QR Code Scam (Quishing): How It Works
Dad held his phone up to the QR code on the parking meter. It wasn't really the city's.
Bernard, 80, in Austin, was parallel parking on South Congress when he saw the new digital parking meter on the curb. There was a yellow sticker on the front with a QR code and the words SCAN TO PAY. He fished out his iPhone, held it up to the code, and a link popped up at the bottom of the screen โ something with a string of letters he did not recognize.
He almost tapped it. The street was busy. He was already late. But the address looked off โ it wasn't the City of Austin domain he expected to see. He set the phone down on the dashboard and looked at the meter more carefully. The yellow sticker was peeling at the corner. Underneath was a different sticker, printed in city blue.
Bernard opened Tiina on his iPhone and asked, out loud, whether scanning a QR code on a parking meter was something you were supposed to do, or something you weren't.
The sticker was peeling. There was a different sticker under it.
He opened Tiina.
A QR code scam โ sometimes called 'quishing' โ uses a fake QR code (often a sticker glued over a real one on a parking meter, menu, or shipping label) to send you to a fraudulent payment or login page. The phone camera doesn't know the difference. With Tiina, a voice-first AI companion for older adults, Dad describes what he's about to scan out loud and gets the rule before the camera opens: use the official app or the printed phone number, not a sticker.
If your dad almost scanned the fake sticker, it is not because he doesn't understand technology. He understood it just fine โ point camera, get link. The problem is that QR codes are designed to be a black box. Nobody reading them can tell what's behind the square, scammer or city.
Your job is not to ban him from using his phone camera. Your job is to give him one simple rule: never tap a link from a sticker on a public surface. Use the printed phone number or the official app instead.
Stickers can lie. Apps usually don't.
What's actually happening with QR code scams
A QR code is just a black-and-white square that encodes a web address. The phone camera reads it and offers the address as a link. There is no built-in verification of where that link goes. Scammers exploit this by printing their own QR code stickers and slapping them on top of legitimate ones โ parking meters, electric vehicle chargers, restaurant menus, package labels, even paper flyers at airports and train stations.
The fake link sends the victim to a page that looks like the real one โ City of Austin parking, the restaurant's payment portal, a USPS package-tracking screen โ and asks for a credit card or login. The data goes straight to the scammer. By the time the senior realizes the parking was never actually paid, the card is already being run at a different merchant.
The FTC and FBI have both issued public alerts about QR code scams (sometimes branded 'quishing') as a growing threat, especially in tourist areas and around shipping and package delivery. IC3 receives thousands of reports annually. Older adults are not the primary targets demographically โ anyone can fall for a sticker โ but the financial losses tend to be higher when seniors are involved because the scripts that follow the scan often escalate.
What Tiina does at the meter
Bernard described the situation to Tiina from the front seat of his car โ the sticker, the peeling corner, the strange URL, the second sticker underneath. Tiina answered fast. The peeling sticker was almost certainly a quishing overlay. He should not tap the link. The right way to pay for parking in Austin was either at the meter's keypad, by calling the printed phone number, or through the official ParkATX app โ never through a sticker that anyone could have put there.
Bernard rolled down the window, peeled off the yellow sticker entirely (it came off in one piece), and saw the real city-blue sticker underneath with the official phone number printed in white. He dialed the number. Parking was paid in two minutes. No card number went to anyone except the city.
He took a photo of the peeled sticker and the meter and emailed it to the parking authority when he got home, the way the official ParkATX page suggested for reporting suspicious overlays.
What changes after Dad parks safely once
Bernard did not stop using his phone camera. He did not stop paying for parking. He just stopped trusting the sticker. The next time he was in a parking garage with a QR code on the wall, he ignored it and used the keypad. The time after that, he used the official app. The rule was simple โ stickers are not authority. Apps and printed phone numbers are.
Farida did not have to drive him around. She did not have to take his iPhone away because of one bad sticker. He kept his independence, his car, and his ability to go downtown on a Saturday afternoon. The scam tried to take a Saturday from him. It got nothing instead.
The dignity matters here. Bernard still gets to use technology like an adult. He just learned which piece of the technology was the lie.
A scammer counts on no one being there to ask. Tiina is โ a companion on the phone who'll talk through any "urgent" call, calmly, before your parent does anything they can't undo.
What you can do for Dad this weekend
First, install the official app for whatever city he parks in most. ParkMobile, ParkATX, PayByPhone, MeterUp โ whichever one your local government uses. Walk him through paying once at the kitchen table with no clock running. He needs the muscle memory in calm conditions, not at the curb.
