Scams & FraudBeginner5 min read

Fake invoices and poisoned QR codes

A $499 'renewal' you never bought and a parking meter sticker that isn't the city's. Two boring scams doing billions in damage.

Not every scam needs a sob story or a romance. Two of the most effective rely on pure administrative reflex: the fake invoice, which counts on you paying (or panicking about) a bill you don't remember, and the malicious QR code, which counts on you scanning without looking. Both work because they imitate the most boring transactions in your life — and boredom is where your guard is lowest.

$1.4B+
Yearly reported losses where the fake-invoice call is the entry point
Tech/refund support fraud estimates, FBI and FTC data
$500
Typical fake 'renewal' invoice amount range
Priced to alarm but stay believable
30 sec
Time to check your actual card statement
The check that ends the scam before it starts

The fake invoice playbook

You get an email: 'Your Geek Squad/Norton/McAfee subscription has renewed for $499.99. To dispute this charge, call...' There is no subscription and no charge — yet. The invoice IS the bait. Call the number and a friendly 'refund agent' walks you into remote-access software, a fake over-refund ('we accidentally sent you $5,000 — please return the difference'), and gift cards or wire transfers to fix it. The scam isn't the invoice; it's the phone call it provokes. Small businesses get a parallel version: real-looking invoices for directory listings, domain renewals, or office supplies nobody ordered, priced just low enough for accounts payable to wave through.

How a $0 invoice becomes a $12,000 loss
A retiree receives a $349 'antivirus renewal' invoice and calls to cancel. The 'agent' takes remote control of her computer to 'process the refund,' fakes her bank screen to show a $3,490 deposit — 'oops, we typed an extra digit' — and tearfully asks her to return $3,141 in gift cards to save his job. Then the follow-up calls start: a fake fraud department, a fake bank investigator, each extracting more. Total taken over three weeks: $12,000. The original invoice cost the scammer nothing to send and charged her for nothing at all — every dollar came from the phone call.

QR codes: phishing with a shortcut

A QR code is just a URL you can't read. That's the entire vulnerability. Scammers exploit it physically — stickers pasted over real codes on parking meters, restaurant tables, EV chargers, and utility notices, routing you to a perfect clone of the payment site — and digitally, in emails ('scan to keep your account active') because QR codes sail past spam filters that would catch a suspicious link. You scan, land on a convincing page, and type in your card number or login like you've done a hundred legitimate times.

Parking meters are the hot zone
Cities across the US have reported waves of fraudulent QR stickers on meters and pay stations — many cities don't use QR codes for parking payment at all. Before scanning any code in public, look: is it a sticker on top of another code? Does the URL preview match the organization (city .gov, the restaurant's actual domain)? When in doubt, type the address yourself or use the official app.

Why the refund theater works

The over-refund trick deserves a closer look because it defeats people who would never fall for a simple payment demand. With remote access to your screen, the scammer edits the HTML of your banking page locally — your browser really does display a balance $5,000 higher, on your real bank's real website. Nothing has actually moved; it's a cosmetic edit that vanishes on refresh, but the victim has no reason to refresh. From that moment the psychology flips: you appear to be holding THEIR money, they're crying about losing their job over the typo, and returning it feels like simple decency. Every subsequent payment is framed as you correcting an error rather than being robbed. The defense is structural, not situational: no legitimate refund process on earth requires remote access to your computer, and no real company's error is fixed with gift cards.

Defenses that take ten seconds

  • Never call a phone number printed on an invoice or email you didn't expect. Look up the company's number independently — or better, check your card and bank statements first: no charge means no problem, delete and move on.
  • Never let anyone you didn't hire install remote-access software (AnyDesk, TeamViewer, and similar). No real refund process requires seeing your screen.
  • No legitimate business collects payment or 'refund corrections' in gift cards. Ever. That sentence alone defeats most of this article.
  • Before acting on a scanned QR code, read the URL your phone previews. Misspellings, weird domains, or link shorteners on a payment page mean walk away.
  • For small businesses: require purchase-order matching before paying any invoice, and verify new 'vendors' by independently found phone numbers.
The statement check beats every fake invoice
A fake invoice's power is that you can't remember whether you bought the thing. Your card statement remembers perfectly. Thirty seconds in your banking app — no charge exists — ends the entire scam without a single phone call. Verify with your money, not with their phone number.

If you already engaged

  1. If remote access happened: disconnect the computer from the internet, run a full malware scan, change banking passwords from a DIFFERENT device, and consider a professional cleanup before using it for finances again.
  2. If you paid: call your bank or card issuer immediately to dispute or attempt recall; gift card payments — call the card issuer (Apple, Amazon, etc.) with the card numbers; sometimes unspent balances can be frozen.
  3. Freeze your credit at all three bureaus if you shared personal information.
  4. Report at reportfraud.ftc.gov and ic3.gov — reports build the cases that shut these operations down.
  5. Expect follow-up scams: 'fund recovery services' that contact victims are almost always the same scammers coming back for dessert.

The bottom line

Fake invoices monetize your panic about a charge that doesn't exist; malicious QR codes monetize your trust in a square of pixels you can't read. The counters are equally boring: check your actual statement before reacting to any bill, never call numbers the 'bill' provides, read URLs before you pay, and treat every gift card request as a confession. Boring beats boring.

Check your understanding

1 of 3
You get an email saying your antivirus 'renewed for $499.99' with a number to call and dispute the charge. What's the fastest way to end this scam?

Not quite — try again.

The Worth letter

Get smarter about money every week

One email, no spam — practical guides and Worth updates. Unsubscribe anytime.

Put this into practice

Worth tracks your accounts, budgets, and goals — so the concepts in this article aren't just theory.

Start free trial