Case Library / Quishing (QR Code Phishing) / Orlando Downtown ParkMobile QR Parking Meter Sticker Scam (2025)

Orlando Downtown ParkMobile QR Parking Meter Sticker Scam (2025)

Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters, redirecting drivers who scanned them to a phishing site that harvested personal and payment information.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In late May/early June 2025, unknown scammers placed roughly 200 counterfeit QR-code stickers over legitimate ParkMobile payment stickers on parking meters throughout downtown Orlando, Florida (including on Orange Avenue). Drivers who scanned the fake codes to pay for parking were redirected to a fraudulent website that solicited personal and financial information rather than processing a legitimate ParkMobile payment. Orlando Police Department's Financial Crimes Unit discovered/was notified of the scheme via downtown parking enforcement, and posted a public scam alert on Monday, June 2, 2025 (covered by local media June 3), describing how to distinguish the genuine sticker (QR code printed directly on a green background) from the counterfeit overlay (printed on a white sticker that peels off). OPD said it was coordinating with the city parking division to inspect all downtown meters and strip out remaining fake stickers, and urged the public to avoid scanning suspicious codes, use the official ParkMobile app directly, and report tampered meters. No dollar-loss total, victim count, suspects, or arrests had been publicly confirmed as of the available reporting.

How the Attack Worked

Unknown scammers manufactured counterfeit QR-code stickers designed to mimic ParkMobile's official meter decals and physically applied them on top of the real stickers on downtown Orlando parking meters (reported locations included Orange Avenue). The genuine ParkMobile code is printed directly onto the meter sticker on a green background; the fraudulent overlay stickers were printed on a plain white background and were loosely affixed so they could be peeled off, meaning the tampering was detectable on close inspection but easily missed by a driver in a hurry. A driver who scanned the fake code with a smartphone camera was redirected not to ParkMobile's real payment flow but to a lookalike phishing site that solicited personal and financial (payment card) information under the guise of paying for parking; once submitted, that data was compromised/available to the scammers. The scheme required no hacking of ParkMobile's systems or the city's meters; it exploited driver trust in the ubiquitous "scan to pay" parking convention and the fact most people do not scrutinize a small sticker before scanning it.

The Lure & the Tell

The lure was a routine, low-friction daily action: scanning a QR code on a parking meter to pay via the widely used ParkMobile app, which drivers do quickly and without suspicion. The tell was physical and visual: the genuine ParkMobile QR sticker is printed directly onto the meter decal on a green background, while the counterfeit sticker was a separate white-background sticker overlaid on top of the real one and could be peeled off, indicating tampering to anyone who looked closely before scanning.

Outcome

Orlando Police Department publicized the scam via a social media/press statement on Monday, June 2, 2025 (reported by local outlets on June 3), crediting downtown parking enforcement with recovering approximately 200 fraudulent stickers from meters across the district. OPD's Financial Crimes Unit, through Sgt. Michael Fiorentino-Tyburski, issued public guidance and said officers were working with the city parking division to inspect all downtown meters and remove any remaining fake stickers. ParkMobile issued its own statement to press reiterating that users should go directly into its app and enter the zone number if a QR code looked suspicious. As of the last reporting found, no suspects had been identified, no arrests had been made, and no official victim count or financial-loss total had been released.

Why It Matters

This case is a clean, well-documented example of "quishing" (QR phishing) applied to shared physical municipal infrastructure rather than email or posted flyers: attackers exploited a payment method (scan-to-pay parking) that millions of people now use reflexively, with no login, no employer-security-awareness training, and no email filter standing between the sticker and the victim's payment data. It illustrates why physical/environmental tampering detection (inspecting the object a QR code sits on, not just the URL it resolves to) is now a necessary public-safety and consumer-protection message, and why municipalities and QR-dependent vendors (ParkMobile, transit, retail) need routine physical-audit programs for public-facing codes, not just backend security.

