A link you cannot read
A QR code is just a link you cannot see with your eyes. Scammers exploit that by placing malicious codes on parking meters, restaurant tables, invoices, and flyers, or by pasting a sticker over a legitimate code.
Scanning it can open a convincing fake payment or login page. Because the destination is hidden until you scan, QR scams, sometimes called quishing, slip past the instinct to check a link before clicking.
How the scam works
A malicious QR appears on a meter, invoice, package, or as a sticker over the real one.
"Scan to pay" or "scan to verify" feels faster than typing an address.
The code opens a counterfeit payment or login screen that looks legitimate.
Your card or credentials are harvested, and the real bill goes unpaid.
What it looks like
PARKING PAYMENT REQUIRED. Scan the QR code to pay your session fee. Failure to pay within 10 minutes will result in a citation. [QR code sticker on the meter]
QR code scam (quishing). When you scan, FraudScope can inspect the link the code points to and flag a lookalike or brand-new domain. Its guidance: pay through the official parking app or website you already trust, not a code on a sticker.
Warning signs to watch for
- A QR code sticker that looks added on top of an existing one.
- A code that asks for payment or login on a page you did not expect.
- The web address after scanning does not match the official business.
- Urgency, like a short window to "pay or be fined."
- Unsolicited QR codes in emails, letters, or on random flyers.
Check the code’s destination
When a QR code leads somewhere suspicious, paste the link into FraudScope. With URL Deep Inspection (a Pro feature) it reveals the true destination, the domain’s age, and its certificate before you ever enter a card.
Analysis runs entirely on your iPhone and makes no network requests. The only time FraudScope touches the internet is if you tap Inspect URL to check where a link really goes, and it tells you before it does.
URL Deep Inspection (Pro) · Intent reconstruction · On-device
Frequently asked
How can a QR code be dangerous?
A QR code simply encodes a web address you cannot read by eye. A malicious one can send you to a fake payment or login page, so the danger is the hidden destination. Always confirm where a code leads before entering any details.
How do I pay safely instead of scanning a code?
Use the official app or website of the business or parking service directly, typed or opened yourself. Avoid QR codes on stickers, unsolicited mail, or anything that looks added on top of an existing label.
Does FraudScope send my messages anywhere?
No. Analysis runs entirely on your iPhone with no network connection. The only time it contacts the internet is if you choose to inspect a link’s destination, and it tells you before it does.
Will FraudScope catch every scam?
No tool can. FraudScope is strongest with the full content of a message and weaker with a bare screenshot that has no link or sender. It is a powerful second opinion, not a guarantee. When in doubt, slow down and check with someone you trust.