Second, share the one-sentence rule: Never pay through a QR code sticker. Use the printed phone number or the official app. Tape it inside the visor of his car if he is that kind of organized โ most dads are.
Third, put Tiina on his iPhone so he can ask, out loud, the next time he sees a QR code on something he wasn't expecting โ a restaurant menu, a package label, a flyer at the post office, a meter on the street.
What this sounds like with Tiina in the room
Bernard opened Tiina from the driver's seat. There's a QR sticker on the parking meter. I scanned it and the link looks weird. Should I tap it? Tiina answered fast. Don't tap it, Bernard. QR scams put fake stickers over the real ones โ there's almost certainly a different sticker underneath that one. He looked again. You're right. The yellow one is peeling. There's a blue one underneath. That's the real one. Use the phone number printed on the blue sticker or the official parking app. Never pay through a sticker on a public meter โ you can't tell who printed it. He dialed the printed number. Parking paid in two minutes.
Dad parks downtown again. He uses the app, not the sticker.
Tiina lives on Dad's iPhone. The next time he sees a QR code on a parking meter, a menu, or a delivery slip, he asks out loud before he scans. The link he doesn't tap is the scam that doesn't happen. Stickers can lie. Apps usually don't.
Set Tiina up for Dad โMethodology & editorial policy
Reviewed and updated May 14, 2026 by the Tiina Editorial Team. Re-checked as new federal data, agency updates, or product changes warrant. Sources are linked below; numbers are not composite.
About composite scenarios. Scenes and sample conversations in this article are composite. Names and identifying details are changed; the moment is real.
About Tiina. Tiina is a voice-first AI companion for older adults โ an app for iPhone and iPad that your parent opens to talk through a moment that doesn't feel right.
Sharing. Quote freely with a link back to this page. For full reprints, email hello@tiina.ai.
Sources. 4 references โ primary sources for the numbers and claims above.View all
- FTC โ QR Code Scams โ We cited the FTC's consumer alert on QR code scams and the recommendation to avoid scanning unfamiliar codes.. consumer.ftc.gov
- FBI IC3 โ Internet Crime Complaint Center โ We referenced IC3 reporting on QR code scams (quishing) as a rising threat category.. ic3.gov
- FBI โ QR Code Scam Public Service Announcement โ We referenced the FBI's public warning about malicious QR codes on parking meters and public infrastructure.. ic3.gov/PSA220118
- AARP Fraud Watch Network โ We referenced AARP's tracking of QR code scams targeting older adults in tourist and retail settings.. aarp.org/money/scams-fraud
Frequently Asked Questions
Yes โ a malicious QR code can send you to a fake login page that harvests passwords, a fake payment page that captures card numbers, or a site that triggers a malware download. This is called quishing (QR phishing), and the FBI's IC3 has issued public alerts about it. The QR code itself doesn't 'steal' data by being scanned, but the website it opens can. Before tapping any URL preview your phone shows after scanning, look for red flags: random hosting domains (e.g., 'pay-now.xyz'), misspellings, or a domain that doesn't match the brand or business you expected. If anything looks off, don't tap.
Three quick checks. First, use your camera's link preview โ every modern iPhone and Android shows the URL before opening it. Read the URL: does the domain match the brand (e.g., 'starbucks.com,' 'austintexas.gov')? Misspellings ('starbuks-pay.xyz'), unrelated domains, or random subdomains are red flags. Second, look at the physical surface โ a sticker that's peeling, misaligned, or covering another sticker is likely a fraud overlay. Third, when in doubt, use the official app or a printed phone number on the device itself instead of the QR. The FTC and FBI both recommend skipping any public QR code you can't verify against another source.
Often identical to a real one โ that's why visual inspection alone isn't enough. The most common giveaways are physical: a sticker overlay on top of an existing QR code (you can sometimes lift the corner), a code on a parking meter or EV charger that looks newer than the surrounding paint, a printed flyer in a public space with no clear business name, or a QR on an email or letter that doesn't match the sender's official domain. The real test happens after you scan: check the URL preview. If the domain doesn't match the brand or city you expected, or if the URL is a random shortener (bit.ly, tinyurl), don't tap.
Act fast. First, disconnect the phone from Wi-Fi and cellular data to stop any in-progress download. Run a full antivirus scan if you have one installed. If you entered a password on the fake page, change it immediately from a different device, and change it everywhere you reused the same password โ start with email and banking. If you entered card info, call the number on the back of the card and request a freeze and chargeback. File reports at reportfraud.ftc.gov and IC3.gov. If the QR was on public infrastructure (parking meter, EV charger, ATM), photograph it and report to the operating agency so they can remove the overlay.