# Booby-trapped QR codes on parking meters and EV chargers: quishing hits the street

> Fraudulent stickers slapped onto parking meters, pay-and-display machines and electric vehicle charging points redirect drivers to fake payment sites, then to a booby-trapped text message. How to spot a tampered QR code and what to do next.

- Source: https://www.envoyer-sms-gratuit.com/en/blog/2026-09-27/arnaque-sms-quishing-qr-code-place-parking-borne-recharge
- Published: 2026-09-27 (27 September 2026)
- Author: L'équipe Envoyer SMS Gratuit
- Language: en
- Categories: Guide
- Tags: Cybersécurité, SMS, Guide, France 2026, Smartphone, Protection des données

---
"Parking payment — scan to pay in 30 seconds, no app required."

The words are printed in black on a clean, laminated white sticker, applied perfectly straight on the front of the parking meter. The QR code below it works flawlessly. The page that opens shows the name of your town, a map of the zone, a municipal logo and a payment form. Three minutes later, you even receive a confirmation text with a ticket number.

All of it is fake — except the charge on your card.

**Quishing** — a blend of *QR* and *phishing* — is the most discreet form of modern phishing. It needs no spoofed sender, no stolen database, no SMS Blaster hidden in a car boot. It needs a printer, a roll of adhesive and ten seconds in front of a piece of street furniture.

![Hands holding a Samsung smartphone with a dark screen outdoors, in front of blurred greenery](/images/blog/2026-09-27-arnaque-sms-quishing-qr-code-place-parking-borne-recharge/hero.jpg)

## Why the QR code became the perfect loophole

A web link can be read. You can spot the suspicious hyphen, the `.top` or `.xyz` extension, the subdomain playing dress-up (`ants-gouv.verif-doc.net`). That is in fact the first prevention rule repeated by **Cybermalveillance.gouv.fr**: hover, read, check the domain name before clicking.

A QR code, on the other hand, is **unreadable to a human being**. It is a graphic blank cheque: you only discover the destination once the link has opened, sometimes after two redirects. And smartphone ergonomics don't help — many devices display the URL in tiny, truncated form for a second and a half, in a notification bar nobody reads.

Three characteristics make it a tool of choice for fraudsters:

- **The trust attached to a physical medium.** A municipal sign, a charging point, a restaurant menu: street furniture enjoys a presumption of authenticity that no text message will ever be granted.
- **Invisibility to filters.** No mobile operator, no spam filter can analyse a sticker stuck on a street. Where a bulk text containing a malicious URL eventually gets blocked, the QR code travels through the one channel that cannot be intercepted: your eyes.
- **Built-in urgency.** You scan a parking QR code because you're in a hurry, double-parked, in the rain, with a meeting in eight minutes. Precisely the conditions in which vigilance collapses.

**ANSSI** and **Arcep** regularly point out that the technical sophistication of a scam matters less than the moment it strikes. Street quishing is the perfect demonstration of that principle.

## The four settings most used in France

### 1. Parking meters and pay-and-display machines

This is the most thoroughly documented case since 2024, with reports in dozens of French towns — Charleville-Mézières, Rouen, Lyon, Toulouse, Nice, and several seaside resorts in high season. The modus operandi is always the same: a sticker is placed on or next to the meter's screen, often covering up a genuine official QR code.

The fake site reproduces the visual identity of legitimate parking apps. It asks for the number plate, the duration, then **full card details**: 16-digit number, expiry date, security code. Some variants go further and offer a "€1 monthly subscription" that in fact conceals a recurring charge.

### 2. Electric vehicle charging points

The setting is ideal: a charging point is a technical piece of equipment, often poorly signposted, with several competing operators, multiple apps and pricing nobody can decipher. The driver doesn't always know **who** they are supposed to be paying. A fraudulent QR code stuck on the charger's column, labelled "pay without a card", finds its target immediately — especially on long journeys, when you want to get back on the road fast.

