Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters.
Social Engineering Examples·5 sources
In late May/early June 2025, unknown scammers placed roughly 200 counterfeit QR-code stickers over legitimate ParkMobile payment stickers on parking meters throughout downtown Orlando, Florida (including on Orange Avenue). Drivers who scanned the fake codes to pay for parking were redirected to a fraudulent website that solicited personal and financial information rather than processing a legitimate ParkMobile payment.
Orlando Police Department's Financial Crimes Unit discovered/was notified of the scheme via downtown parking enforcement, and posted a public scam alert on Monday, June 2, 2025 (covered by local media June 3), describing how to distinguish the genuine sticker (QR code printed directly on a green background) from the counterfeit overlay (printed on a white sticker that peels off).
OPD said it was coordinating with the city parking division to inspect all downtown meters and strip out remaining fake stickers, and urged the public to avoid scanning suspicious codes, use the official ParkMobile app directly, and report tampered meters. No dollar-loss total, victim count, suspects, or arrests had been publicly confirmed as of the available reporting.
Unknown scammers manufactured counterfeit QR-code stickers designed to mimic ParkMobile's official meter decals and physically applied them on top of the real stickers on downtown Orlando parking meters (reported locations included Orange Avenue). The genuine ParkMobile code is printed directly onto the meter sticker on a green background; the fraudulent overlay stickers were printed on a plain white background and were loosely affixed so they could be peeled off, meaning the tampering was detectable on close inspection but easily missed by a driver in a hurry.
A driver who scanned the fake code with a smartphone camera was redirected not to ParkMobile's real payment flow but to a lookalike phishing site that solicited personal and financial (payment card) information under the guise of paying for parking; once submitted, that data was compromised/available to the scammers. The scheme required no hacking of ParkMobile's systems or the city's meters; it exploited driver trust in the ubiquitous "scan to pay" parking convention and the fact most people do not scrutinize a small sticker before scanning it.
The lure was a routine, low-friction daily action: scanning a QR code on a parking meter to pay via the widely used ParkMobile app, which drivers do quickly and without suspicion. The tell was physical and visual: the genuine ParkMobile QR sticker is printed directly onto the meter decal on a green background, while the counterfeit sticker was a separate white-background sticker overlaid on top of the real one and could be peeled off, indicating tampering to anyone who looked closely before scanning.
Orlando Police Department publicized the scam via a social media/press statement on Monday, June 2, 2025 (reported by local outlets on June 3), crediting downtown parking enforcement with recovering approximately 200 fraudulent stickers from meters across the district. OPD's Financial Crimes Unit, through Sgt. Michael Fiorentino-Tyburski, issued public guidance and said officers were working with the city parking division to inspect all downtown meters and remove any remaining fake stickers.
ParkMobile issued its own statement to press reiterating that users should go directly into its app and enter the zone number if a QR code looked suspicious. As of the last reporting found, no suspects had been identified, no arrests had been made, and no official victim count or financial-loss total had been released.
This case is a clean, well-documented example of "quishing" (QR phishing) applied to shared physical municipal infrastructure rather than email or posted flyers: attackers exploited a payment method (scan-to-pay parking) that millions of people now use reflexively, with no login, no employer-security-awareness training, and no email filter standing between the sticker and the victim's payment data.
It illustrates why physical/environmental tampering detection (inspecting the object a QR code sits on, not just the URL it resolves to) is now a necessary public-safety and consumer-protection message, and why municipalities and QR-dependent vendors (ParkMobile, transit, retail) need routine physical-audit programs for public-facing codes, not just backend security.
OPD and ParkMobile issued matching guidance: inspect the meter/sticker for tampering before scanning (genuine ParkMobile code is printed directly on a green-background sticker; the fake was printed on a separate white sticker that peels off when placed over the real one); if anything looks off, do not scan; open the ParkMobile app directly and enter the zone number instead, or use another official payment method; report suspicious stickers to OPD.
OPD paired the public warning with an operational response: parking enforcement/police physically inspected all downtown meters and stripped fraudulent stickers off in the field.
