All scam guides

Fake QR codes on parking meters

Updated October 11, 2026

You park, the meter has a QR code that says "scan to pay", and the page that opens looks like a parking app. On a growing number of meters, that code is a sticker placed by a scammer. The page takes your card details, and sometimes signs you up for a recurring charge. Councils and police in the UK, Belgium, Switzerland and US cities have all issued warnings.

How the scam works

  • A sticker with the scammer’s QR code goes on top of the real code, or on a meter or sign that never had one.
  • The page copies a parking operator: logo, zone number field, "pay now" button.
  • It asks for your card number, expiry and security code, sometimes your plate and phone number too.
  • Your parking is not paid, so you may still get a ticket, and the card details are used elsewhere.

Who has warned about it

  • Hartlepool Borough Council (UK, May 2025): its pay and display machines never use QR codes for payment.
  • Royal Borough of Kensington and Chelsea (UK, January 2025): fake codes on parking signs in at least six places.
  • Police in Northern Ireland and Brussels, and the Swiss National Cyber Security Centre.
  • US cities including New York and Fort Lauderdale, and the FTC (September 2026).

How to spot a fake parking code

  • The code is a sticker: raised edges, a slightly different colour, stuck on at an angle, or covering part of the printed sign.
  • The sign tells you to use an app. Install that app from the App Store or Google Play instead of scanning.
  • The address is not the operator’s own site. Real operators use their own domains, such as paybyphone.com, ringgo.co.uk, parkmobile.io or easypark.com. Check what the sign names.
  • The page asks for more than a card payment: your bank login, an ID photo, or a code sent to your phone.
  • A tiny or odd price, or a countdown pushing you to pay fast.

The safe way to pay

  • Use the operator’s official app, or pay at the machine with a card or coins.
  • If you want to use the web, type the address printed on the sign yourself.
  • If QR Snap says the link opens a site that is not the operator’s, or that the site was registered days ago, do not pay there.

What QR Snap checks before you open a link

QR Snap shows you the link first and does not open it until you tap. Before you do, it runs these checks:

  • Where it really goes. Short links and redirects are followed to the page they end on, and QR Snap shows that site ("Opens example.com, after 2 redirects").
  • Known threats. The link and its destination are checked against Google Web Risk and a public list of active phishing sites.
  • Look-alike names. A company name on a site it does not own, misspellings like paypa1 or rnicrosoft, letters from other alphabets, and an "@" that hides the real address.
  • Free website builders and file hosts. A payment or sign-in page hosted on a free site builder, a dynamic-DNS name or a storage bucket is a common scam setup.
  • Brand-new websites. Most scam sites are days or weeks old, so QR Snap shows when the site was registered.

If you paid on a fake page

  • Call your bank on the number on your card, block the card and dispute the charge.
  • Tell the council or city that runs the car park, so they can remove the stickers.
  • Report it to the police: Action Fraud in England and Wales, ic3.gov and reportfraud.ftc.gov in the US, or your local police in the EU.

What no checker can promise

New scam sites appear every day, and some hide behind bot checks so automated tools only see a harmless page. A clean result means none of the checks found a known threat, not that the page is guaranteed safe. If a page asks for card details or a password you did not expect to give, close it and go to the company yourself: type its address or open its official app.

Sources

More guides