Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

The QR code on a parking meter may be somebody else's sticker

A parking meter may direct you to an app or payment page through a QR code. Check that nobody has covered the genuine instructions before you pay.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
10 September 2026
READING TIME
7 min read
TOPIC
Human Security
The QR code on a parking meter may be somebody else's sticker

You are standing beside the car, rain is starting and the parking meter tells you to scan a QR code. Your telephone opens a page resembling the city’s payment system. You enter the registration number and card details because the code was attached to a machine on the street.

The code may not be part of the meter at all. It could be a sticker placed over the genuine instructions by somebody who wants to redirect drivers to a fake page. The physical setting inspires confidence, but a sticker can be replaced as easily as a link in a message.

Look at the meter first

Check whether the code is raised, covers another label or uses a different visual style from the rest of the instructions. Adhesive marks, uneven corners, different printing or several labels stacked on top of each other are reasons to choose another payment method.

A neatly applied code is not proof either. Look for the official app name, website address or parking-zone number printed elsewhere on the machine. If the city or operator has an app you already use, open it from your telephone’s home screen instead of installing something through the scanned link.

Read the address before opening it

Many camera applications preview the destination before visiting it. Pause on that screen. A spelling error, extra hyphen, unusual domain ending or city name that appears only later in the address should make you cautious.

On the page, compare the operator and charging rules with the information on the meter. A fake form can be polished, carry a map and display the correct logo. A padlock means your connection to that page is encrypted; it does not establish that the city owns it.

Parking should not require your bank password

Paying for a space normally needs details about the vehicle, zone, duration and payment method. The page should not ask for an email password, account recovery code or software to “confirm your location”. Do not approve a banking-app operation when its amount or recipient does not match the parking payment.

If anything differs from the usual process, use the card reader on the machine, coins, a known app or another meter. A few minutes spent checking cost less than blocking a card and recovering an account.

If you already scanned it

If you only opened the page and entered nothing, close it. Photograph the questionable sticker without scanning it again and report it to the parking operator or road authority. Do not remove it yourself if that risks damaging the equipment or provoking a confrontation.

If you supplied card details, contact your bank, freeze or replace the card under its guidance and review transactions. If you entered a password, change it through the genuine service, particularly anywhere else that shares it. Preserve the photograph, destination address and transaction records.

What the source says and what Breachroad recommends

On 3 September 2026, the US Federal Trade Commission warned about QR codes placed over genuine codes on parking meters. Reports describe fraudulent codes leading to pages designed to steal money, personal information or both. The FTC advises inspecting the address preview and, after entering information, changing passwords and reviewing transactions.

Breachroad recommends checking both the physical sticker and the digital address. A QR code is not an operator’s seal; it is simply a convenient way to store a link.

Our guide to quishing and QR-code phishing covers more examples. We help organisations develop the same practical instincts through cybersecurity training.

SHARE / COPY