FRAUD CHECK — Squire It™
sharelivefraud.com/squire-it
LIVE FRAUD ALERT
LIVEFRAUD Check #68
FTC WARNS

Scammers are reported to be covering legitimate parking-meter QR codes with their own stickers that lead to fake payment sites built to take money and personal information.

MODERATE CONFIDENCEPublished 2026-09-04
S
Q
U
I
R
E
D
E
S
K
·
C
H
E
C
K
E
D
·
B
A
T
T
L
E
D
·
R
E
C
E
I
P
T
E
D
·
S

What we found

The FTC says people have reported scammers covering up legitimate QR codes on parking meters with a QR code of their own. According to that alert, scanning the substituted code can send you to a fake site designed to take your money, your personal information, or both. The same alert notes that many QR readers preview the link before opening it, so the address can be read for misspellings or switched letters first. Before you scan any code stuck to a meter, stop and pay through the parking operator's own app or a phone number you looked up yourself instead. The harvested alert does not say how many people were affected, where the tampered meters were found, when the reports were made, or how much money was taken. It also does not name any parking operator, city agency, or payment brand being impersonated, so we name none. LIVEFRAUD ALERTS is independent and not affiliated with the FTC or any parking or payment provider; this alert was written only from the public material listed above.
THE RULE
A tampered sticker on a parking meter can send a payment and personal details to a scammer in seconds, and the driver may not notice until the card statement arrives.

What we don’t know

The bench — who voted

4 INDEPENDENT AI MODELS REVIEWED THIS. ALL 4: MODERATE RISK.

The card names a count. Here are the seats behind it, with what each one said.

ANTHROPICclaude-opus-5 · MODERATE
The finding attributes a second substantive statement to the FTC alert — that 'many QR readers preview the link before opening it, so the address can be read for misspellings or switched letters first' — but the single evidence row says nothing about link previews or reader behaviour. That sentence is sourced to the alert in the text without any supporting row, so it is an unsupported attribution even though the core sticker-substitution claim is fully carried.
DISSENT, PRESERVEDThe URL-inspection advice carried in this alert is weak protection in practice and should not be presented as a primary defence: shortened links, redirect chains and lookalike domains routinely defeat visual inspection of a previewed address. The 'pay through the operator's own app or a number you looked up yourself' guidance is the sound part and should stand alone.
DISSENT, PRESERVEDI graded the pattern moderate rather than high because exposure per victim is typically bounded by a single card transaction, but readers should note that the same fake page can harvest identity details, so downstream harm can exceed the parking fee. I would not object to a colleague grading this high.
GOOGLEgemini-flash-latest · MODERATE
The finding asserts that 'The same alert notes that many QR readers preview the link before opening it, so the address can be read for misspellings or switched letters first,' but this detail is entirely absent from the provided evidence row.
GROQopenai/gpt-oss-120b · MODERATE
Finding adds that many QR readers preview links before opening, which is not supported by the cited FTC advisory.
OPENROUTERopenrouter/free · MODERATE
The finding restates the FTC advisory's core claim without embellishment. The disclosed limitations (no numbers, locations, dates, or named brands) are accurately reflected in the evidence row. The practical advice about checking URLs and using official apps flows reasonably from the reported threat.

Reviewed by 4 independent models: 1 found it carried by the evidence, 3 did not.

