Where fake QR codes turn up
Most QR code fraud happens in open spaces: parking meters, car parks, stations, restaurant tables and posters, where a sticker can cover the real code. The UK’s National Cyber Security Centre said so in February 2024, and Action Fraud (now Report Fraud) counted 784 reports and almost £3.5 million lost between April 2024 and April 2025, with car parks the most common place. In the US, the FTC warned about codes in unexpected emails, texts and letters in December 2023 and about fake codes on parking meters in September 2026, and the FBI’s 2022 warning adds: check that a code hasn’t been stuck on top of another.
What the checks look at
The address is split the way a browser reads it. The example above starts with paypal.com, but the site is parking-fines.example: everything before the real name is decoration, and that trick is flagged red. The checks also flag lookalike spellings (paypa1, accented or foreign letters), a brand’s name on someone else’s domain, an @ in the address, shorteners and dynamic QR services that hide the destination, free hosting where anyone can publish, domain endings most abused for phishing, a second address hidden inside the link and app downloads.
What to do next
If the verdict is red, don’t open the link: pay through the operator’s own app or a website you type yourself. If it’s amber, compare the website name with the organisation you expect. When a code on a meter looks stuck on, tell the operator so they can remove it.