Fake invoices and poisoned QR codes
A $499 'renewal' you never bought and a parking meter sticker that isn't the city's. Two boring scams doing billions in damage.
Not every scam needs a sob story or a romance. Two of the most effective rely on pure administrative reflex: the fake invoice, which counts on you paying (or panicking about) a bill you don't remember, and the malicious QR code, which counts on you scanning without looking. Both work because they imitate the most boring transactions in your life — and boredom is where your guard is lowest.
The fake invoice playbook
You get an email: 'Your Geek Squad/Norton/McAfee subscription has renewed for $499.99. To dispute this charge, call...' There is no subscription and no charge — yet. The invoice IS the bait. Call the number and a friendly 'refund agent' walks you into remote-access software, a fake over-refund ('we accidentally sent you $5,000 — please return the difference'), and gift cards or wire transfers to fix it. The scam isn't the invoice; it's the phone call it provokes. Small businesses get a parallel version: real-looking invoices for directory listings, domain renewals, or office supplies nobody ordered, priced just low enough for accounts payable to wave through.
QR codes: phishing with a shortcut
A QR code is just a URL you can't read. That's the entire vulnerability. Scammers exploit it physically — stickers pasted over real codes on parking meters, restaurant tables, EV chargers, and utility notices, routing you to a perfect clone of the payment site — and digitally, in emails ('scan to keep your account active') because QR codes sail past spam filters that would catch a suspicious link. You scan, land on a convincing page, and type in your card number or login like you've done a hundred legitimate times.
Why the refund theater works
The over-refund trick deserves a closer look because it defeats people who would never fall for a simple payment demand. With remote access to your screen, the scammer edits the HTML of your banking page locally — your browser really does display a balance $5,000 higher, on your real bank's real website. Nothing has actually moved; it's a cosmetic edit that vanishes on refresh, but the victim has no reason to refresh. From that moment the psychology flips: you appear to be holding THEIR money, they're crying about losing their job over the typo, and returning it feels like simple decency. Every subsequent payment is framed as you correcting an error rather than being robbed. The defense is structural, not situational: no legitimate refund process on earth requires remote access to your computer, and no real company's error is fixed with gift cards.
Defenses that take ten seconds
- Never call a phone number printed on an invoice or email you didn't expect. Look up the company's number independently — or better, check your card and bank statements first: no charge means no problem, delete and move on.
- Never let anyone you didn't hire install remote-access software (AnyDesk, TeamViewer, and similar). No real refund process requires seeing your screen.
- No legitimate business collects payment or 'refund corrections' in gift cards. Ever. That sentence alone defeats most of this article.
- Before acting on a scanned QR code, read the URL your phone previews. Misspellings, weird domains, or link shorteners on a payment page mean walk away.
- For small businesses: require purchase-order matching before paying any invoice, and verify new 'vendors' by independently found phone numbers.
If you already engaged
- If remote access happened: disconnect the computer from the internet, run a full malware scan, change banking passwords from a DIFFERENT device, and consider a professional cleanup before using it for finances again.
- If you paid: call your bank or card issuer immediately to dispute or attempt recall; gift card payments — call the card issuer (Apple, Amazon, etc.) with the card numbers; sometimes unspent balances can be frozen.
- Freeze your credit at all three bureaus if you shared personal information.
- Report at reportfraud.ftc.gov and ic3.gov — reports build the cases that shut these operations down.
- Expect follow-up scams: 'fund recovery services' that contact victims are almost always the same scammers coming back for dessert.
The bottom line
Fake invoices monetize your panic about a charge that doesn't exist; malicious QR codes monetize your trust in a square of pixels you can't read. The counters are equally boring: check your actual statement before reacting to any bill, never call numbers the 'bill' provides, read URLs before you pay, and treat every gift card request as a confession. Boring beats boring.
Check your understanding
1 of 3Not quite — try again.
Get smarter about money every week
One email, no spam — practical guides and Worth updates. Unsubscribe anytime.
Put this into practice
Worth tracks your accounts, budgets, and goals — so the concepts in this article aren't just theory.
Start free trial