The FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters and phishing emails/texts using QR codes to steal credentials or install malware.
Reviewed by the Social Engineering Examples team.
On December 6, 2023, the FTC published a consumer alert titled "Scammers hide harmful links in QR codes to steal your information," written by consumer education specialist Alvaro Puig. It described two primary methods scammers were using to weaponize QR codes: (1) placing fraudulent QR-code stickers directly over legitimate codes in public places, notably parking meters, so a driver trying to pay for parking would instead be routed to a scammer-controlled page; and (2) emailing or texting QR codes paired with a fabricated urgent pretext, such as a failed package delivery, an account problem, or a claim of suspicious account activity requiring an immediate password reset. Scanning either type of malicious code could send the victim to a spoofed site designed to harvest login credentials, payment details, or personal information, or could silently install malware on the device. The alert followed a wave of parking-meter QR-sticker scams that police departments in San Antonio, Austin, and Houston, TX reported between December 2021 and January 2022 (fraudulent stickers routed drivers to a fake "passportlab.xyz" payment page), plus the FBI/IC3's own Public Service Announcement describing the general physical and digital QR-code tampering method (Jan 18, 2022, Alert I-011822-PSA, which did not name specific cities), and a later FBI El Paso field-office advisory (Sept 19, 2023) reiterating the same tactics and noting reports had been coming in since 2022. The FTC alert generated significant mainstream coverage, including from the New York Times, CNBC, Ars Technica, and The Verge, cementing "quishing" (QR phishing) as a recognized consumer threat category by the end of 2023.
For physical overlays: scammers printed their own QR-code stickers and affixed them on top of legitimate codes on parking meters and other public signage; a person scanning the sticker to pay for parking or access a service was instead redirected to a scam payment page that captured card details, or to a malicious link. For the email/text vector: scammers sent messages that could not easily be scanned by automated text-based spam/phishing filters because the malicious link was embedded as an image (the QR code) rather than as clickable text; the accompanying message manufactured urgency (a delivery failure, a locked account, suspicious sign-in activity) to pressure quick scanning without scrutiny. Because QR codes obscure the destination URL until after scanning, victims had no easy way to preview or verify the link before their phone camera or a scanning app opened it, which the FTC identified as the core exploit of consumer trust and habit around ubiquitous, pandemic-era-normalized QR code use.
Lure: an official-looking QR sticker on a parking meter, or an email/text with urgent framing ("Your package could not be delivered," "Unusual sign-in activity detected, verify your account," "Update your payment method now") accompanied by a QR code as the only actionable link. Tell (per FTC/FBI guidance): a QR code physically stuck over or slightly misaligned with existing signage; unsolicited QR codes arriving by email or text at all (legitimate parking, delivery, and account services rarely require scanning a code sent this way); after scanning, a URL that does not match the expected official domain, contains misspellings, or uses an unfamiliar shortener; requests for payment, password, or personal data immediately after scanning.
No law enforcement action, indictment, or named prosecution resulted from this alert; the FTC's and FBI's responses were both purely consumer-guidance advisories rather than enforcement actions. The FTC recommended inspecting the URL a QR code produces before interacting with the resulting site, treating unexpected QR codes in email/text as suspicious, verifying any urgent request through an independently looked-up phone number or website rather than the one provided, keeping phone operating systems updated, and using strong unique passwords plus multi-factor authentication. The FBI's parallel guidance recommended checking physical codes for signs of tampering (a sticker placed over the original), distrusting QR codes embedded in emails, and reporting suspected scams to the IC3 (Internet Crime Complaint Center).
This was the FTC's first major, widely publicized consumer alert specifically about QR code scams, and it functioned as a mainstream signal-flare that quishing had become common enough to warrant federal consumer guidance, roughly two years after the FBI's initial 2022 warning (the Jan 2022 IC3 PSA). It illustrates a structural detection gap: QR codes hide the destination URL from the human eye and from many automated email/SMS security filters that scan for embedded text-based links, letting the same phishing/malware playbook bypass defenses built for traditional link-based phishing. The parking-meter sticker vector also shows social engineering extending into physical and public infrastructure, not just digital channels, widening the attack surface security awareness training needs to cover.
Do not scan unsolicited or unexpected QR codes received via email or text; treat urgency-based framing (delivery failures, locked accounts, suspicious activity) attached to a QR code as a red flag; before scanning any public QR code, visually inspect it for signs it was pasted over an existing code (a raised edge, mismatched material, different sticker size); after scanning any QR code, review the full URL preview before tapping through, and check for misspellings or unfamiliar domains; never enter login credentials or payment information on a page reached via QR code without independently verifying the site through a known, bookmarked, or manually typed URL; enable multi-factor authentication and use unique passwords so a single harvested credential does not cascade; keep phone operating systems and camera/scanning apps updated; report suspected QR scams to the FTC (reportfraud.ftc.gov) or FBI IC3 (ic3.gov).
LevelBlue's MDR SOC documented a real client quishing case in which a PDF impersonating a Microsoft MFA-setup notice, hiding a…
Hornetsecurity documented a QR-phishing (quishing) email sent to a single employee at a US-based MSP that spoofed an MFA-reactivation notice…
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset,…