Case Library / Pretexting & Impersonation / PG&E Utility Shutoff Barcode/QR Payment Scam

PG&E Utility Shutoff Barcode/QR Payment Scam

Scammers impersonating PG&E threaten customers and small businesses with immediate service disconnection, then text or email a barcode/QR code and tell them to have a store cashier scan it to "pay," draining funds instantly through a channel with no fraud checkpoint; PG&E's own fraud investigator quantified over $211,000 in losses through mid-2026.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Beginning in 2025 and accelerating through the first half of 2026, scammers impersonating Pacific Gas and Electric Company (PG&E) called customers and small businesses across PG&E's Northern and Central California territory, falsely claiming their account was past due and threatening immediate service disconnection unless they paid right away. In a "new wrinkle" that emerged in 2026, instead of (or in addition to) demanding payment via prepaid debit card or Zelle/Venmo, scammers began texting or emailing victims a barcode or QR code and instructing them to bring it to a retail store and have a cashier scan it to complete the "payment," a channel that let the scammer drain funds instantly through a transaction that looked routine to the cashier. PG&E publicly disclosed the scheme and its losses in a June 15, 2026 press release (updated with new figures July 2, 2026), attributing the analysis to its lead scam investigator Matt Foley and spokesperson Jason King, stating losses had already topped $211,000 in the first half of 2026 (versus $301,000 for all of 2025) and that the trend was on track to significantly exceed 2025's total by year-end.

How the Attack Worked

The attack chain has two linked stages. Stage 1 (voice pretext): scammers cold-call a PG&E customer or small business, impersonate PG&E, and falsely claim the account is delinquent, using urgency and a threat of immediate service disconnection (sometimes within the hour) to pressure quick action, deliberately timed to a business's busy hours to maximize the owner's fear of having to close. Stage 2 (novel payment channel): rather than the older ask for a prepaid debit card, gift card, or Zelle/Venmo transfer, the scammer sends the victim a barcode or QR code via text message or email and instructs them to bring it to any retail store, present it to a cashier, and have the cashier scan it to "pay the bill." Because this looks like an ordinary in-store scan-to-pay transaction, the cashier has no natural cue to flag it as fraud (unlike some digital payment apps that surface scam warnings), and funds are drained by the scammer essentially instantly and are very difficult to reverse.

The Lure & the Tell

Lure: an unsolicited phone call claiming your PG&E bill is overdue and your power/gas will be shut off immediately unless you pay right now, followed by a barcode/QR code texted or emailed to you to take to a store. Tell: PG&E never demands payment by barcode, QR code, prepaid card, gift card, crypto, or Zelle/Venmo; it never threatens same-call disconnection without prior written notice; and it never asks to view your bill at your door. Genuine disconnection notices arrive in advance by mail and on the regular bill, not as a surprise phone ultimatum.

Outcome

No named individual perpetrators or arrests were identified in the sources reviewed; this is reported by PG&E as an ongoing, evolving fraud pattern rather than a single prosecuted case. PG&E responded with public consumer-alert press releases (June 15, 2026 and July 2, 2026), an updated scams page, a dedicated scam-reporting line (1-833-500-SCAM), and named its lead scam investigator (Matt Foley) as a public spokesperson; local coverage noted San Jose Police were investigating related reports. Losses were continuing to accrue and were projected by PG&E to exceed 2025's total by year-end 2026.

Why It Matters

This case documents a genuinely novel monetization channel within a very old pretext (utility-disconnection fear): using a barcode/QR code scanned by a real, unwitting retail cashier as the money-laundering step, instead of a prepaid card, wire, or crypto ATM. It matters for awareness training because (1) it shows scammers actively engineering around existing fraud checkpoints, choosing a payment rail (in-store barcode scan) specifically because front-line staff have no built-in prompt to question it, unlike some digital wallets and money-transfer apps that now surface scam warnings; (2) it demonstrates a utility company using its own named fraud investigator and hard loss figures to drive public-interest reporting, a useful primary-source template for "first-party disclosure" case studies; and (3) the sharp jump in average loss per victim (from $590 in 2025 to $969 in H1 2026) suggests the new channel may be more effective per-victim than older prepaid-card or wire-based utility scams, even though report volume dynamics are still emerging.