Defenses

OPD and ParkMobile issued matching guidance: inspect the meter/sticker for tampering before scanning (genuine ParkMobile code is printed directly on a green-background sticker; the fake was printed on a separate white sticker that peels off when placed over the real one); if anything looks off, do not scan; open the ParkMobile app directly and enter the zone number instead, or use another official payment method; report suspicious stickers to OPD. OPD paired the public warning with an operational response: parking enforcement/police physically inspected all downtown meters and stripped fraudulent stickers off in the field.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and target selection: The scammers likely surveyed downtown Orlando parking meters in person to identify ParkMobile's sticker design, the branding and QR placement they would need to imitate, and to pick a target area (reported locations included Orange Avenue) with enough meter volume and driver foot traffic to make mass tampering worthwhile.
Countering Stage 1: Public parking meters are, by design, openly accessible for anyone to photograph or examine, so this reconnaissance step cannot realistically be prevented; the practical control is at Stage 4, making tampering with the physical sticker itself harder to pull off unnoticed or undetected.
2
Phishing infrastructure setup: Before placing any stickers, the scammers likely registered a lookalike domain and built a fraudulent payment page designed to mimic a legitimate ParkMobile checkout flow closely enough to collect personal and payment-card details from a driver who had no reason to expect anything but a routine parking payment.
Countering Stage 2: Domain-monitoring and brand-protection services that watch for newly registered lookalike domains referencing a company's name, and rapid takedown requests once a phishing site is identified, shorten the window a fraudulent payment page can stay live, though registration itself is hard to block preemptively.
3
Counterfeit sticker production: The scammers manufactured QR-code stickers on plain white adhesive stock encoding the phishing site's URL, a low-cost, low-skill step consistent with commodity sticker-printing services rather than any technical exploit of ParkMobile's or the city's systems.
Countering Stage 3: Commodity sticker printing is not something a vendor or city can restrict, so there is no meaningful control at this stage; the response instead relies on the physical-inspection and reporting controls at Stages 4 and 5.
4
Physical placement and tampering: The scammers, over an unknown period leading up to early June 2025, physically applied roughly 200 counterfeit stickers directly over the genuine green-background ParkMobile decals on meters across downtown Orlando, betting that most drivers would not inspect a parking meter closely before scanning.
Countering Stage 4: Tamper-evident sticker materials or seals that visibly void or discolor when peeled, along with routine physical-audit patrols of public QR codes by parking enforcement, would make an overlay sticker either harder to apply cleanly or faster to catch before many drivers scan it.
5
Victim scan and redirection: A driver, treating scan-to-pay as a routine habituated action, scanned the counterfeit sticker with a smartphone camera and was redirected away from ParkMobile's real payment flow to the fraudulent lookalike site.
Countering Stage 5: Public-facing guidance, as OPD and ParkMobile both issued here, to inspect a meter's sticker for tampering (genuine ParkMobile code printed directly on a green background, versus a peelable white overlay) before scanning, and to default to opening the official app and entering the zone number instead of scanning an unfamiliar code, directly interrupts this step.
6
Data harvesting and objective completion: The driver, believing they were paying for parking, entered personal and payment-card information into the fraudulent site; once submitted, that data was captured by the scammers, completing the theft with no further interaction needed and no confirmed suspects or financial tally ever disclosed.
Countering Stage 6: Payment-card monitoring and fraud alerts from banks or card issuers, plus prompt reporting of suspicious charges, limit the financial damage once data has already been submitted, since neither ParkMobile nor OPD can retroactively prevent data a victim already typed into a phishing page.
Quick Facts
Victim
City of Orlando parking division / drivers parking in downtown Orlando
Location
Downtown Orlando, Florida, USA
Date
2025-06-02
Impact
No dollar loss figure was ever published. FOX 35 explicitly reported that as of its story, "officials have not specified the total number of victims or the financial impact to date" and that no suspects or arrests had been confirmed. No follow-up reporting with a final tally was found.
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Government & Public Sector, Transportation & Logistics
Related

Related Cases

FBI/USPIS/FTC "Brushing 2.0" Quishing Package Scam Advisories (2025)

The FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that,…

Incident 2025Read →

UK Council Car Park QR Code ("Quishing") Scams - Cheltenham, Swindon & Somerset

Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset,…

Incident 2024Read →

LevelBlue MTDR SOC "Quishing" Case Study - Fake Microsoft MFA-Setup QR Code Harvests Employee Credentials (2023)

LevelBlue's MDR SOC documented a real client quishing case in which a PDF impersonating a Microsoft MFA-setup notice, hiding a…

Incident 2023Read →