Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters, redirecting drivers who scanned them to a phishing site that harvested personal and payment information.
Reviewed by the Social Engineering Examples team.
In late May/early June 2025, unknown scammers placed roughly 200 counterfeit QR-code stickers over legitimate ParkMobile payment stickers on parking meters throughout downtown Orlando, Florida (including on Orange Avenue). Drivers who scanned the fake codes to pay for parking were redirected to a fraudulent website that solicited personal and financial information rather than processing a legitimate ParkMobile payment. Orlando Police Department's Financial Crimes Unit discovered/was notified of the scheme via downtown parking enforcement, and posted a public scam alert on Monday, June 2, 2025 (covered by local media June 3), describing how to distinguish the genuine sticker (QR code printed directly on a green background) from the counterfeit overlay (printed on a white sticker that peels off). OPD said it was coordinating with the city parking division to inspect all downtown meters and strip out remaining fake stickers, and urged the public to avoid scanning suspicious codes, use the official ParkMobile app directly, and report tampered meters. No dollar-loss total, victim count, suspects, or arrests had been publicly confirmed as of the available reporting.
Unknown scammers manufactured counterfeit QR-code stickers designed to mimic ParkMobile's official meter decals and physically applied them on top of the real stickers on downtown Orlando parking meters (reported locations included Orange Avenue). The genuine ParkMobile code is printed directly onto the meter sticker on a green background; the fraudulent overlay stickers were printed on a plain white background and were loosely affixed so they could be peeled off, meaning the tampering was detectable on close inspection but easily missed by a driver in a hurry. A driver who scanned the fake code with a smartphone camera was redirected not to ParkMobile's real payment flow but to a lookalike phishing site that solicited personal and financial (payment card) information under the guise of paying for parking; once submitted, that data was compromised/available to the scammers. The scheme required no hacking of ParkMobile's systems or the city's meters; it exploited driver trust in the ubiquitous "scan to pay" parking convention and the fact most people do not scrutinize a small sticker before scanning it.
The lure was a routine, low-friction daily action: scanning a QR code on a parking meter to pay via the widely used ParkMobile app, which drivers do quickly and without suspicion. The tell was physical and visual: the genuine ParkMobile QR sticker is printed directly onto the meter decal on a green background, while the counterfeit sticker was a separate white-background sticker overlaid on top of the real one and could be peeled off, indicating tampering to anyone who looked closely before scanning.
Orlando Police Department publicized the scam via a social media/press statement on Monday, June 2, 2025 (reported by local outlets on June 3), crediting downtown parking enforcement with recovering approximately 200 fraudulent stickers from meters across the district. OPD's Financial Crimes Unit, through Sgt. Michael Fiorentino-Tyburski, issued public guidance and said officers were working with the city parking division to inspect all downtown meters and remove any remaining fake stickers. ParkMobile issued its own statement to press reiterating that users should go directly into its app and enter the zone number if a QR code looked suspicious. As of the last reporting found, no suspects had been identified, no arrests had been made, and no official victim count or financial-loss total had been released.
This case is a clean, well-documented example of "quishing" (QR phishing) applied to shared physical municipal infrastructure rather than email or posted flyers: attackers exploited a payment method (scan-to-pay parking) that millions of people now use reflexively, with no login, no employer-security-awareness training, and no email filter standing between the sticker and the victim's payment data. It illustrates why physical/environmental tampering detection (inspecting the object a QR code sits on, not just the URL it resolves to) is now a necessary public-safety and consumer-protection message, and why municipalities and QR-dependent vendors (ParkMobile, transit, retail) need routine physical-audit programs for public-facing codes, not just backend security.
OPD and ParkMobile issued matching guidance: inspect the meter/sticker for tampering before scanning (genuine ParkMobile code is printed directly on a green-background sticker; the fake was printed on a separate white sticker that peels off when placed over the real one); if anything looks off, do not scan; open the ParkMobile app directly and enter the zone number instead, or use another official payment method; report suspicious stickers to OPD. OPD paired the public warning with an operational response: parking enforcement/police physically inspected all downtown meters and stripped fraudulent stickers off in the field.
The FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that,…
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset,…
LevelBlue's MDR SOC documented a real client quishing case in which a PDF impersonating a Microsoft MFA-setup notice, hiding a…