Scammers impersonating PG&E threaten customers and small businesses with immediate service disconnection.
Social Engineering Examples·4 sources
Beginning in 2025 and accelerating through the first half of 2026, scammers impersonating Pacific Gas and Electric Company (PG&E) called customers and small businesses across PG&E's Northern and Central California territory, falsely claiming their account was past due and threatening immediate service disconnection unless they paid right away. In a "new wrinkle" that emerged in 2026, instead of (or in addition to) demanding payment via prepaid debit card or Zelle/Venmo, scammers began texting or emailing victims a barcode or QR code and instructing them to bring it to a retail store and have a cashier scan it to complete the "payment," a channel that let the scammer drain funds instantly through a transaction that looked routine to the cashier.
PG&E publicly disclosed the scheme and its losses in a June 15, 2026 press release (updated with new figures July 2, 2026), attributing the analysis to its lead scam investigator Matt Foley and spokesperson Jason King, stating losses had already topped $211,000 in the first half of 2026 (versus $301,000 for all of 2025) and that the trend was on track to significantly exceed 2025's total by year-end.
The attack chain has two linked stages. Stage 1 (voice pretext): scammers cold-call a PG&E customer or small business, impersonate PG&E, and falsely claim the account is delinquent, using urgency and a threat of immediate service disconnection (sometimes within the hour) to pressure quick action, deliberately timed to a business's busy hours to maximize the owner's fear of having to close.
Stage 2 (novel payment channel): rather than the older ask for a prepaid debit card, gift card, or Zelle/Venmo transfer, the scammer sends the victim a barcode or QR code via text message or email and instructs them to bring it to any retail store, present it to a cashier, and have the cashier scan it to "pay the bill." Because this looks like an ordinary in-store scan-to-pay transaction, the cashier has no natural cue to flag it as fraud (unlike some digital payment apps that surface scam warnings), and funds are drained by the scammer essentially instantly and are very difficult to reverse.
Lure: an unsolicited phone call claiming your PG&E bill is overdue and your power/gas will be shut off immediately unless you pay right now, followed by a barcode/QR code texted or emailed to you to take to a store. Tell: PG&E never demands payment by barcode, QR code, prepaid card, gift card, crypto, or Zelle/Venmo; it never threatens same-call disconnection without prior written notice; and it never asks to view your bill at your door.
Genuine disconnection notices arrive in advance by mail and on the regular bill, not as a surprise phone ultimatum.
No named individual perpetrators or arrests were identified in the sources reviewed; this is reported by PG&E as an ongoing, evolving fraud pattern rather than a single prosecuted case. PG&E responded with public consumer-alert press releases (June 15, 2026 and July 2, 2026), an updated scams page, a dedicated scam-reporting line (1-833-500-SCAM), and named its lead scam investigator (Matt Foley) as a public spokesperson; local coverage noted San Jose Police were investigating related reports.
Losses were continuing to accrue and were projected by PG&E to exceed 2025's total by year-end 2026.
This case documents a genuinely novel monetization channel within a very old pretext (utility-disconnection fear): using a barcode/QR code scanned by a real, unwitting retail cashier as the money-laundering step, instead of a prepaid card, wire, or crypto ATM. It matters for awareness training because (1) it shows scammers actively engineering around existing fraud checkpoints, choosing a payment rail (in-store barcode scan) specifically because front-line staff have no built-in prompt to question it, unlike some digital wallets and money-transfer apps that now surface scam warnings; (2) it demonstrates a utility company using its own named fraud investigator and hard loss figures to drive public-interest reporting, a useful primary-source template for "first-party disclosure" case studies; and (3) the sharp jump in average loss per victim (from $590 in 2025 to $969 in H1 2026) suggests the new channel may be more effective per-victim than older prepaid-card or wire-based utility scams, even though report volume dynamics are still emerging.
PG&E's stated defenses/advice: hang up on unsolicited disconnection-threat calls; never provide payment via barcode, QR code, prepaid debit card, gift card, cryptocurrency, or money-transfer apps (Zelle/Venmo) in response to a phone demand; do not show a utility bill to anyone who comes to the door; delinquent accounts get advance disconnection notices by mail and on the regular bill, never a surprise same-call shutoff threat; verify any account/billing concern directly via PGE.com or PG&E's official number (800-743-5000); report suspected scam calls to 1-833-500-SCAM; call 911 if in-person contact feels threatening.
PG&E also publishes real-time scam alerts and by-the-numbers reporting to build public awareness, and flags that retail cashiers scanning a barcode/QR code have no built-in fraud-warning moment the way some digital payment apps do, which is part of why this channel is being exploited.
