# Quishing: When a Simple QR Code Stuck on a Parking Meter Replaces the Booby-Trapped Text Message

> Scammers are ditching the clickable link in favour of the QR code: stickers on parking meters, EV charging points, fake letters. Understanding quishing and adopting the right reflexes before you scan.

- Source: https://www.envoyer-sms-gratuit.com/en/blog/2026-08-29/arnaque-sms-qr-code-quishing-affiches-parkings
- Published: 2026-08-29 (29 August 2026)
- Author: L'équipe Envoyer SMS Gratuit
- Language: en
- Categories: Guide
- Tags: Cybersécurité, Smartphone, Protection des données, Guide, France 2026, Seniors

---
You park in the town centre. The parking meter displays a clean, neatly centred sticker, with a credible municipal logo and that now-familiar line: "Pay for your parking without cash — scan here". You take out your phone, you scan, a form opens, you enter your number plate and your bank card. Thirty seconds, no app to install. It's exactly the action that cities have been encouraging you to take for years.

Except that the sticker was pasted over the real one the night before.

No link displayed, no spelling mistakes, no alarmist tone. Quishing — a blend of *QR code* and *phishing* — has nothing in common with the threatening text message we've learned to resist. It doesn't put you under pressure: it does you a favour. And a reader who feels helped doesn't feel in danger.

![Close-up of a woman's face as she holds a black smartphone to her ear](/images/blog/2026-08-29-arnaque-sms-qr-code-quishing-affiches-parkings/hero.jpg)

## Why the QR code has become vigilance's blind spot

For the past ten years, all public education against phishing has rested on a single skill: **reading an address**. Spotting the extra hyphen, the `.xyz` instead of the `.fr`, the bank's name followed by a parasitic word. Cybermalveillance.gouv.fr, ANSSI and banking services have hammered home the same advice for years: check the link before you click.

The QR code wipes out that skill in one stroke. A square of black pixels says nothing. You can't hover over it, you can't read it, you can't compare it. You scan it — which means you trust it in advance.

Three factors make the situation worse:

- **Post-2020 normalisation.** Restaurant menus, ticketing systems, charging points, furniture instructions, product labels: scanning has become a reflex, without the slightest suspicion attached to it.
- **The break in context.** A fraudulent text message arrives in a stream (your inbox) where other messages serve as reference points. The QR code, on the other hand, is physical: it borrows the credibility of whatever it is stuck on. A sticker on official street furniture *looks* official.
- **The screen switch.** You often scan a code displayed outdoors with a phone held at arm's length, in bright light, in a hurry. That's the worst possible context for carefully reading a truncated address bar.

Classic smishing hasn't disappeared — the waves of fake banking or administrative texts reported in recent months by the regional press prove it. But the QR code offers scammers something text messages no longer give them: **the complete absence of any filter**. No mobile operator can analyse a sticker.

## Where you actually find them in France

The reports passed on to consumer associations and local authorities paint a fairly consistent picture.

| Hijacked medium | Stated pretext | What the scammer collects |
|---|---|---|
| Parking meter, underground car park | Parking payment | Bank card, number plate, identity |
| Electric charging point | Starting the charging session | Bank card, account creation |
| Shared bikes and scooters | Quickly unlocking the vehicle | Banking details |
| Car-sharing poster / small ad | Contacting the seller | Platform login credentials |
| "Official" paper letter | Sorting out a file, a refund | Full personal data |
| Parcel received with a "gift" flyer | A review in exchange for a voucher | Retail account, hidden subscription |
| Café terrace, restaurant table | Menu or paying the bill | Bank card |

Two variants deserve particular attention.

**The fake official letter.** Receiving a paper letter still feels, for many people, like a mark of seriousness. Campaigns imitating public bodies — health insurance, pension funds, the tax administration — are now replacing the web address with a QR code, precisely because a QR code is easier to forge than an institutional website is to verify. It's worth recalling the principle set out by Ameli: the French health insurance service never asks for banking details by message or unsolicited letter in order to "release" a refund.

**"Brushing" with a flyer.** You receive a small parcel you never ordered, along with a card offering a gift in exchange for a review. The QR code leads to a form that collects far more than necessary.

## What really happens after the scan

Contrary to a stubborn misconception, scanning a QR code does not "hack" a phone. The code contains only one piece of data: most often a web address, sometimes a phone number to call, a Wi-Fi network, a piece of text, or a payment instruction. The danger comes from **what you do next**.

Three scenarios dominate:

1. **The harvesting page.** A very faithful copy of a payment site. You enter your card details, and they go straight to the scammer — or, more insidiously, they're used to validate a recurring subscription of a few euros a week, an amount deliberately kept low to slip beneath your attention threshold on your bank statement.
2. **The triggered call.** The code encodes a premium-rate number; the device offers to dial it, and a second's inattention is enough. It's the wangiri mechanism transposed onto a physical medium.
3. **Installation outside the official store.** A page invites you to install a "parking app" via a directly downloaded file. On Android, accepting an installation from an unknown source opens the door to software capable of intercepting your text messages — and therefore your banking verification codes.

The third case is the most serious, because it turns a one-off theft into lasting access. It is also the only one that requires several explicit confirmations from you: that's just as many moments when you can still say no.

> A simple rule to remember: a legitimate QR code never asks you to install anything outside the App Store or the Play Store. Ever.

## The six habits that are enough to keep you safe

### 1. Touch before you scan

The most effective action costs nothing: run your finger over the QR code. A sticker pasted over the top can be felt — a slightly lifted edge, added thickness, a different shine from the surface, a misaligned angle, a pixelated logo. On a parking meter or a charging point, also check whether the code partly covers some information (serial number, legal notice). An official operator never masks its own markings.

