The parking meter takes payment by QR code now. So does the restaurant menu, the museum ticket, the package redelivery slip. Scammers noticed. In 2026, the fake QR code has quietly become one of the fastest-growing fraud formats in the country — security researchers call it "quishing," and the numbers deserve your attention.
The scale of it
QR phishing attacks grew fivefold in 2025. The curve hasn't bent since: quishing incidents jumped roughly 146% across U.S. tourist destinations in the first half of 2026, with Miami, Dallas, Seattle, and Philadelphia flagged as the biggest hotspots.
The mechanics are almost insultingly simple. A criminal prints a sheet of QR stickers and pastes them over real codes — on a parking meter, a table tent, an information kiosk. You scan what looks like the city's parking code, land on a convincing clone site, and your card number goes straight to the fraudster. Some variants harvest logins instead. Others push malware.
Why QR codes beat your instincts
Twenty years of security advice trained you to squint at a link before clicking it. QR codes erase that skill. The destination stays invisible until after you scan, and a malicious code looks pixel-for-pixel identical to a real one. Context does the social engineering — a code stuck on a parking meter borrows the meter's legitimacy.
That's the difference between quishing and ordinary phishing. The scam email has to earn your trust. The sticker just inherits it.
Where the traps get set
The pattern across security reports is consistent. Physical overlays cluster wherever QR payment is normal and people are rushed or new in town: parking meters top the list, then restaurants and tourist kiosks. Off the street, malicious codes show up on shipping packages, on posters, and in unsolicited texts and emails — anywhere a scannable square can pose as a shortcut to something you already wanted to do.
The habits that actually protect you
The defenses are refreshingly low-tech.
Before you scan a public code, look at it. Touch it, even. A sticker sitting on top of printed signage is the single biggest tell.
After you scan, stop. Your phone's camera previews the destination URL before opening it — read that preview the way you'd read a suspicious link. Misspelled domain? Odd ending? A payment page where a menu should be? Close it.
For payments, prefer the official app. If a meter's code leads anywhere other than the city's own parking app or site, pay another way. And treat any QR code that shows up uninvited — by text, by email, on a package you weren't expecting — exactly like a link from a stranger. Because that's what it is.
The bottom line
Quishing works because it hides inside a gesture we've all stopped thinking about. The fix isn't fear — it's five seconds of friction. Check the sticker. Read the URL preview. Use the official app. The scam's entire business model depends on you skipping those steps.





