A little sticker on a parking meter in San Clemente cost a California man’s wife her credit card, and it happened in about the time it takes to walk back to the car. Vance Ingmanson scanned a code, typed his card number into a page that said Passport Parking and looked completely legit, and a few minutes later his wife’s card company was already calling about charges he never made. When he went back and searched the parking website online, he found that the top five results were all fakes.
That is the whole scam in a sentence. And the part that gets me is how cheap it is to pull off. There is no genius hacker in a basement. There is a guy with a label printer and a glue stick.
Nobody Hacked Anything. It’s Just a Sticker.
The FBI actually has a name for this trick. They call it quishing, which mashes together QR code and phishing. Sounds high tech. It is anything but. Criminals never touch the meter’s software or install a single thing. They print a QR code that points to a website they control, stick it over the real one, and stroll off.
When you scan, your phone opens a page built to look exactly like the city’s payment portal. You enter your card. It lands in a stranger’s inbox instead of the city’s account. And because the whole thing runs on a website, not on some flaw inside your phone, iPhone and Android users are equally exposed. There is no update that patches this. The scam targets your habits, not your hardware.
One Beach Town Doesn’t Even Use QR Codes
Manhattan Beach, one of those pretty Los Angeles beach towns, does not use QR codes for parking. Never has. So when police there spotted QR stickers showing up on the meters, they knew right away that every single one was planted by a thief. There was no real version to confuse them with.
Think about how clean that is as a rule of thumb. In that city, a code on a meter is a red flag, period. It is a good reminder that a lot of towns still want you to pay with coins, a card in the machine, or an app you download yourself. If a bright new sticker is telling you the only way to pay is to scan and type your card, be suspicious.
The One-Letter Trick That Fools Everyone
Down the coast in Redondo Beach, police peeled fake codes off roughly 150 meters along the Esplanade and Riviera Village. The thieves glued them right next to the real ParkMobile and PayByPhone labels, which is honestly diabolical. The fake site was called poybyphone.online. Read that again. Poybyphone. They swapped one letter and rushed drivers sailed right past it.
Another version used a site called poi2park.com, dressed up to look like pay2park.com. One character. That is the entire disguise. When you are half out of your car and already late, your brain fills in what it expects to see, and it reads the word it wants to read. That tiny gap between what you glanced at and what was actually printed is the whole business model.
You Can Actually Get Robbed Twice
The cruelest wrinkle is that one scan can hit you two ways. Your card details go to the crook, obviously. But the meter never registered a payment, because you never actually paid the city. So you can walk back to a parking ticket on your windshield, or a towed car, sitting right on top of the fraud. Congratulations, you paid a stranger and the city still wants its money.
Thieves also like to run a tiny test charge first, something small enough that you probably will not notice, just to confirm the card works before they swing for something bigger. So that weird 99 cent charge you do not recognize is not nothing. It is a warning shot. If you spot one, call your bank before the real hit comes.
Why Smart People Still Fall For It
Plenty of folks who would never click a sketchy email get caught by this one. Why? Timing and setting. You are in a strange neighborhood, you are running late, the meter looks old and busted, and paying by phone feels like the modern, easy option. Everything about the moment pushes you to move fast and stop asking questions.
A privacy consultant summed it up nicely: the convenience of point and pay is so tempting that it usually beats out good caution. Travelers get burned the hardest because they are always in unfamiliar spots, always rushed, and already scanning codes ten times a day. The crooks are not outsmarting you. They are just betting you will be in a hurry, and they are usually right.
It’s Way Bigger Than a Couple Beach Towns
This is not a two-beach-towns problem. Quishing reports have jumped 587% since 2023, according to Check Point Research. The FBI put out a public warning after fake stickers turned up on meters in Austin, Houston, and San Antonio. Austin alone reported more than 100 tampered meters in a single incident.
It has hit Chicago. It hit Toronto, where police confirmed cases in late April 2026 and told drivers to check codes for peeling edges and mismatched branding. It has popped up across the UK and Australia too. Same sticker, same script, different zip code. What started as a clever little California stunt turned into a copy-and-paste crime you can now find almost anywhere people park.
It Already Jumped Off the Meter
Meters were just the opening act. The Better Business Bureau got reports of fake codes on public transit, plus packages, concert flyers, and pop-up ads. Some were stuck onto traffic signals, signposts, and the windows of empty storefronts, places where a code looks completely normal and nobody is watching.
Toronto’s bike share program warned that thieves were slapping fake codes right over the real ones on the bikes themselves. The company reminded riders it will never ask for payment through a code you scan with your phone camera. Restaurant menus, hotel flyers, scooter docks, they are all fair game. Anywhere a QR code feels ordinary, somebody is testing whether they can fake it.
How to Beat It in About Three Seconds
The simplest move is to skip the code on the meter entirely. Download the actual parking app straight from the App Store or Google Play, or type the city’s payment website into your browser by hand. Scanning a random square glued to a pole is the risky part, so cut it out of your routine.
Feel the meter before you trust it. Real city instructions are usually printed on the machine or built right in, not a shiny decal slapped on top. Run a finger along the edge. If there is a sticker sitting over another sticker, that is your cue to walk away and pay with coins or a card at the machine instead. Compare it to the meter next to it while you are at it.
Pay with a credit card, not a debit card. Credit cards give you far better protection if your number gets stolen, and the money is not vanishing out of your checking account while you argue about it. And if you already typed your card into a shady page, call your bank first, before anything else, and freeze the card. The first couple of hours matter most.
What sticks with me is how boring this scam looks. A QR code on a meter is exactly what you expect to see now. That is the entire reason it works. Scanning has become such a reflex that most of us stopped actually looking. A quick glance at the sticker edge and a read of the web address, and you beat the whole thing.