### 2. Read the address before opening it

All recent phones show a preview of the URL before opening the page. Take the two seconds needed. What matters is the word **just before the first `/`**: that's the real domain. `paiement.ville-de-lyon.fr/parking` is plausible; `ville-de-lyon.paiement-securise-fr.co/parking` is not at all, even though it starts off convincingly.

If you struggle to read the screen outdoors, in full sunlight or with varifocal glasses, that isn't a matter of comfort: it's a risk factor. An [anti-glare screen protector for smartphones](https://www.amazon.co.uk/s?k=film+antireflet+mat+smartphone+protection+ecran&tag=ds0608-21) markedly improves readability in bright light and, indirectly, your ability to check an address before clicking.

### 3. Refuse the shortcut when an alternative exists

There is almost always a route that can't be booby-trapped:

- for parking, the city's official app installed from the app store, or quite simply coins and your card inserted into the meter;
- for a public body, typing the known address manually (ameli.fr, impots.gouv.fr, agirc-arrco.fr) into your browser;
- for a bank, the app you already have installed — never a link you received.

The principle is always the same: **never follow a path that someone has held out to you; take the one you already know.**

### 4. Ring-fence your payments

Many QR code frauds yield nothing because the card used is empty. That's the role of the single-use virtual cards offered by most French banks, or of a [rechargeable prepaid card](https://www.amazon.co.uk/s?k=carte+prepayee+rechargeable&tag=ds0608-21) set aside for on-the-go payments — parking, charging, purchases while out and about. The ceiling mechanically limits the damage, and a hidden subscription can't debit money that isn't there.

### 5. Lock down your device in advance

Two settings, once and for all:

- on Android, leave the permission to install apps from unknown sources switched off (Settings → Apps → Special access);
- on both iPhone and Android, turn on fraudulent site protection in your browser settings.

For anyone who handles their phone outdoors, often with their hands full, a [phone case with a built-in card holder](https://www.amazon.co.uk/s?k=coque+smartphone+porte+carte+integre&tag=ds0608-21) avoids having to pull out phone and wallet at the same time on the pavement — the typical setting in which people scan quickly and carelessly.

### 6. Report it, every time

A fraudulent sticker stays in place as long as no one removes it. Three useful steps:

- **peel off the fake QR code** if it's clearly an addition, or photograph it;
- **alert the operator**: the town hall, the parking service, the charging point operator, the shop manager;
- **report the page** on the Cybermalveillance.gouv.fr platform, and any associated text message to **33700** when a message preceded or followed the scan.

If a payment has gone through, block your card immediately, then file a complaint. The European payment services directive (PSD2), transposed into French law, governs the refund of unauthorised transactions: your bank must refund an operation you did not authorise, unless it can demonstrate gross negligence on your part. Hence the importance of keeping the evidence — a photo of the sticker, a screenshot of the page, the time and date.

## The particular case of older people and vulnerable groups

Quishing hits especially hard among people who took up smartphones late. They have often internalised a simplified instruction — "don't click on links" — without the QR code fitting into that mental category. For many, scanning isn't clicking.

A few support measures that work:

- rephrase the instruction in terms of destination rather than medium: "you never pay from a code displayed outdoors, you pay from an app you installed yourself";
- install together the two or three genuinely useful apps (parking, transport, banking) so there's no need to scan anything at all;
- increase the font size and contrast to make the address preview legible;
- for a parent who is very reluctant about technology, embrace minimal usage: a [big-button phone for seniors](https://www.amazon.co.uk/s?k=telephone+portable+senior+grosses+touches&tag=ds0608-21) with no browser closes the door on all of these attacks, which remains a perfectly legitimate option.

An [accessible book on cybersecurity](https://www.amazon.co.uk/s?k=livre+cybersecurite+grand+public+debutant&tag=ds0608-21), left on the coffee table, often has more effect than a ten-minute verbal explanation: reading at one's own pace avoids the feeling of being patronised that blocks so many family conversations on the subject.

## What sets a legitimate QR code apart from a trap

| Signal | Legitimate | Suspicious |
|---|---|---|
| Medium | Printed into the surface, engraved, built into the fixture | Sticker added on top, layered over |
| Domain displayed | Organisation's name before the first `/` | Organisation's name as a subdomain or with a hyphen |
| Request | Amount, number plate, session | Card + ID document + tax number |
| Installation | Redirect to the App Store / Play Store | Direct download of a file |
| Urgency | None | Countdown, "offer valid for 15 minutes" |
| Alternative | Conventional payment available | The QR code is presented as the only option |

The last criterion is probably the most revealing. An institution never removes all the other channels. When a sign tells you scanning is the only possible route, it's because someone wants to stop you checking elsewhere.

## The heart of the problem isn't technical

Quishing relies on no computing feat whatsoever. It relies on a collective habit built up over just a few years: trusting a physical medium because it's there, visible, in public space. We've learned to be wary of what arrives on our screen unsolicited — texts, emails, calls — but not of what's stuck on a terminal in the street.

The good news is that the defence takes less effort than for a fraudulent text message. A link received by message has to be analysed mentally in a second. A QR code, on the other hand, can be touched with your finger. The most reliable test against this 2026 scam is also the oldest in the world: using your hand to check whether something has been stuck over something else.

And if you need to warn someone close to you quickly about a scam spotted in your neighbourhood, a short, clear message remains the most effective tool — far more than a long voice note or an illegible screenshot. One sentence, one place, one piece of advice. That's often all that was missing to prevent one scan too many.

{/* image-sources: https://images.pexels.com/photos/6964158/pexels-photo-6964158.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 */}