Social Engineering Examples. “Orlando Downtown ParkMobile QR Parking Meter Sticker Scam (2025)”. Accessed 16 September 2026. https://socialengineeringexamples.com/orlando-parkmobile-qr-parking-meter-sticker-scam-2025
The scammers likely surveyed downtown Orlando parking meters in person to identify ParkMobile's sticker design, the branding and QR placement they would need to imitate, and to pick a target area (reported locations included Orange Avenue) with enough meter volume and driver foot traffic to make mass tampering worthwhile.
Public parking meters are, by design, openly accessible for anyone to photograph or examine, so this reconnaissance step cannot realistically be prevented; the practical control is at Stage 4, making tampering with the physical sticker itself harder to pull off unnoticed or undetected.
Before placing any stickers, the scammers likely registered a lookalike domain and built a fraudulent payment page designed to mimic a legitimate ParkMobile checkout flow closely enough to collect personal and payment-card details from a driver who had no reason to expect anything but a routine parking payment.
Domain-monitoring and brand-protection services that watch for newly registered lookalike domains referencing a company's name, and rapid takedown requests once a phishing site is identified, shorten the window a fraudulent payment page can stay live, though registration itself is hard to block preemptively.
The scammers manufactured QR-code stickers on plain white adhesive stock encoding the phishing site's URL, a low-cost, low-skill step consistent with commodity sticker-printing services rather than any technical exploit of ParkMobile's or the city's systems.
Commodity sticker printing is not something a vendor or city can restrict, so there is no meaningful control at this stage; the response instead relies on the physical-inspection and reporting controls at Stages 4 and 5.
The scammers, over an unknown period leading up to early June 2025, physically applied roughly 200 counterfeit stickers directly over the genuine green-background ParkMobile decals on meters across downtown Orlando, betting that most drivers would not inspect a parking meter closely before scanning.
Tamper-evident sticker materials or seals that visibly void or discolor when peeled, along with routine physical-audit patrols of public QR codes by parking enforcement, would make an overlay sticker either harder to apply cleanly or faster to catch before many drivers scan it.
A driver, treating scan-to-pay as a routine habituated action, scanned the counterfeit sticker with a smartphone camera and was redirected away from ParkMobile's real payment flow to the fraudulent lookalike site.
Public-facing guidance, as OPD and ParkMobile both issued here, to inspect a meter's sticker for tampering (genuine ParkMobile code printed directly on a green background, versus a peelable white overlay) before scanning, and to default to opening the official app and entering the zone number instead of scanning an unfamiliar code, directly interrupts this step.
The driver, believing they were paying for parking, entered personal and payment-card information into the fraudulent site; once submitted, that data was captured by the scammers, completing the theft with no further interaction needed and no confirmed suspects or financial tally ever disclosed.
Payment-card monitoring and fraud alerts from banks or card issuers, plus prompt reporting of suspicious charges, limit the financial damage once data has already been submitted, since neither ParkMobile nor OPD can retroactively prevent data a victim already typed into a phishing page.
Browse by what this case has in common with others in the library.
The FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that,…
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
LevelBlue's MDR SOC documented a real client quishing case in which a PDF impersonating a Microsoft MFA-setup notice, hiding a…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.
A Bengaluru retiree lost Rs 6.88 lakh after an AI-generated deepfake Facebook video falsely showed Finance Minister Nirmala Sitharaman endorsing…
A Chicago hairstylist wired $20,000 of her own money to scammers after a caller impersonating Bank of America.
DOJ/FTC alleged that Citizens Disability and subsidiary CD Media made 109 million-plus illegal telemarketing calls.
A Russian-speaking threat actor used disposable, one-conversation ChatGPT accounts to iteratively build and debug a Go-based Windows malware family.
The FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that,…
Attackers hijacked a staff email account and used fake solar-panel invoices to trick the US charity into wiring $997,400 to…
A fraudster posing as AFGlobal's CEO, backed by a fake KPMG "attorney," pressured the accounting director into wiring $480,000 to…
Criminals impersonated a trusted vendor over email and redirected two building-fund payments totaling $4.92M from a North Dakota school district.
A mass SMS phishing campaign impersonating U.S. toll agencies spoofed 'unpaid toll' notices, drawing 2,000+ FBI complaints within weeks.
The FBI's 2025 Internet Crime Report introduced its first dedicated AI-fraud tracking category, logging $893 million in losses.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…