Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters.
Social Engineering Examples·5 sources
In late May/early June 2025, unknown scammers placed roughly 200 counterfeit QR-code stickers over legitimate ParkMobile payment stickers on parking meters throughout downtown Orlando, Florida (including on Orange Avenue). Drivers who scanned the fake codes to pay for parking were redirected to a fraudulent website that solicited personal and financial information rather than processing a legitimate ParkMobile payment.
Orlando Police Department's Financial Crimes Unit discovered/was notified of the scheme via downtown parking enforcement, and posted a public scam alert on Monday, June 2, 2025 (covered by local media June 3), describing how to distinguish the genuine sticker (QR code printed directly on a green background) from the counterfeit overlay (printed on a white sticker that peels off).
OPD said it was coordinating with the city parking division to inspect all downtown meters and strip out remaining fake stickers, and urged the public to avoid scanning suspicious codes, use the official ParkMobile app directly, and report tampered meters. No dollar-loss total, victim count, suspects, or arrests had been publicly confirmed as of the available reporting.
Unknown scammers manufactured counterfeit QR-code stickers designed to mimic ParkMobile's official meter decals and physically applied them on top of the real stickers on downtown Orlando parking meters (reported locations included Orange Avenue). The genuine ParkMobile code is printed directly onto the meter sticker on a green background; the fraudulent overlay stickers were printed on a plain white background and were loosely affixed so they could be peeled off, meaning the tampering was detectable on close inspection but easily missed by a driver in a hurry.
A driver who scanned the fake code with a smartphone camera was redirected not to ParkMobile's real payment flow but to a lookalike phishing site that solicited personal and financial (payment card) information under the guise of paying for parking; once submitted, that data was compromised/available to the scammers. The scheme required no hacking of ParkMobile's systems or the city's meters; it exploited driver trust in the ubiquitous "scan to pay" parking convention and the fact most people do not scrutinize a small sticker before scanning it.
The lure was a routine, low-friction daily action: scanning a QR code on a parking meter to pay via the widely used ParkMobile app, which drivers do quickly and without suspicion. The tell was physical and visual: the genuine ParkMobile QR sticker is printed directly onto the meter decal on a green background, while the counterfeit sticker was a separate white-background sticker overlaid on top of the real one and could be peeled off, indicating tampering to anyone who looked closely before scanning.
Orlando Police Department publicized the scam via a social media/press statement on Monday, June 2, 2025 (reported by local outlets on June 3), crediting downtown parking enforcement with recovering approximately 200 fraudulent stickers from meters across the district. OPD's Financial Crimes Unit, through Sgt. Michael Fiorentino-Tyburski, issued public guidance and said officers were working with the city parking division to inspect all downtown meters and remove any remaining fake stickers.
ParkMobile issued its own statement to press reiterating that users should go directly into its app and enter the zone number if a QR code looked suspicious. As of the last reporting found, no suspects had been identified, no arrests had been made, and no official victim count or financial-loss total had been released.
This case is a clean, well-documented example of "quishing" (QR phishing) applied to shared physical municipal infrastructure rather than email or posted flyers: attackers exploited a payment method (scan-to-pay parking) that millions of people now use reflexively, with no login, no employer-security-awareness training, and no email filter standing between the sticker and the victim's payment data.
It illustrates why physical/environmental tampering detection (inspecting the object a QR code sits on, not just the URL it resolves to) is now a necessary public-safety and consumer-protection message, and why municipalities and QR-dependent vendors (ParkMobile, transit, retail) need routine physical-audit programs for public-facing codes, not just backend security.
OPD and ParkMobile issued matching guidance: inspect the meter/sticker for tampering before scanning (genuine ParkMobile code is printed directly on a green-background sticker; the fake was printed on a separate white sticker that peels off when placed over the real one); if anything looks off, do not scan; open the ParkMobile app directly and enter the zone number instead, or use another official payment method; report suspicious stickers to OPD.
