and reviewed against the linked primary sources.

More Financial Reading