Defenses

PG&E's stated defenses/advice: hang up on unsolicited disconnection-threat calls; never provide payment via barcode, QR code, prepaid debit card, gift card, cryptocurrency, or money-transfer apps (Zelle/Venmo) in response to a phone demand; do not show a utility bill to anyone who comes to the door; delinquent accounts get advance disconnection notices by mail and on the regular bill, never a surprise same-call shutoff threat; verify any account/billing concern directly via PGE.com or PG&E's official number (800-743-5000); report suspected scam calls to 1-833-500-SCAM; call 911 if in-person contact feels threatening. PG&E also publishes real-time scam alerts and by-the-numbers reporting to build public awareness, and flags that retail cashiers scanning a barcode/QR code have no built-in fraud-warning moment the way some digital payment apps do, which is part of why this channel is being exploited.

Sources
  • PG&E Warns Customers About Emerging "Barcode Scam:" Here's What You Should Know. PG&E Corporation Primary. Official June 15, 2026 press release; source of the $211,000 H1-2026 loss figure, $969 average loss, 2025 comparison figures, and quotes from lead scam investigator Matt Foley. Verified by direct fetch: content matches exactly, including the 656 vs 846 business-report figures.
  • Scams | PG&E. PG&E Primary. PG&E's standing consumer-facing scam-awareness and reporting page, including the 1-833-500-SCAM line and guidance never to pay via barcode/QR code, gift card, or money-transfer app. Verified by direct fetch.
  • 'Barcode scam' has cost PG&E customers $211,000 so far this year, utility says. The Press Democrat Secondary. July 2, 2026 report with regional breakdown (Sonoma County 144, Napa County 21) and PG&E spokesperson Jason King's explanation of why cashier-scanned barcodes lack fraud warnings. Verified by direct fetch: all cited figures and the King attribution match.
  • PG&E warns of new scam involving bar codes or QR codes. NBC Bay Area Secondary. June 23, 2026 secondary coverage. Verified by direct fetch, including further down the article: a direct statement from the San Jose Police Department confirming it was aware of and investigating the scam.
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
List and contact acquisition: Scammers typically work from broad, low-cost lead sources rather than individually researched targets, consistent with the mass, opportunistic targeting PG&E describes; likely inputs include leaked or scraped consumer contact lists, publicly available residential and business phone directories, and simple knowledge that a target lives or operates within a large utility's service territory, since no specific account data appears necessary to run the pretext convincingly.
Countering Stage 1: Consumer contact information is broadly available through data brokers and leaked lists and is very hard to suppress at the individual level; the realistic control is downstream, at the point where the scammer tries to establish false authority and urgency (Stage 3), rather than trying to prevent contact-list acquisition itself.
2
Spoofed or unverified caller setup: Scammers likely use commercially available caller-ID spoofing or VoIP calling services (PG&E itself warns that scam calls can display a real PG&E number such as 800-743-5000) so the call looks legitimate at first glance and survives a casual caller-ID check.
Countering Stage 2: Caller-ID spoofing is difficult for an individual consumer to detect or block outright; PG&E's advice is to never trust caller ID alone and instead independently verify any billing claim by calling PG&E's published number (800-743-5000) or logging into PGE.com directly, rather than using any number or link the caller provides.
3
Voice pretext and disconnection threat: The scammer calls the customer or small business, impersonates PG&E, falsely claims the account is delinquent, and threatens immediate service disconnection, timing calls to a business's busy hours to maximize the owner's fear of having to close.
Countering Stage 3: PG&E states it never threatens same-call disconnection without prior written notice and never asks to view a bill at the door; consumer and business education on this specific script, reinforced by PG&E's public press releases and scams page, lets a recipient recognize the disconnection-threat call as fraudulent before feeling pressured to act.
