Security & privacy
QR code stickers placed over real ones — the overlay attack
Because a QR code is unreadable to humans, replacing one with a printed sticker is invisible until someone checks. The attack costs pennies and targets parking meters, EV chargers, payment standees and restaurant tables. Feel for a raised edge before paying, and venues should use tamper-evident labels and routine audits.
The attack in one sentence
Print a sticker with your own QR code, paste it over a genuine one, and every scan from that moment on goes to you instead. No malware, no hacking, no technical skill — a sheet of self-adhesive labels and a domestic printer are the entire toolkit, and one sheet is enough to compromise dozens of locations.
Why it works so well
- Codes are opaque to humans. Nobody can tell two QR patterns apart at a glance, so a substituted code raises no suspicion the way a substituted sign would.
- The trust transfers automatically. The victim trusts the parking machine, the payment standee or the table tent. The sticker inherits that trust for free.
- Detection is passive. The genuine owner rarely scans their own codes. An overlay can sit undetected for days or weeks — until a customer complains about a payment that never arrived, which is often the first signal.
- The cost asymmetry is extreme. The attacker spends pennies per location; the victim loses card details or a full payment.
Where it happens
The documented pattern concentrates on unattended payment points:
| Location | What the fake code does |
|---|---|
| Parking meters and signs | Fake payment page harvesting card details — see parking QR scams |
| EV charging stations | Same card-harvesting flow, often with "activate charger" framing |
| Restaurant tables | Cloned menu or ordering page taking card payments — see fake menu scams |
| Payment standees in shops | Payee substitution: your payment goes to the attacker's account |
| Charity collection boxes and posters | Diverted donations |
The common factor is a code that handles money and sits unattended in public.
What scanners can do
- Feel the surface. An overlay sticker has a raised edge a printed original does not. Two seconds of touch defeats most of these attacks.
- Read the preview banner and check the domain before opening — the full checking routine takes under ten seconds.
- Check the payee name. For payment codes, the name your payment app displays must match the business printed on the sign. This catches substitution even when the sticker is physically perfect.
- Decode without opening when in doubt: our scanner shows the raw text in your browser without following it.
What venue owners can do
- Use tamper-evident labels that shred or reveal a VOID pattern when peeled, so an overlay requires visibly destroying the original.
- Print the destination domain in text under the code. A mismatch between the printed domain and the preview banner turns every customer into an auditor.
- Design the code into the artwork rather than applying it as a separate label — an overlay on a flush-printed panel is easier to spot than a sticker on a sticker.
- Audit on a schedule. Scan every public code weekly — or daily for payment codes — and keep a count of how many codes each site should have. A sticker sheet regenerated from the same data makes replacements cheap.
- Brief staff. The people wiping tables and emptying meters see the signage every day; tell them what an overlay looks like and who to report it to.
FAQ
How common are QR code sticker scams?
Common enough that the FBI and FTC have issued public warnings, and that some councils have removed QR codes from parking machines entirely. Parking, EV charging and restaurant payments are the repeatedly documented targets.
How can I tell if a QR code is a sticker over the original?
Feel it. An applied sticker has a raised edge; an original printed into the sign does not. Also compare the domain on your phone's preview banner with any domain printed on the sign itself.
What should a business do if it finds an overlay sticker?
Remove it, photograph it first, report it to the police and the payment provider, and check whether other codes on the premises were also replaced. Then move to tamper-evident labels and a regular audit.
Do tamper-evident labels really help?
Yes. They do not stop someone pasting over the top, but they make removal of the original destructive and obvious, and they give auditing staff a clear visual check — an intact security cut means an intact code.
Try it — free, no signup
Related
- Are QR codes safe? — Scanning a QR code is safe in itself — it decodes text and nothing else. The risk is entirely in what you do next. A code cannot install software, dial,…
- How to spot a malicious QR code — A malicious code looks identical to a real one, so judge context and destination instead. The physical tells, the digital tells, and how to decode safely.
- Tamper-evident QR labels — Destructible vinyl, void laminates and holographic overlays make QR sticker swaps visible for pennies per label — if you pair them with a physical audit routine.
- Parking QR code scams — how they work and how to avoid them — Fake QR stickers on parking meters lead to card-harvesting payment pages. What the FTC and FBI have warned about, and the rules for drivers and operators.