People & Platforms

QR Code Scam Investigator

A QR code is a link you cannot read before opening — which makes it the perfect wrapper for phishing. Fake codes now appear on parking meters, restaurant tables, packages, and in texts about tolls and deliveries. Describe where you found the code and what happened after scanning, and the AI will tell you whether it matches known quishing patterns — and what to do if it does.

scamanot.com — qr code investigator

Works with physical codes and digital ones — parking meters, menus, packages, texts, emails, and flyers.

🔒 Content you paste is never stored, logged, or shared. It is processed server-side and discarded immediately after your result is returned. If a scanned page asked for a login or payment: treat it as hostile, close it, and change any password you entered from a clean browser. This tool informs your decision — it does not guarantee outcomes.

Content never stored
AI runs server-side only
No account required
Cloudflare protected

How quishing actually works.

The QR code isn't the scam — it's the delivery vehicle. These are the patterns the AI checks your encounter against.

The Sticker Overlay

A fraudulent code stuck over the real one on parking meters, EV chargers, menus, and posters. Raised edges or misalignment around a code are worth a look before every scan.

The Unexpected Text

Unpaid tolls, package redelivery, account alerts — arriving with a QR code or link you never asked for. Unsolicited codes carry the same risk as unsolicited links: total.

The Instant Login Page

Scanning leads straight to a "sign in" for your bank, Microsoft, or Amazon. Real codes on legitimate materials rarely demand credentials first — phishing pages always do.

The Payment Redirect

Parking or charging codes leading to unfamiliar payment processors instead of the city's or vendor's official app. Your card details are the entire objective.

The Disguised URL

Shorteners and lookalike domains (rnicrosoft-secure.com) hide the destination. Most phone cameras preview the URL before opening — the habit of reading it is the defense.

The Package You Didn't Order

A mystery delivery with "scan to see who sent you a gift." Brushing-adjacent quishing that trades curiosity for credentials or card numbers.

Three scans, checked.

The same trick in a parking lot, a text thread, and an inbox.

3
Low
The Meter Sticker

A parking meter's QR code leads to "quickpay-parking.net" asking for your plate and card. The city's parking app is mentioned nowhere, and the sticker sits slightly crooked over another code.

Physical overlay quishing — cheap stickers, printed by the hundred, harvesting cards all day in busy lots. Cities take payment through their named apps and official sites; an unfamiliar processor at a meter is a scam by default.

5
Caution
The Toll Text

"FasTrak: Our records show an unpaid toll of $6.49. To avoid a $50 late fee, settle today," with a QR code — and the linked page is a convincing DMV-styled form requesting card and license details.

Unpaid-toll smishing is one of the highest-volume scams in the country, and the QR variant dodges link-scanning filters. Tolling agencies bill by mail and through accounts you log into directly — never by QR-coded text. The $50 late fee is the pressure; the form is the harvest.

8
High Risk
The Office MFA Reset

A work email from "IT Security," correctly branded, says your multi-factor authentication expires today — "scan with your phone to re-enroll." The code opens a flawless Microsoft 365 login that accepts your password and then asks you to approve an MFA prompt.

Enterprise quishing: the QR moves the attack from your protected work laptop to your unfiltered phone, and approving that prompt hands the attacker a live session. Anything time-boxed about MFA arriving by email deserves a call to real IT first. If you approved a prompt — report it to IT immediately; minutes matter.

About QR code scams.