### 3. Parking tickets and delivery notices

Fake "unpaid parking notices" slipped under windscreen wipers, printed on yellow or green paper, with a QR code to settle up. The same logic applies to fake courier delivery notices left on a letterbox: no need to send a parcel text any more, just leave a slip of paper.

### 4. Terraces, posters and shop windows

A menu QR code covered over, a hijacked concert or car-boot-sale poster, a "free Wi-Fi" sticker in a waiting room. Here the goal is not always immediate payment: it is often the **harvesting of phone numbers and email addresses**, resold or reused for a targeted smishing campaign a few weeks later.

![Close-up of a person's hand holding a black smartphone above a white table](/images/blog/2026-09-27-arnaque-sms-quishing-qr-code-place-parking-borne-recharge/body-1.jpg)

## The text message: the scam's second storey

This is the point most prevention articles forget: **the QR code is almost never the end of the story**. It serves to capture a piece of data, and that data is then used to write a perfectly credible text message.

The full scenario looks like this:

| Step | What you experience | What is actually happening |
|---|---|---|
| 1 | You scan the QR code on the parking meter | You land on a domain created the week before |
| 2 | You enter your plate, phone number and card | The data is sent unencrypted to a third-party server |
| 3 | You receive a text: "ticket validated no. 48219" | The text is sent by the fraudsters to kill any doubt |
| 4 | 3 to 20 days later: "payment failed, please settle" | A second charge, or theft of your 3-D Secure code |
| 5 | A call "from your bank" asks you to confirm | Fake adviser fraud, with accurate data in hand |

The confirmation text plays an essential psychological role: it turns a dubious operation into a successful transaction. You put your phone away reassured, you don't watch your account, and you won't connect the odd charge on the 14th of the month with that car park on the 2nd.

That same text is also what makes the fraud so hard to trace: by the time the victim understands, they have deleted the message, cleared their browser history and forgotten the name of the street.

> One simple rule to remember: a QR code never confirms anything to you. Only an official app that **you** installed, or a site that **you** typed in yourself, can do that.

## How to spot a tampered QR code in ten seconds

The good news is that this fraud is physical — and therefore detectable with the naked eye. Before scanning anything in a public space:

- **Touch the code.** A sticker placed on top can be felt with a fingertip: a raised edge, a corner peeling off, an air bubble. Official QR codes are screen-printed, engraved or printed directly onto the panel, under hard plastic.
- **Look at the alignment and typography.** A font that differs from the rest of the sign, a missing accent, a pixelated logo, a "City of…" line with no official crest: all of these are red flags.
- **Look for duplicates.** Two QR codes on the same piece of equipment, one of them clearly added in a hurry, is the most common scenario.
- **Check the domain before opening it.** French public bodies and local authorities use identifiable `.gouv.fr` or `.fr` domains. A link ending in `.top`, `.icu`, `.shop`, `.online`, a link shortener (`bit.ly`, `cutt.ly`), or a long domain stuffed with hyphens: close it.
- **Be wary of the security code.** No public parking service will ever ask for your 3-digit code on a page reached via QR code without going through 3-D Secure.

One very ordinary accessory helps more than you'd think: a [car phone mount](https://www.amazon.co.uk/s?k=support+t%C3%A9l%C3%A9phone+voiture+magn%C3%A9tique&tag=ds0608-21), which keeps your smartphone at eye level so you can read the URL calmly instead of scanning at arm's length with the door open and the engine running.

### The one habit that solves 90% of the problem

Pay for your parking some other way. France's official parking apps can be downloaded from the app stores, and once installed, **they no longer require any QR code at all**. Paying by card directly on the meter, where that's possible, also remains unbeatable: no web page, no form, no phone number handed over.

