Scammers impersonating PG&E threaten customers and small businesses with immediate service disconnection, then text or email a barcode/QR code and tell them to have a store cashier scan it to "pay," draining funds instantly through a channel with no fraud checkpoint; PG&E's own fraud investigator quantified over $211,000 in losses through mid-2026.
Reviewed by the Social Engineering Examples team.
Beginning in 2025 and accelerating through the first half of 2026, scammers impersonating Pacific Gas and Electric Company (PG&E) called customers and small businesses across PG&E's Northern and Central California territory, falsely claiming their account was past due and threatening immediate service disconnection unless they paid right away. In a "new wrinkle" that emerged in 2026, instead of (or in addition to) demanding payment via prepaid debit card or Zelle/Venmo, scammers began texting or emailing victims a barcode or QR code and instructing them to bring it to a retail store and have a cashier scan it to complete the "payment," a channel that let the scammer drain funds instantly through a transaction that looked routine to the cashier. PG&E publicly disclosed the scheme and its losses in a June 15, 2026 press release (updated with new figures July 2, 2026), attributing the analysis to its lead scam investigator Matt Foley and spokesperson Jason King, stating losses had already topped $211,000 in the first half of 2026 (versus $301,000 for all of 2025) and that the trend was on track to significantly exceed 2025's total by year-end.
The attack chain has two linked stages. Stage 1 (voice pretext): scammers cold-call a PG&E customer or small business, impersonate PG&E, and falsely claim the account is delinquent, using urgency and a threat of immediate service disconnection (sometimes within the hour) to pressure quick action, deliberately timed to a business's busy hours to maximize the owner's fear of having to close. Stage 2 (novel payment channel): rather than the older ask for a prepaid debit card, gift card, or Zelle/Venmo transfer, the scammer sends the victim a barcode or QR code via text message or email and instructs them to bring it to any retail store, present it to a cashier, and have the cashier scan it to "pay the bill." Because this looks like an ordinary in-store scan-to-pay transaction, the cashier has no natural cue to flag it as fraud (unlike some digital payment apps that surface scam warnings), and funds are drained by the scammer essentially instantly and are very difficult to reverse.
Lure: an unsolicited phone call claiming your PG&E bill is overdue and your power/gas will be shut off immediately unless you pay right now, followed by a barcode/QR code texted or emailed to you to take to a store. Tell: PG&E never demands payment by barcode, QR code, prepaid card, gift card, crypto, or Zelle/Venmo; it never threatens same-call disconnection without prior written notice; and it never asks to view your bill at your door. Genuine disconnection notices arrive in advance by mail and on the regular bill, not as a surprise phone ultimatum.
No named individual perpetrators or arrests were identified in the sources reviewed; this is reported by PG&E as an ongoing, evolving fraud pattern rather than a single prosecuted case. PG&E responded with public consumer-alert press releases (June 15, 2026 and July 2, 2026), an updated scams page, a dedicated scam-reporting line (1-833-500-SCAM), and named its lead scam investigator (Matt Foley) as a public spokesperson; local coverage noted San Jose Police were investigating related reports. Losses were continuing to accrue and were projected by PG&E to exceed 2025's total by year-end 2026.
This case documents a genuinely novel monetization channel within a very old pretext (utility-disconnection fear): using a barcode/QR code scanned by a real, unwitting retail cashier as the money-laundering step, instead of a prepaid card, wire, or crypto ATM. It matters for awareness training because (1) it shows scammers actively engineering around existing fraud checkpoints, choosing a payment rail (in-store barcode scan) specifically because front-line staff have no built-in prompt to question it, unlike some digital wallets and money-transfer apps that now surface scam warnings; (2) it demonstrates a utility company using its own named fraud investigator and hard loss figures to drive public-interest reporting, a useful primary-source template for "first-party disclosure" case studies; and (3) the sharp jump in average loss per victim (from $590 in 2025 to $969 in H1 2026) suggests the new channel may be more effective per-victim than older prepaid-card or wire-based utility scams, even though report volume dynamics are still emerging.
PG&E's stated defenses/advice: hang up on unsolicited disconnection-threat calls; never provide payment via barcode, QR code, prepaid debit card, gift card, cryptocurrency, or money-transfer apps (Zelle/Venmo) in response to a phone demand; do not show a utility bill to anyone who comes to the door; delinquent accounts get advance disconnection notices by mail and on the regular bill, never a surprise same-call shutoff threat; verify any account/billing concern directly via PGE.com or PG&E's official number (800-743-5000); report suspected scam calls to 1-833-500-SCAM; call 911 if in-person contact feels threatening. PG&E also publishes real-time scam alerts and by-the-numbers reporting to build public awareness, and flags that retail cashiers scanning a barcode/QR code have no built-in fraud-warning moment the way some digital payment apps do, which is part of why this channel is being exploited.
An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…
A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it…
Google's Threat Intelligence Group disclosed PROMPTFLUX, a VBScript dropper that calls the Gemini API mid-execution to have an LLM rewrite…