QR code scams (“quishing”)

A QR code on a parking meter, a restaurant table or in an email looks harmless, but you can't see where it leads until you scan it. Scammers use that.

In short

Fake QR codes stuck on parking meters or sent in emails can lead to phishing sites. How to scan safely.

Top warning signs: A sticker placed over another code; An email asking you to scan a code to log in; The preview address doesn't match the organisation.

First thing to do: Use the official app or type the official website address for parking and payments.

Example · EmailIllustrative, links disabled
IT Service Desk
Your email password expires today. To keep access, scan the QR code below with your phone and confirm your login details.
An example scam message with the warning signs highlighted.

How the scam works

Criminals stick their own QR codes over real ones on parking meters and charging points, or put codes in emails to get past security filters. The code opens a fake payment or login page.

Red flags to look for

  • A sticker placed over another code. Look for tampering.
  • An email asking you to scan a code to log in. A common trick to move you from a protected computer to your phone.
  • The preview address doesn't match the organisation. Most phone cameras show the link before opening. Read it.

What to do if you get one

  1. Use the official app or type the official website address for parking and payments.
  2. Before opening a scanned link, read the address in the preview. If unsure, copy it into our link checker.

If you already paid or shared details

Act quickly. It makes a difference.

  1. Contact your bank if you paid or entered card details.
  2. Change your password if you entered login details, and turn on two-step verification.
  3. Tell the car park operator or venue about the fake sticker.

More help: what to do after a scam, and where to report it in your country.

Official sources and further reading

We check our guides against advice from government agencies and consumer protection bodies.