Case Library / Quishing (QR Code Phishing) / FTC Consumer Alert: QR Code Scams (Quishing)

FTC Consumer Alert: QR Code Scams (Quishing)

The FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters and phishing emails/texts using QR codes to steal credentials or install malware.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

On December 6, 2023, the FTC published a consumer alert titled "Scammers hide harmful links in QR codes to steal your information," written by consumer education specialist Alvaro Puig. It described two primary methods scammers were using to weaponize QR codes: (1) placing fraudulent QR-code stickers directly over legitimate codes in public places, notably parking meters, so a driver trying to pay for parking would instead be routed to a scammer-controlled page; and (2) emailing or texting QR codes paired with a fabricated urgent pretext, such as a failed package delivery, an account problem, or a claim of suspicious account activity requiring an immediate password reset. Scanning either type of malicious code could send the victim to a spoofed site designed to harvest login credentials, payment details, or personal information, or could silently install malware on the device. The alert followed a wave of parking-meter QR-sticker scams that police departments in San Antonio, Austin, and Houston, TX reported between December 2021 and January 2022 (fraudulent stickers routed drivers to a fake "passportlab.xyz" payment page), plus the FBI/IC3's own Public Service Announcement describing the general physical and digital QR-code tampering method (Jan 18, 2022, Alert I-011822-PSA, which did not name specific cities), and a later FBI El Paso field-office advisory (Sept 19, 2023) reiterating the same tactics and noting reports had been coming in since 2022. The FTC alert generated significant mainstream coverage, including from the New York Times, CNBC, Ars Technica, and The Verge, cementing "quishing" (QR phishing) as a recognized consumer threat category by the end of 2023.

How the Attack Worked

For physical overlays: scammers printed their own QR-code stickers and affixed them on top of legitimate codes on parking meters and other public signage; a person scanning the sticker to pay for parking or access a service was instead redirected to a scam payment page that captured card details, or to a malicious link. For the email/text vector: scammers sent messages that could not easily be scanned by automated text-based spam/phishing filters because the malicious link was embedded as an image (the QR code) rather than as clickable text; the accompanying message manufactured urgency (a delivery failure, a locked account, suspicious sign-in activity) to pressure quick scanning without scrutiny. Because QR codes obscure the destination URL until after scanning, victims had no easy way to preview or verify the link before their phone camera or a scanning app opened it, which the FTC identified as the core exploit of consumer trust and habit around ubiquitous, pandemic-era-normalized QR code use.

The Lure & the Tell

Lure: an official-looking QR sticker on a parking meter, or an email/text with urgent framing ("Your package could not be delivered," "Unusual sign-in activity detected, verify your account," "Update your payment method now") accompanied by a QR code as the only actionable link. Tell (per FTC/FBI guidance): a QR code physically stuck over or slightly misaligned with existing signage; unsolicited QR codes arriving by email or text at all (legitimate parking, delivery, and account services rarely require scanning a code sent this way); after scanning, a URL that does not match the expected official domain, contains misspellings, or uses an unfamiliar shortener; requests for payment, password, or personal data immediately after scanning.

Outcome

No law enforcement action, indictment, or named prosecution resulted from this alert; the FTC's and FBI's responses were both purely consumer-guidance advisories rather than enforcement actions. The FTC recommended inspecting the URL a QR code produces before interacting with the resulting site, treating unexpected QR codes in email/text as suspicious, verifying any urgent request through an independently looked-up phone number or website rather than the one provided, keeping phone operating systems updated, and using strong unique passwords plus multi-factor authentication. The FBI's parallel guidance recommended checking physical codes for signs of tampering (a sticker placed over the original), distrusting QR codes embedded in emails, and reporting suspected scams to the IC3 (Internet Crime Complaint Center).

Why It Matters

This was the FTC's first major, widely publicized consumer alert specifically about QR code scams, and it functioned as a mainstream signal-flare that quishing had become common enough to warrant federal consumer guidance, roughly two years after the FBI's initial 2022 warning (the Jan 2022 IC3 PSA). It illustrates a structural detection gap: QR codes hide the destination URL from the human eye and from many automated email/SMS security filters that scan for embedded text-based links, letting the same phishing/malware playbook bypass defenses built for traditional link-based phishing. The parking-meter sticker vector also shows social engineering extending into physical and public infrastructure, not just digital channels, widening the attack surface security awareness training needs to cover.

Defenses

Do not scan unsolicited or unexpected QR codes received via email or text; treat urgency-based framing (delivery failures, locked accounts, suspicious activity) attached to a QR code as a red flag; before scanning any public QR code, visually inspect it for signs it was pasted over an existing code (a raised edge, mismatched material, different sticker size); after scanning any QR code, review the full URL preview before tapping through, and check for misspellings or unfamiliar domains; never enter login credentials or payment information on a page reached via QR code without independently verifying the site through a known, bookmarked, or manually typed URL; enable multi-factor authentication and use unique passwords so a single harvested credential does not cascade; keep phone operating systems and camera/scanning apps updated; report suspected QR scams to the FTC (reportfraud.ftc.gov) or FBI IC3 (ic3.gov).

