Quishing more than doubled in 2026 — and it went physical
QR code phishing, commonly called "quishing," emerged as one of the fastest-growing attack vectors of 2026, more than doubling in reported incidents over a single reporting period. What makes quishing distinct from email-based phishing isn't the destination — it's the delivery mechanism. A QR code shows you nothing about where it leads until your phone has already begun resolving the link, unlike a hyperlink where hovering reveals the destination before you click.
Why parking meters specifically
Physical quishing has found a particularly effective home on parking meters, restaurant table menus, and public event posters — locations where scanning a QR code to pay or access information is already an expected, routine action. Attackers print a sticker with a malicious QR code and place it directly over the meter's genuine payment code, banking on the fact that most people scan without a second thought in a location where scanning is the normal behavior.
The physical tells that still matter
- A sticker layered on top of the original code. This is the single most common installation method — look for adhesive edges, a slightly different printing style, or a code that looks freshly applied compared to the rest of a weathered meter.
- Inconsistency with nearby meters. If every other meter on the block has a consistent, official-looking code and one has a visually different sticker, that's the one to be suspicious of.
The digital tells that catch what your eyes miss
Most modern phone cameras display a preview of the destination URL before actually opening it when you scan a QR code — read that preview carefully rather than tapping through automatically. A domain that doesn't match the city or official parking vendor, or that redirects to an app download outside your phone's official app store, are both strong indicators the code has been tampered with.
The alternative-payment-method check
Nearly every official parking system offers at least one non-QR payment path — a phone number to call, or an official app you can open directly rather than through the scanned link. If that alternative exists and works, it's both a safer way to pay and confirms the QR code itself was never strictly necessary.
Reporting matters more than most people realize
A tampered QR code sticker typically stays in place until someone reports it to the city or property owner — there's no automated system that detects and removes a physical sticker the way a malicious website might eventually get blocklisted. Reporting what you find protects everyone who would have scanned that code after you.
Frequently Asked Questions
Quishing is QR code phishing — using a malicious QR code instead of a phishing link. It more than doubled as an attack vector during 2026, partly because a QR code reveals nothing about its destination until your phone has already started resolving it, unlike a hyperlink you can hover over first.
Most commonly, an attacker prints a sticker with a malicious QR code and places it directly over the meter's genuine, official payment code. Look for adhesive edges, a mismatched printing style, or a code that looks newer than the rest of a weathered meter — these are signs of a sticker layered on top.
It's one of the most useful checks available. Read the previewed URL carefully and compare it against the official city or parking vendor's actual domain — a mismatch, or a domain that looks like a close copy of the real one, is a strong scam signal before you ever open the page.
Look for the official parking app or a phone number printed on the meter as an alternative payment method — nearly every official system offers one. If it exists and works, that also confirms the QR code was never strictly required to pay.
Yes — the Fake Parking Meter QR Scam Checker is an 11-point field checklist covering sticker tampering, URL preview verification, domain matching, and alternative payment methods, fast enough to run in under 30 seconds before you scan.