For charging points, your mobility operator's card or RFID fob solves the problem at the root. A compatible charging card reader or a [multi-network charging fob](https://www.amazon.co.uk/s?k=badge+recharge+voiture+%C3%A9lectrique+multi+r%C3%A9seaux&tag=ds0608-21) means you never have to scan anything on an unfamiliar charger.

![Hand holding a smartphone with a dark screen outdoors, in front of green leaves](/images/blog/2026-09-27-arnaque-sms-quishing-qr-code-place-parking-borne-recharge/body-2.jpg)

## Getting your phone ready before you need it

A handful of settings, configured once, change everything on the day you scan a bad code.

**Turn off automatic link opening.** On both iPhone and Android, the camera can be set to display the URL and wait for confirmation rather than opening the browser straight away. It is the only genuinely effective safeguard, and it's free.

**Switch on your bank's payment notifications.** An alert for every debit, even a €1 one, cuts detection time from three weeks to three minutes. All French banks offer this service free of charge in their app.

**Use a [virtual or capped card](https://www.amazon.co.uk/s?k=portefeuille+RFID+protection+carte+bancaire&tag=ds0608-21) for street payments.** Most banks and neobanks let you generate a single-use number. A fraudster who harvests an already-expired number has harvested nothing at all.

**Keep your phone charged.** It sounds trivial, but a great many bad decisions in a car park are taken under pressure, with 6% battery left and a desperate urge to be done with it. A [compact power bank](https://www.amazon.co.uk/s?k=batterie+externe+compacte+USB-C&tag=ds0608-21) in the glovebox removes part of that pressure.

**Make a note of what you scanned.** If you have any doubt, take an immediate photo of the equipment and the QR code. That's the piece of evidence that will let the local council have the sticker removed and your bank process the dispute.

## You scanned and paid: what to do now

Time matters enormously. In order:

1. **Block your card immediately** through your bank (emergency number available 24/7) or, failing that, via the interbank service on **0 892 705 705**.
2. **Request a refund.** Article L133-18 of the French Monetary and Financial Code requires the bank to refund an unauthorised payment reported within the deadline, unless gross negligence on your part is proven. Make the request **in writing**.
3. **Report the text you received to 33700**, the official platform for reporting fraudulent texts and calls, run by the French mobile operators.
4. **File a complaint** at a police station, a gendarmerie, or via the **THESEE** platform on service-public.fr for online fraud.
5. **Report the fraudulent site** to **Phishing Initiative**, and the physical QR code to the town hall or the charging point operator: that's what gets the sticker removed.
6. **Watch your accounts for three months.** Stolen data is often resold and reused several weeks later, notably in the form of fake calls "from your adviser".

And if you need to warn a friend or colleague who parks on the same street quickly, a short message is enough: "Booby-trapped QR code on the meter on X street, pay by card directly on the machine." That is exactly the kind of instant alert that an online text-sending service, with nothing to install, is useful for.

## What this fraud tells us about the rest

Street quishing is not a very sophisticated scam. It is a **well-placed** one. It illustrates a shift found in almost every recent campaign: fraudsters are no longer trying to fool your judgement, they are looking for the moment when you're not exercising any.

Standing in front of a parking meter, in the rain, with the thought of a possible fine going round your head, nobody analyses a domain name. That is why the only lasting defence is not suspicion — which is exhausting and unworkable — but **habit**: always paying through the same channel, the one you chose calmly, on a day when you weren't in a rush.

A [notebook kept in the car](https://www.amazon.co.uk/s?k=carnet+de+notes+format+poche&tag=ds0608-21) with the useful numbers (card blocking, roadside assistance, 33700) costs two euros and saves a decisive quarter of an hour. Prevention, whether against fraudulent texts or booby-trapped QR codes, almost always plays out before the incident.

{/* image-sources: https://images.pexels.com/photos/7439/pexels-photo.jpg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 https://images.pexels.com/photos/12829/pexels-photo-12829.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 https://images.pexels.com/photos/3639946/pexels-photo-3639946.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 */}
