That QR Code on the Parking Meter? It Might Be a Trap.

You scan the "Pay Here" sticker, enter your card details, and drive off — not knowing a scammer pasted it over the real code minutes ago. One tap. That's all it takes to lose your payment info to a fake site built to look exactly like the real thing. It's happening right now on streets across Melbourne, Sydney, and Brisbane.

Rise in quishing incidents

recorded across the Asia-Pacific region in the first half of 2026 alone

Australian cities targeted

Melbourne, Sydney, Brisbane & Perth — parking meters and bike-share docks hit hardest

Why a Little Square of Dots Can Be So Dangerous

With a regular link, you can hover before you click. With a QR code, you can't — you're already en route to the destination before you ever see the URL. That blind leap is exactly what scammers exploit.

73%

of people scan QR codes

without checking where they actually go first

The Low-Tech Physical Scam

A scammer prints a sticker with their own malicious QR code and slaps it over the real one — on a parking meter, an EV charger, a restaurant table. You land on a pixel-perfect clone that hoovers up your card number, billing address, and CVV in real time.

It's Not Just Parking Meters

Scammers embed QR codes inside email images to slip past security filters — impersonating tax agencies, HR portals, even your own IT department. And because the scan happens on your personal phone, your workplace's defenses never even see it coming.

Simple Ways to Stay Safe

Give it a quick look first

Before you scan a QR code — say, on a parking meter in the CBD or at an EV charger — just take a quick peek. If the code looks like it has a sticker sitting on top of it, or the edges are peeling up, it's worth walking away and finding another way to pay.

Read the address your phone shows you

When you scan a QR code, your phone will show you a web address before it takes you anywhere. That's your chance to check it looks right. If it looks odd or unfamiliar, just don't tap "go" — it's that simple.

Watch out for funny-looking addresses

A real bank or government website will have a clean, recognisable address — like mybank.com.au. If you see something with random hyphens, odd spellings, or a strange ending like .xyz, it's almost certainly a scam. If it doesn't look right, trust your gut.

Be careful with codes you weren't expecting

If a QR code turns up in an email or a text message out of the blue — pretending to be from the ATO, Medicare, or your bank — don't scan it. Scammers try to make you feel rushed or worried so you act before you think. Take a breath. There's no hurry.

Not sure? Just type it in yourself

If something feels off, skip the QR code altogether. Open your browser and type in the address yourself, or go straight to the official app. A couple of extra seconds is a very small price for peace of mind.

The good news is that most QR codes — at your local café, at the footy, at the shops — are completely fine. You don't need to be afraid of them. Just take one small moment to check before you scan. That's really all it takes.

It's Happening in Australia Right Now

Scamwatch and the Australian Federal Police flagged quishing as a fast-growing threat in 2025–2026. Fake QR stickers have been found on parking meters, bike-share docks, and café menus in Melbourne, Sydney, and Brisbane. The scam works because we've been trained to trust QR codes — and criminals know it.

Fake stickers on real infrastructure

Fraudsters placed counterfeit QR stickers directly over official codes on parking meters and bike-share docks across Australian CBDs. One scan, and your payment or login goes straight to them.

The physical check is your best defence

Run your finger across the code. Look for peeling edges, bubbling corners, or branding that doesn't match the sign around it. A fake sticker almost never blends in perfectly — if you know to look.

Read the URL before you tap

Your phone previews the destination — actually read it. Addresses like cityofmelbourne-pay.xyz are traps. If it looks even slightly wrong, stop. Type the official address yourself instead.

If You Manage a Business, Restaurant, or Public Space

QR code scams aren't just a consumer problem. If you use QR codes for payments, menus, or check-ins, a single fake sticker on your premises can drain your customers' accounts — and your reputation with them.

🛡️ Use tamper-evident materials

Laminate your codes or choose sticker stock that visibly tears or discolours when removed. Most Australian office supply stores stock it.

🔍 Do a weekly physical check

Walk your venue and inspect every QR code for peeling edges, bubbling, or anything layered on top. Two minutes. Do it.

🌐 Display your URL alongside the code

Print your official web address next to every QR code so customers can verify they've landed in the right place.

📣 Brief your staff

Show your team what a tampered code looks like and who to contact if they spot one. Five minutes at your next team meeting is all it takes.

Australian payment processors and parking tech companies are beginning to embed security features — colour-shifting ink, unique serial numbers — directly into official QR codes. Until that becomes the norm, a human eye remains the best defence.

Not every code warrants suspicion. Codes printed onto menus, boarding passes, or original marketing materials are generally safe — they're part of the item itself. The question to ask is simple: was this code added on top of something, or is it part of the original?

#CyberSecurity#QRCodeScam#Quishing#ScamAlert#StaySafeOnline#ConsumerSafety

Your Simple Take-Away

Staying safe from QR code scams does not require any technical skill. It just takes one extra second before you scan. Here is all you need to remember:

Look before you scan

Check if the QR code looks like a sticker stuck on top of something. Peeling edges or mismatched branding are red flags.

Read the link preview

Your phone shows you the web address before opening it. If it looks odd or unfamiliar, do not tap "Open."

Type it yourself when unsure

If anything feels off, skip the QR code and go directly to the official website or app by typing the address yourself.

Ignore unexpected codes

Never scan a QR code sent to you in an email or text you were not expecting — even if it looks official.

Glossary: Key Terms Made Simple

New to some of these words? Here is a plain-English explanation of the key terms used in this article.

QR Code

A square pattern of black and white dots that your phone's camera can read. It works like a shortcut — scanning it automatically opens a website or app, the same way clicking a link does.

Quishing

A made-up word combining "QR code" and "phishing." It means a scam where criminals use a fake QR code to trick you into visiting a fraudulent website and handing over your personal or financial details.

Phishing

A type of online scam where criminals pretend to be a trusted organisation (like your bank, a government office, or a well-known company) to trick you into giving them your passwords, card numbers, or other sensitive information.

Cloned Website

A fake copy of a real website. It is designed to look identical to the genuine site — same colors, logos, and layout — but it is run by scammers who capture everything you type into it.

Tamper-Evident Material

A special sticker or label material that visibly tears, discolors, or leaves a mark if anyone tries to peel it off or stick something on top of it. Businesses use it to show if something has been interfered with.

Email Security Filter

An automatic system that scans your incoming emails and tries to block dangerous links or attachments before they reach your inbox. Scammers sometimes use QR codes inside images to sneak past these filters.

Billing Address

The home or business address linked to your payment card. Banks use it to verify that the person making a purchase is the real cardholder.

Security Code (CVV)

The 3- or 4-digit number printed on the back (or front) of your payment card. It is used as an extra check when paying online to confirm you physically have the card.