Scammers are sticking fake QR codes over legitimate ones on D.C. parking meters, and the Federal Trade Commission wants drivers to stop and look before they scan.

The FTC issued a consumer alert in September warning that people have reported fraudulent QR codes placed on top of real ones at meters. Scanning a tampered code can send a driver to a phishing site built to steal money, personal information, or both, the FTC said. The tactic is known as "quishing," a combination of "QR code" and "phishing."

The scam is not new. WUSA9 first reported on quishing at D.C. parking meters in 2022. ParkMobile CEO Jeff Perkins told the station then that the fake sites are often easy to spot if drivers pay attention.

"Sometimes these scammers will just set up a dummy website aimed to get your information, but you can kind of see when you look at it, it doesn't really look legitimate," Perkins told WUSA9 in 2022.

WUSA9 reported that the District Department of Transportation (DDOT) is asking anyone who spots a suspicious or tampered QR code on a meter or elsewhere in D.C. to call 311 so it can be removed.

How to protect yourself

The FTC alert recommends several steps before scanning any QR code:

  • Check the URL preview. Most phone cameras show a link preview before opening it. Look for misspellings or switched letters in the web address.
  • Keep your phone updated. Installing the latest operating system and app updates can help block malicious links.
  • Use strong passwords and multi-factor authentication. These add a layer of protection if a scammer captures login credentials.

If you already scanned a suspicious code

The FTC recommends that drivers who believe they scanned a fraudulent code stop interacting with the site immediately, change passwords for any accounts where they entered credentials and review credit card and bank statements for unauthorized charges.