A QR code is a door with the address painted on the other side.
That is convenient when the code belongs to a restaurant menu, transit system, ticket, parking meter, or event organizer. It is also the reason QR-code phishing works: the user often cannot judge the destination until the phone has already decoded it.
In September 2026, the Federal Trade Commission warned about reports of scammers covering legitimate QR codes on parking meters with fraudulent ones. A driver sees the meter, sees a code in roughly the place a code should be, scans it, and lands on a site designed to collect money or personal information.
See the FTC’s warning about altered parking QR codes.
The physical object lends the link credibility
A scam email has a sender address. A suspicious website has a visible domain. A QR sticker attached to a city parking meter inherits some of the meter’s authority before the phone ever opens a browser.
That transfer of trust is the trick.
The FTC has also documented QR-code scams delivered through texts and emails, including messages claiming a package could not be delivered, an account had a problem, or suspicious activity required a password change.
See the FTC’s earlier consumer alert on harmful links hidden in QR codes.
The code itself does not prove who created it. A perfectly functional QR code can lead to a perfectly fraudulent site.
Preview the destination before trusting the context
Many phone cameras and QR readers display the destination before opening it. That preview deserves more attention than the logo, sign, envelope, flyer, or parking meter carrying the code.
Look for misspellings, substituted letters, strange subdomains, or a domain that simply does not belong to the organization named on the physical object.
For a payment, account change, fine, or government notice, the safer route is often to ignore the code entirely and reach the organization through a known website or official app.
The same rule applies when a QR code appears in a message that creates urgency.
A square of black-and-white pixels is not proof of identity.
It is merely a compressed instruction telling your phone where to go next.
The security decision begins after the phone decodes it, not before.