For modern, updated phones — effectively no. Scanning only reads the encoded URL; the danger begins with what you do next: opening the link, entering credentials, downloading a file, or approving a prompt. This is genuinely good news, because it means the defense is entirely in your hands. Scanning a suspicious code and then closing the preview costs you nothing. The scam needs your cooperation on the page it leads to — deny it that, and the code is just ink.
Your phone already shows you. Both iPhone and Android camera apps display the destination URL in a small banner before you tap through — the entire skill is pausing to read it. Look for the actual domain (the part before the first single slash): city services should be on .gov or the city's known domain, companies on their exact real domain. Shortened links (bit.ly and similar), IP addresses, and near-miss spellings are all reasons to close the preview. For payments and logins, skip codes entirely and type the official address yourself.
Fraudsters print QR code stickers pointing at fake payment sites and stick them on parking meters, pay stations, and EV chargers — often directly over the legitimate code. Drivers in a hurry scan, land on a professional-looking payment page, and enter card details that go straight to the scammer, sometimes alongside a fake "parking session" confirmation that leaves them ticketed too. Before scanning at any meter: check whether the code is a sticker sitting on top of another, and prefer the city's official parking app or the phone number printed on the meter itself.
Almost certainly not. Unpaid-toll smishing has become one of the highest-volume text scams in the US, and tolling agencies — E-ZPass, FasTrak, SunPass and the rest — do not send payment demands with QR codes or links by text. Real toll billing arrives by mail or through the account you already hold, accessed by typing the agency's site yourself. Delete the text, and if you're genuinely unsure whether you owe a toll, look up the agency's official site independently and check there. The late-fee countdown in the message is the pressure tactic, not a fact.
No. Per our Security Policy Framework §3.1, nothing you submit is stored in our database. Your description is processed server-side, analyzed, and discarded immediately after your result is returned. We never retain, sell, or train on your submissions.
Respond to what you entered. A password: change it immediately from a different, trusted browser, change it anywhere it was reused, and turn on two-factor authentication. Card details: call the number on the back of the card, report it, and request a replacement — issuers handle this daily and dispute fraudulent charges. Work credentials: report to your IT team right away, especially if you approved an MFA prompt, because minutes determine whether a session gets hijacked. Then report the scam at reportfraud.ftc.gov — and if it was a physical sticker, tell the business or city so it comes down before the next person scans.

Straight Answers

The questions people ask most — answered directly.

Can scanning a QR code by itself hack my phone?

For modern, updated phones — effectively no. Scanning only reads the encoded URL; the danger begins with what you do next: opening the link, entering credentials, downloading a file, or approving a prompt. This is genuinely good news, because it means the defense is entirely in your hands. Scanning a suspicious code and then closing the preview costs you nothing. The scam needs your cooperation on the page it leads to — deny it that, and the code is just ink.

How can I tell where a QR code leads before opening it?

Your phone already shows you. Both iPhone and Android camera apps display the destination URL in a small banner before you tap through — the entire skill is pausing to read it. Look for the actual domain (the part before the first single slash): city services should be on .gov or the city's known domain, companies on their exact real domain. Shortened links (bit.ly and similar), IP addresses, and near-miss spellings are all reasons to close the preview. For payments and logins, skip codes entirely and type the official address yourself.

What is the parking meter QR sticker scam?

Fraudsters print QR code stickers pointing at fake payment sites and stick them on parking meters, pay stations, and EV chargers — often directly over the legitimate code. Drivers in a hurry scan, land on a professional-looking payment page, and enter card details that go straight to the scammer, sometimes alongside a fake "parking session" confirmation that leaves them ticketed too. Before scanning at any meter: check whether the code is a sticker sitting on top of another, and prefer the city's official parking app or the phone number printed on the meter itself.

I got a text about unpaid tolls with a QR code. Is it real?

Almost certainly not. Unpaid-toll smishing has become one of the highest-volume text scams in the US, and tolling agencies — E-ZPass, FasTrak, SunPass and the rest — do not send payment demands with QR codes or links by text. Real toll billing arrives by mail or through the account you already hold, accessed by typing the agency's site yourself. Delete the text, and if you're genuinely unsure whether you owe a toll, look up the agency's official site independently and check there. The late-fee countdown in the message is the pressure tactic, not a fact.

Why Scamanot Exists

Built by someone who's been there.

Scamanot was founded by Robert Scott Singleton — 63 years old, online since 1992, and a scam victim more times than he cares to count. Car dealers. Email schemes. Fake online sellers. He watched fraud grow from an obscure curiosity into a billion-dollar catastrophe targeting everyday people.

"When it happens, you don't say anything. You just go quiet. Forget about it. Move on. That's what I did for decades. That's what most people do. And that silence — that's exactly what scammers are counting on."

So he built something about it. Every tool on Scamanot is AI-powered, free to use, and built on one principle: nobody should have to just go quiet and move on. Your searches are never stored. The AI runs server-side only. We find the truth. We never expose yours.

Founder

Robert Scott Singleton

Founded

2026

Online since

1992

Data stored

Zero. None. Ever.