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and target selection: Consistent with FTC and FBI guidance, scammers typically select high-footfall public payment infrastructure such as on-street parking meters, or draw on commonly effective phishing pretexts (failed package delivery, locked account, suspicious sign-in) that work at mass scale over email and SMS, rather than researching any specific individual victim.
Countering Stage 1: Public payment infrastructure and mass-phishing pretexts are inherently hard to hide from would-be scammers; the practical control is hardening the payment and notification channel itself (for example, cities posting official payment-app information at the point of use) rather than trying to prevent this kind of reconnaissance.
2
Infrastructure setup: Before deployment, scammers likely register look-alike or throwaway domains, such as the fake "passportlab.xyz" payment site documented in the Dec 2021-Jan 2022 Texas parking-meter incidents, and build spoofed login or payment pages designed to mimic the legitimate service.
Countering Stage 2: Domain-monitoring and takedown services, plus browser and OS phishing-domain blocklists, can flag newly registered look-alike domains quickly, and organizations running public payment systems can proactively register close domain variants themselves.
3
Code fabrication: Scammers print physical QR-code stickers styled to pass a casual glance as official signage, or embed a malicious QR code as an image inside a phishing email or text so the destination URL is hidden from automated, text-based link scanners, a technique Ars Technica's Dec 2023 reporting specifically flagged as evading anti-phishing filters.
Countering Stage 3: Email and SMS security gateways that decode embedded QR-code images and check the extracted URL against reputation and phishing-domain lists close the specific evasion gap Ars Technica described, treating the image-based link the same way a text-based one would be treated.
4
Distribution and placement: The sticker is physically affixed over the legitimate QR code on a parking meter or other public signage, or the phishing email or text is sent at mass scale using a fabricated urgent pretext designed to discourage careful inspection before scanning.
Countering Stage 4: Routine visual inspection of public payment signage by staff, as San Antonio, Austin, and Houston parking authorities did once alerted, can catch physical tampering, and awareness training that treats any unsolicited QR code in email or text as inherently suspicious addresses the digital distribution channel.
5
Victim scan and redirect: The victim scans the code with a phone camera or QR app, which opens the encoded URL without previewing it first, taking the victim to a spoofed site or triggering a malware download, per the FTC's and FBI's description of the mechanism.
Countering Stage 5: QR-scanning apps and phone camera software that display a full URL preview before opening it, paired with a user habit of actually checking that preview, directly interrupts this stage before the malicious page or file ever loads.
6
Credential or payment harvesting: On the spoofed page the victim enters login credentials, payment card details, or other personal information, which the scammer captures directly, or the device is compromised by malware installed during the redirect.
Countering Stage 6: Multi-factor authentication and unique per-site passwords limit the damage of a harvested credential, and up-to-date phone operating systems and mobile security software reduce the odds a malware payload executes successfully.
7
Monetization and follow-on fraud: Scammers use captured payment details for direct fraudulent charges, use or resell harvested personal information for broader identity theft, or leverage stolen account access for further account-takeover fraud, consistent with the payment-fraud and identity-theft objectives both the FTC and FBI flagged.
Countering Stage 7: Card issuers' fraud-monitoring and dispute or chargeback processes, plus prompt victim reporting to the FTC (reportfraud.ftc.gov) and FBI IC3 (ic3.gov), are the main backstops once credentials or payment data have already been captured.
Quick Facts
Victim
US consumers generally
Location
United States (nationwide alert; parking-meter QR sticker scams reported in multiple US cities, including San Antonio, Austin, and Houston, TX)
Date
2023-12-06
Impact
No aggregate dollar-loss figure was published by the FTC or FBI for this specific wave. The FBI's Sept 19, 2023 advisory noted that in 2022 it began receiving reports of people falling victim to QR code scams, including some who lost money, but gave no total. Third-party figures cited in coverage (not FTC/FBI): eMarketer estimated 94 million US QR-scanner users in 2023 (102.6M projected by 2026, via CNBC); Trellix reported over 60,000 QR-code attack samples detected in Q3 2023 (via NYT/The Verge).
Status
Confirmed
Case Type
Research / Advisory
Sector
Consumer / General Public, Government & Public Sector
Related

Related Cases

LevelBlue MTDR SOC "Quishing" Case Study - Fake Microsoft MFA-Setup QR Code Harvests Employee Credentials (2023)

LevelBlue's MDR SOC documented a real client quishing case in which a PDF impersonating a Microsoft MFA-setup notice, hiding a…

Incident 2023Read →

Hornetsecurity QRishing Attack on US-Based MSP (2023)

Hornetsecurity documented a QR-phishing (quishing) email sent to a single employee at a US-based MSP that spoofed an MFA-reactivation notice…

Incident 2023Read →

UK Council Car Park QR Code ("Quishing") Scams - Cheltenham, Swindon & Somerset

Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset,…

Incident 2024Read →