▼ Protocol & challenge record
Objection (medium): UNSOURCED ADVICE PRESENTED IN THE SAME VOICE AS THE FTC MATERIAL. The sentence 'Before you scan any code stuck to a meter, stop and pay through the parking operator's own app or a phone number you looked up yourself instead' carries no row_ids and appears nowhere in the harvested alert. The FTC's actual guidance is the opposite in emphasis: it says to preview and inspect the URL before clicking, not to avoid scanning meter codes altogether. A reader will not distinguish the paragraph's sourced sentences from the invented one, so the draft effectively attributes 'don't scan meter codes' to the FTC. Either drop it, or mark it explicitly as LIVEFRAUD's own suggestion, not the agency's.
Resolved: Not resolved in the draft. Fix required: delete the sentence or relabel it as an editorial suggestion distinct from the FTC's guidance, and restore the FTC's own 'inspect the URL preview' instruction as the primary sourced advice.
Objection (medium): THE UNDERLYING EVIDENCE IS UNVERIFIED CONSUMER COMPLAINTS, NOT CONFIRMED INCIDENTS. The source's own wording is 'People have reported' — i.e., complaint-intake anecdotes relayed in a consumer-education post. The FTC alert does not state that the agency confirmed a single tampered meter. The draft's confidence_reasons call this 'an official advisory,' which conflates the authority of the publisher with the verification status of the underlying facts. The alternative explanation — that some or all reports are misidentified (legitimate operator stickers, third-party payment-app decals, or codes reported secondhand from viral social posts) — is never raised. Prior public reporting on 2022-era parking QR scam waves showed that several widely circulated claims could not be substantiated in the cities named. Confidence should be low-to-moderate, and the alternative explanation should appear in unknowns or limitations.
Not resolved — preserved on the record.
Objection (medium): DATE CURRENCY / HARVEST INTEGRITY. The row carries pub 2026-09-03 and a /consumer-alerts/2026/09/ path. If that timestamp is ahead of or artificially near the run date, it is a harvest artifact and the whole row's provenance is suspect; if it is genuine, the draft still never tells the reader when the alert was published. The finding says the alert gives no dates for the reports but omits the one date it does have — the publication date — which is the only currency signal a reader can use. Add the publication date to the finding text and confirm the timestamp against the live page.
Resolved: Partially addressed only insofar as the draft admits the alert gives no incident dates. Publication date still needs to be printed and independently verified against consumer.ftc.gov.
Objection (high): GENERATION PIPELINE IS VISIBLY CONTAMINATED. callout_options includes 'ATTENTION: MULTI-FACTORS'; directive_options include 'Send this to any multi-factor you know,' 'Forward this to the multi-factors in your life,' and 'Send this to any wherever you know.' targeting_dropped names the groups 'feeding' and 'coins,' neither of which appears in the harvested text in any group sense. These are keyword-extraction failures ('multi-factor authentication' turned into a demographic; 'wherever' treated as a noun). The selected callout and null share_directive are fine, but the option pool shows the selector could have emitted incoherent or falsely-targeting output on a different draw. This is a defect to fix upstream, not a wording preference.
Resolved: Mitigated in this instance by the selection: 'ATTENTION: ANYONE WHO PAYS FOR PARKING' is coherent, share_directive is null, and the two nonsense targeting groups were correctly dropped with a §11 Rule 2 rationale. The defect is in the option pool, not the published output.
Objection (medium): PUBLIC-BENEFIT OMISSION. The source's most actionable content — what to do if you already scanned a bad code (do not interact with the site, change reused passwords immediately, review card and bank statements, report at ReportFraud.ftc.gov) — is entirely absent from the finding, while an unsourced prevention tip was added in its place. The draft drops sourced remediation and adds unsourced prevention. That trade should be reversed.
Not resolved — preserved on the record.
Objection (low): RISK LINE ADDS AN UNSOURCED DETECTION CLAIM. 'the driver may not notice until the card statement arrives' is an inference. The source mentions reviewing statements as a remediation step, but says nothing about typical detection lag. It is plausible, but it is the draft's assertion dressed as fact in the most quotable line of the item.
Resolved: Downgradeable if the risk line is trimmed to 'A tampered sticker on a parking meter can send a payment and personal details to a scammer in seconds' — everything up to that point is sourced.
Objection (low): PRESENT-TENSE ONGOING FRAMING. The claim reads 'Scammers are reported to be covering...' — continuous present, implying an active, current campaign. One dated advisory relaying past complaints does not establish current field activity. The unknowns list flags this ('Whether the stickers are still being found in the field'), but the headline claim does not carry the hedge to the reader.
Not resolved — preserved on the record.
Objection (low): PARAPHRASE SOFTENS THE SOURCE ON ONE POINT. The source says inspect the link 'before you click'; the draft says the address 'can be read for misspellings or switched letters first.' The source's condition is that many — not all — QR readers preview links, and the draft carries that 'many' correctly, but a reader could take 'the address can be read' as always available. Minor, but the conditional should stay attached.
Resolved: Effectively handled: the draft preserves 'many QR readers' rather than generalizing to all readers. No change needed beyond keeping the qualifier.
Preserved dissent
ON THE RECORDI do not accept 'moderate' confidence on this record. The evidence is one consumer-education page whose own operative phrase is 'People have reported.' That is complaint-intake anecdote republished by an authoritative body — the authority attaches to the publisher, not to the facts. With zero counts, zero locations, zero dates of incident, zero loss figures, no named operator, and no independent corroboration, low confidence is the honest label. The Desk is borrowing the FTC's credibility to cover an unverified factual core.
ON THE RECORDThe added sentence telling readers to pay through the operator's app or a looked-up phone number instead of scanning is not in the source and is not what the FTC advised. Adding unsourced instructions while dropping the source's own actionable remediation steps inverts the correct priority. I would strike the added advice outright rather than merely relabel it.
ON THE RECORDThe contaminated option pools ('ATTENTION: MULTI-FACTORS', 'Send this to any multi-factor you know', dropped groups named 'feeding' and 'coins') are not cosmetic. They show a term extractor that cannot tell a security control from a demographic. The safeguards caught it this time. I do not think that should be recorded as a pass, and I want the failure preserved on the record.
ON THE RECORDNo one in this draft asks the obvious counter-question: is it possible that some of these reported stickers are legitimate? Municipal and third-party parking operators do affix QR decals to meters. An alert built entirely on consumer reports, with no field verification, cannot distinguish a scam sticker from a real one that a driver distrusted. That alternative explanation belongs in the published limitations, not only in my dissent.