Social Engineering Examples. “PG&E Utility Shutoff Barcode/QR Payment Scam”. Accessed 19 September 2026. https://socialengineeringexamples.com/pge-barcode-qr-utility-shutoff-scam-2026
Scammers typically work from broad, low-cost lead sources rather than individually researched targets, consistent with the mass, opportunistic targeting PG&E describes; likely inputs include leaked or scraped consumer contact lists, publicly available residential and business phone directories, and simple knowledge that a target lives or operates within a large utility's service territory, since no specific account data appears necessary to run the pretext convincingly.
Consumer contact information is broadly available through data brokers and leaked lists and is very hard to suppress at the individual level; the realistic control is downstream, at the point where the scammer tries to establish false authority and urgency (Stage 3), rather than trying to prevent contact-list acquisition itself.
Scammers likely use commercially available caller-ID spoofing or VoIP calling services (PG&E itself warns that scam calls can display a real PG&E number such as 800-743-5000) so the call looks legitimate at first glance and survives a casual caller-ID check.
Caller-ID spoofing is difficult for an individual consumer to detect or block outright; PG&E's advice is to never trust caller ID alone and instead independently verify any billing claim by calling PG&E's published number (800-743-5000) or logging into PGE.com directly, rather than using any number or link the caller provides.
The scammer calls the customer or small business, impersonates PG&E, falsely claims the account is delinquent, and threatens immediate service disconnection, timing calls to a business's busy hours to maximize the owner's fear of having to close.
PG&E states it never threatens same-call disconnection without prior written notice and never asks to view a bill at the door; consumer and business education on this specific script, reinforced by PG&E's public press releases and scams page, lets a recipient recognize the disconnection-threat call as fraudulent before feeling pressured to act.
The scammer pressures the victim to act immediately and steers them away from PG&E's normal payment channels toward an unusual one, consistent with PG&E's observation that scammers favor irreversible payment methods.
Recognizing that legitimate utilities do not demand irreversible, unusual payment methods breaks the urgency tactic; PG&E explicitly tells customers it will never require payment by prepaid card, gift card, cryptocurrency, or money-transfer apps, giving a clear rule of thumb independent of the specific method named.
The scammer sends the victim a barcode or QR code by text message or email, generated through commonly available barcode-generation tools or payment-app features, and instructs them to take it to a retail store.
Treat any unsolicited barcode or QR code sent by text or email as a red flag rather than a legitimate billing tool, since PG&E states it does not use this channel to collect payment; deleting the message and verifying by phone or online account instead of scanning anything sent by an unknown contact closes this stage.
The victim presents the barcode or QR code to a store cashier, who scans it as part of what looks like a routine transaction; because cashiers have no built-in fraud-warning prompt for this payment type (unlike some digital wallets), the transaction completes without anyone flagging it as suspicious.
Because retail cashiers currently have no built-in fraud-warning cue for a scanned barcode payment (unlike some digital wallets that surface scam alerts), the realistic control here is upstream consumer awareness and, longer term, payment processors or retailers building in warnings for this transaction type; PG&E has flagged this gap publicly as a driver of the scam's success.
The scammer receives the funds essentially instantly through the scanned transaction, a payment rail PG&E notes is very difficult to reverse, completing the theft before the victim or the retailer realizes it was fraudulent.
Once funds are drained through this rail they are, per PG&E, very difficult to reverse, so the effective defense is preventing the transaction from being initiated at all (Stages 3 to 6); after the fact, the only recourse is prompt reporting to PG&E's scam line (1-833-500-SCAM), local law enforcement, and the retailer/payment processor to attempt recovery or prevent further victimization.
Browse by what this case has in common with others in the library.
An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…
A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.
Google's Threat Intelligence Group disclosed PROMPTFLUX, a VBScript dropper that calls the Gemini API mid-execution to have an LLM rewrite.
Researchers from UIUC, the University of Michigan, and Google dropped 297 USB drives across the UIUC campus and found that…
The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
The FBI's 2025 Internet Crime Report introduced its first dedicated AI-fraud tracking category, logging $893 million in losses.
The Caesars Entertainment breach: Scattered Spider social-engineered an IT help desk, stealing a loyalty database and prompting a $15M ransom…
Costa Rica-based ringleader Roger Roger used spoofed government caller ID to convince hundreds of elderly victims they had won sweepstakes…
A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.
Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…
DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad.
Criminals impersonated a trusted vendor over email and redirected two building-fund payments totaling $4.92M from a North Dakota school district.
Costa Rica-based ringleader Roger Roger used spoofed government caller ID to convince hundreds of elderly victims they had won sweepstakes…
ESET researchers found "PromptLock," a Go-based ransomware sample on VirusTotal that used a locally-run open-weight AI model.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
P&G-hired competitive-intelligence contractors retrieved roughly 80 unshredded confidential Unilever hair-care documents from the trash before P&G.
A Taiwan-linked money courier was caught in an Austin bank sting while collecting part of the $1.4 million a victim…