OPD paired the public warning with an operational response: parking enforcement/police physically inspected all downtown meters and stripped fraudulent stickers off in the field.
Social Engineering Examples. “Orlando Downtown ParkMobile QR Parking Meter Sticker Scam (2025)”. Accessed 19 September 2026. https://socialengineeringexamples.com/orlando-parkmobile-qr-parking-meter-sticker-scam-2025
The scammers likely surveyed downtown Orlando parking meters in person to identify ParkMobile's sticker design, the branding and QR placement they would need to imitate, and to pick a target area (reported locations included Orange Avenue) with enough meter volume and driver foot traffic to make mass tampering worthwhile.
Public parking meters are, by design, openly accessible for anyone to photograph or examine, so this reconnaissance step cannot realistically be prevented; the practical control is at Stage 4, making tampering with the physical sticker itself harder to pull off unnoticed or undetected.
Before placing any stickers, the scammers likely registered a lookalike domain and built a fraudulent payment page designed to mimic a legitimate ParkMobile checkout flow closely enough to collect personal and payment-card details from a driver who had no reason to expect anything but a routine parking payment.
Domain-monitoring and brand-protection services that watch for newly registered lookalike domains referencing a company's name, and rapid takedown requests once a phishing site is identified, shorten the window a fraudulent payment page can stay live, though registration itself is hard to block preemptively.
The scammers manufactured QR-code stickers on plain white adhesive stock encoding the phishing site's URL, a low-cost, low-skill step consistent with commodity sticker-printing services rather than any technical exploit of ParkMobile's or the city's systems.
Commodity sticker printing is not something a vendor or city can restrict, so there is no meaningful control at this stage; the response instead relies on the physical-inspection and reporting controls at Stages 4 and 5.
The scammers, over an unknown period leading up to early June 2025, physically applied roughly 200 counterfeit stickers directly over the genuine green-background ParkMobile decals on meters across downtown Orlando, betting that most drivers would not inspect a parking meter closely before scanning.
Tamper-evident sticker materials or seals that visibly void or discolor when peeled, along with routine physical-audit patrols of public QR codes by parking enforcement, would make an overlay sticker either harder to apply cleanly or faster to catch before many drivers scan it.
A driver, treating scan-to-pay as a routine habituated action, scanned the counterfeit sticker with a smartphone camera and was redirected away from ParkMobile's real payment flow to the fraudulent lookalike site.
Public-facing guidance, as OPD and ParkMobile both issued here, to inspect a meter's sticker for tampering (genuine ParkMobile code printed directly on a green background, versus a peelable white overlay) before scanning, and to default to opening the official app and entering the zone number instead of scanning an unfamiliar code, directly interrupts this step.
The driver, believing they were paying for parking, entered personal and payment-card information into the fraudulent site; once submitted, that data was captured by the scammers, completing the theft with no further interaction needed and no confirmed suspects or financial tally ever disclosed.
Payment-card monitoring and fraud alerts from banks or card issuers, plus prompt reporting of suspicious charges, limit the financial damage once data has already been submitted, since neither ParkMobile nor OPD can retroactively prevent data a victim already typed into a phishing page.
Browse by what this case has in common with others in the library.
The FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that,…
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
LevelBlue's MDR SOC documented a real client quishing case in which a PDF impersonating a Microsoft MFA-setup notice, hiding a…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support.
Between 2000 and 2009, GAO undercover investigators repeatedly used fake law-enforcement badges (and, in a related 2009 test.
A Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into…
A revived Lampion banking-trojan campaign spoofed Portugal's tax authority site to trick victims into pasting a PowerShell command into the…
Impersonators posing as two School District of Philadelphia vendors switched payments to ACH and diverted nearly $700,000 into fraud accounts.
Russian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar.
The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports.
DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund".
A complex criminal phishing scheme induced Argan, Inc. to send two outbound wires in March 2023, producing a roughly $3…
A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…
TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels.
An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…