The sources

Official sourceSee a QR code parked somewhere? Don’t scan it…yet!2026-09-03
The FTC says people have reported scammers covering up legitimate QR codes on parking meters with a QR code of their own, sending scanners to fake sites built to take money or personal information.
Authority: official. Retrieved 2026-09-04.
Limitation: The advisory reports consumer complaints in general terms; it gives no number of reports, no locations, no dates, and no loss figures, and it names no impersonated operator or brand.
Open the original source →

Other checks

Every check we have published →

Share this receipt
sharelivefraud.com/check/Qo9avaY

Published under standing founder pass (A9) — every claim source-mapped by the machine.

▼ What the machine checked
  • ✓ Not a community submission.
  • ✓ No entity is named.
  • ✓ All 3 material sentence(s) map to FTC.
  • ✗ anthropic returned "overstated"; google returned "overstated"; groq returned "overstated"; openrouter raised 1 objection(s) — published on the receipt, not blocking (A9 amendment).
  • ✓ No audience band is set.

No human affirmed these. They were verified by the classifier described in Amendment A9, on 2026-09-05.

Something wrong here? Tell us and we'll correct it — corrections are published, not quietly edited.

Phishy? Send it → sharelivefraud.com/squire-it

Not affiliated with any government agency, credit bureau, bank, platform, or law-enforcement agency. Informational only — not legal or financial advice.

Naming a source is not an endorsement, and being named here is not an accusation against any company.

Powered by SquireIt™

Verify this receipt at squireit.com

Join Squire’s First Watch

Alerts before the feed. Credit when your summons becomes a receipt. A vote on what we check next. Founding names are permanent.

Get the next one

We publish a receipt for every alert, including the ones we decide not to run.

We will ask you to confirm before anything is sent. Your address is used for this and nothing else, and is never shared.