AI Scam SensePart of AI Sure Tech

QR code payment request

The QR Code on the Counter

A customer scans a QR code that appears to belong to a business, but the code sends them to an unfamiliar payment page.

Scenario story

The convenient option

Sofia stops at a small parking lot before a community event. A sign near the payment kiosk says she can scan a QR code to pay from her phone. The printed code looks official, and several people are waiting behind her.

The odd payment page

The code opens a payment page that asks for card details and a phone number. The page uses general words like "secure payment portal" but does not clearly show the parking company name. Sofia notices that a sticker with the QR code appears to be placed over an older sign.

The quick check

Instead of paying through the scanned link, Sofia checks the parking lot's posted website address and opens it manually. The official site uses a different payment page and warns customers not to use stickered QR codes. She pays through the official site and tells the event staff about the suspicious sticker.

The pattern

The scam did not require a complicated story. It relied on convenience, a line of people, and the assumption that a QR code in a public place must be safe.

Warning signs

  • A QR code appears as a sticker placed over another code or sign.
  • The payment page does not clearly identify the business.
  • The web address looks unrelated to the location or company.
  • The page asks for more information than needed.
  • There is pressure to act quickly because of a line, event, or deadline.
  • There is no alternative way to verify the payment destination.

Questions to ask

  • Does this QR code look original or added later?
  • Can I verify the payment page through the business's official website?
  • Does the page clearly identify the company I am paying?
  • Is the web address familiar and appropriate?
  • Can I pay through an official app, kiosk, or known website instead?

Safer next steps

  • Inspect public QR codes before scanning.
  • Open the business website manually when possible.
  • Use official apps or payment kiosks for parking, tickets, and bills.
  • Avoid entering card details on pages that do not identify the business clearly.
  • Report suspicious QR stickers to the business or event staff.

What not to do

  • Do not assume a public QR code is safe because it is on a sign.
  • Do not enter payment details if the destination page is vague.
  • Do not ignore signs that a sticker has been placed over another code.
  • Do not use QR links from unexpected emails or texts for sensitive payments.
  • Do not save card details on unfamiliar payment pages.