You're late, the parking meter's card reader is broken, and there's a clean little sticker on the pole that says "Scan to Pay." You scan it, type in your card number, and go on with your day. Nothing looks wrong. Nothing feels wrong.
That's the whole scam. The FTC and the FBI's Internet Crime Complaint Center have both issued formal warnings about "quishing" — QR code phishing — after fake sticker codes turned up pasted directly over real ones on parking meters in cities including Austin, Houston, and Fort Lauderdale. New York City's transportation department issued a similar warning. Miami's parking authority got tired of it entirely and pulled QR-code payment as an option.
The trick works because a QR code doesn't announce itself the way a suspicious link does. You can hover over a link and see where it goes before you click. You can't do that with a QR code — your phone commits the moment it reads the square.
A QR code isn't a program and it isn't magic. It's encoded text — nothing more. After this, you'll understand what that text actually contains, why some QR codes carry real risk and others carry almost none, and the one habit that closes off the scam entirely, no matter how convincing the sticker looks.
Here's the part most warnings skip: a QR code is just text, and the "type" is simply a hint that tells your phone how to act on that text. A Website type hands your browser a URL and opens it. A Wi-Fi type hands your device network credentials and joins it. A Contact type hands your address book a name and number. Same mechanism underneath, very different consequences depending on what your phone does with it.
That's why the risk isn't flat across every QR code you'll ever scan:
High risk — Website codes. This is the type behind every documented quishing case above. It takes you off your device to a page that can ask for a card number, a password, or push a bad download. If a QR code wants you to log in or pay, this is the type doing the work, and it's the one that deserves real caution.
Moderate risk — Wi-Fi codes. These join your device to a network automatically. Less immediately dangerous than a phishing page, but a malicious network can still position itself to see unencrypted traffic. Worth a second look, not a full stop.
Low risk — Contact, Phone, and Plain Text codes. These display information or pre-fill an action — add a contact, dial a number, show a message. They don't take you anywhere or ask you for anything. Any real risk here comes from what the message talks you into doing next, not from the code itself.
The QR code itself never steals anything. It only points. The danger is entirely in what it points to and whether you check before you follow.
A code applied as a sticker is worth more suspicion than one printed directly on the surface — a parking authority's official signage, a restaurant's laminated table card. Printed doesn't mean guaranteed safe (tampered restaurant codes are documented too), but it does carry more built-in trust than a loose sticker slapped on top of something else.
Look for the physical tells: a corner peeling up, a sticker sitting slightly crooked or off-center, a code that looks new next to signage that looks old. And watch for the behavioral tell regardless of how official it looks — any QR code that wants a password or a card number the moment you scan it has crossed into the territory where you should slow down.
When you scan any QR code, your phone shows you the destination before it fully commits — a URL preview, an app opening, a Wi-Fi network name. Read that preview before you tap into it or type anything. If it's a website and the address doesn't match the business you expected, close it and walk away. If something about the URL looks scrambled or unfamiliar, running it through a link checker before you go any further is a smart extra step.
That single pause — read before you act — defeats the sticker trick completely. The scammer is counting on you scanning and typing without a second look. Give it the second look.
Want to see for yourself that a QR code really is just text with nothing hidden inside it? Build one with the ZTDev QR Code Maker — try a Website type and a Contact type back to back, and you'll feel the difference in what each one actually triggers on your phone.