4
Urgency and payment-method narrowing: The scammer pressures the victim to act immediately and steers them away from PG&E's normal payment channels toward an unusual one, consistent with PG&E's observation that scammers favor irreversible payment methods.
Countering Stage 4: Recognizing that legitimate utilities do not demand irreversible, unusual payment methods breaks the urgency tactic; PG&E explicitly tells customers it will never require payment by prepaid card, gift card, cryptocurrency, or money-transfer apps, giving a clear rule of thumb independent of the specific method named.
5
Barcode/QR code delivery: The scammer sends the victim a barcode or QR code by text message or email, generated through commonly available barcode-generation tools or payment-app features, and instructs them to take it to a retail store.
Countering Stage 5: Treat any unsolicited barcode or QR code sent by text or email as a red flag rather than a legitimate billing tool, since PG&E states it does not use this channel to collect payment; deleting the message and verifying by phone or online account instead of scanning anything sent by an unknown contact closes this stage.
6
In-person cash-out via unwitting cashier: The victim presents the barcode or QR code to a store cashier, who scans it as part of what looks like a routine transaction; because cashiers have no built-in fraud-warning prompt for this payment type (unlike some digital wallets), the transaction completes without anyone flagging it as suspicious.
Countering Stage 6: Because retail cashiers currently have no built-in fraud-warning cue for a scanned barcode payment (unlike some digital wallets that surface scam alerts), the realistic control here is upstream consumer awareness and, longer term, payment processors or retailers building in warnings for this transaction type; PG&E has flagged this gap publicly as a driver of the scam's success.
7
Instant fund extraction and objective completion: The scammer receives the funds essentially instantly through the scanned transaction, a payment rail PG&E notes is very difficult to reverse, completing the theft before the victim or the retailer realizes it was fraudulent.
Countering Stage 7: Once funds are drained through this rail they are, per PG&E, very difficult to reverse, so the effective defense is preventing the transaction from being initiated at all (Stages 3 to 6); after the fact, the only recourse is prompt reporting to PG&E's scam line (1-833-500-SCAM), local law enforcement, and the retailer/payment processor to attempt recovery or prevent further victimization.
Quick Facts
Victim
PG&E customers, California (individuals and small/medium businesses)
Location
California (statewide across PG&E's Northern and Central California service territory; regional detail reported for Sonoma County and Napa County)
Date
2025-2026 (ongoing; PG&E quantified losses through mid-2026 in a June 15, 2026 press release, updated July 2, 2026)
Impact
PG&E reported customers lost over $211,000 to this and related utility-impersonation scams through mid-2026 (average loss $969/victim in H1 2026), on pace to exceed 2025's total of over $301,000 (average loss $590/victim, ~24,000 scam reports in 2025). Business customers were also targeted: 656 scam reports against businesses in the first half of 2026 vs. 846 for all of 2025. Regionally, Sonoma County reported 144 targeted customers and Napa County 21 in H1 2026. These are company-reported, self-disclosed figures (not independently audited or tied to a single adjudicated criminal case), and PG&E states the true total is likely higher since many incidents go unreported.
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Critical Infrastructure, Energy & Utilities, Cross-Sector / Multiple Industries
Related

Related Cases

Susie Wiles AI Voice Impersonation via Hacked Contact List (2025)

An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…

Incident 2025Read →

Single Operator Weaponizes Claude Code and GPT-4.1 to Breach Nine Mexican Government Agencies

A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it…

Incident 2025Read →

GTIG Discloses PROMPTFLUX: First "Just-in-Time" Self-Obfuscating AI Malware Using the Gemini API

Google's Threat Intelligence Group disclosed PROMPTFLUX, a VBScript dropper that calls the Gemini API mid-execution to have an LLM rewrite…

Incident 2025Read →