Consumer Safety & Digital Privacy
FTC warns about fake parking QR codes: what California drivers should check
Scammers can cover a legitimate parking QR code with their own sticker. California cities use different payment systems, so verify the local rule before scanning or paying.

A sticker over a parking code can redirect the payment
Scammers have covered legitimate QR codes on parking meters with their own codes, the Federal Trade Commission warned Thursday, September 3. A driver who scans the replacement may land on a convincing payment page built to collect money, card details, account credentials or other personal information. The warning does not identify a specific California city or publish a victim count. Its immediate value is the method: a routine curbside payment can be redirected before the driver sees a clear reason to question it.
California cities do not use one universal QR-code rule
A sticker is a reason to stop, but the absence or presence of a QR code is not a statewide test of legitimacy. Sacramento says its official parking QR codes are printed directly on city signs, not applied as stickers; the city asks people to report a suspicious or altered code to Sacramento 311 and use another payment method when unsure. Beverly Hills takes a different approach: the city says it does not use QR codes for parking payments at all and asks people who find one on a meter to note the location and report it to the police non-emergency line or AskBH. Those two official policies show why advice from another city—or a photo from social media—cannot authenticate the sign in front of you.
Verify the city’s payment path before opening the camera
Read the entire sign and look for a meter number, zone code, city web address and signs of a label placed over another surface. If anything appears altered, move to a different meter or payment method and open the parking agency’s website by typing its known address or finding it through the city’s official website. Download a named parking app from the phone’s official app store rather than through a QR prompt. Match the zone or location number in the app to the physical sign before paying. A polished page, padlock icon or familiar color scheme does not prove that the payment recipient is the city or its contractor.
If you scan first, inspect the destination before entering anything
Many phones show the destination domain before opening it. Compare the spelling and domain ending with the address published by the city, and close the page if letters are switched, the name is unfamiliar or the site asks for information the normal parking process does not require. The FBI advises people not to download an app from a QR code and to avoid making a payment through a QR destination when a known, trusted route is available. Keep the phone operating system and apps current, and use a unique password plus multifactor authentication on accounts that store payment details.
What to do after a suspicious scan depends on what happened next
If you only opened the page and did not enter information, make no payment, download no file and grant no permission. Close it, preserve the destination address if that can be done safely and report the altered sign to the local parking authority. If you entered a password, change it immediately on the real service and anywhere else it was reused, then turn on multifactor authentication. If you entered card or bank information or approved a payment, contact the financial institution through the number on the card or its official app, report the transaction as fraudulent and ask what can still be stopped or disputed. Review recent activity instead of waiting for the next statement.
Preserve the curbside evidence and use direct reporting channels
Photograph the meter or sign from a safe position, including the sticker, meter or zone number and enough surroundings to identify the location. Save the destination URL, payment receipt, time, amount and any bank alert without continuing to interact with the suspected site. Report the sign to the city or parking operator using contact information from an official page. The FTC accepts fraud reports at ReportFraud.ftc.gov; the FBI directs victims of stolen funds or suspicious QR schemes to IC3.gov. If personal information was exposed, IdentityTheft.gov can build a recovery plan. A report does not guarantee recovery, but it gives investigators and the payment provider a usable record.
The California angle is local verification, not a claimed statewide outbreak
The FTC alert is national, and NOCTI found no official basis to claim a new statewide or Southern California surge. Sacramento and Beverly Hills are included because their current public instructions demonstrate a material local difference: one uses QR codes only when they are printed into official signage, while the other tells drivers that no parking QR code is legitimate. Check the rule for the jurisdiction where the vehicle is parked, and do not assume Irvine, Orange County, Los Angeles, San Diego or another city follows either example. This article is consumer education, not legal or financial advice.
Sources
- FTC: See a QR code parked somewhere? Don’t scan it…yet! (September 3, 2026) ↗
- City of Sacramento: parking-meter payment and QR-code warning ↗
- City of Beverly Hills: Flowbird and parking QR-code policy ↗
- FBI Internet Crime Complaint Center: tampered QR-code warning and reporting ↗
- California Attorney General: payment-scam verification and reporting guidance ↗
- FTC: IdentityTheft.gov recovery planning ↗
Find men's massage near you
Compare local providers privately and contact the professional you choose directly.
Search NOCTI