IONITY, one of Europe’s largest high-power EV charging networks, has published a fraud alert warning drivers that criminals are placing counterfeit QR code stickers directly over the genuine payment codes on its charging stations. The tactic is called “quishing” — QR code phishing — and according to IONITY’s own support page, the fake codes send unsuspecting drivers to cloned payment pages designed to look identical to the real thing while quietly harvesting card numbers, expiration dates, and security codes. The scam works because it exploits the one moment every EV driver is vulnerable: standing at a charger, phone out, just wanting to get electrons flowing and get back on the road.

Electric vehicle charging cable plugged into a car at a charging station

How the sticker scam actually works

IONITY says fraudsters have been “placing fake QR codes over the genuine ones, redirecting unsuspecting customers to fraudulent websites that closely mimic” its official payment platform. The counterfeit sites are built to replicate IONITY’s branding, layout, and even the flow of a legitimate transaction closely enough that a driver in a hurry has no obvious reason to be suspicious. Once payment details are entered, they go straight to whoever printed the sticker — not to the charging network, and not toward actually starting a charging session. The driver is left standing at a dead terminal, out however much money they just handed over, sometimes with a subscription-style charge still ticking against their card weeks later.

This isn’t a hypothetical problem grafted onto EV charging from some other industry. The U.S. Federal Trade Commission has been sounding a nearly identical alarm domestically, warning in a September 2026 consumer alert about “scammers covering up legit QR codes” on parking meters with fraudulent codes of their own — the exact same mechanic, just a different piece of curbside hardware. The FTC’s advice for spotting a bad link before you tap it applies just as well at a charging bay as it does at a parking spot: look closely at the URL preview your phone shows before it opens, and watch for misspellings or subtly altered domain names.

What to actually check before you scan

IONITY’s fraud alert lays out specific physical tells drivers can look for on the sticker itself. The company advises checking for “peeling edges, mismatched colours, or stickers placed over the original QR code” — a fake sticker slapped on top of a manufactured screen or payment terminal often sits slightly proud of the surface, or doesn’t quite match the finish around it. Before entering any payment information, IONITY also tells customers to verify that the address in their browser actually reads “https://payment.ionity.eu” rather than a lookalike domain with an extra letter, hyphen, or unfamiliar top-level domain tacked on.

  • Inspect the sticker itself for peeling edges, bubbling, or a mismatched color/finish versus the terminal around it
  • Check the URL that loads before entering any card details — confirm it matches the network’s actual payment domain exactly
  • Prefer the charging network’s own app over scanning any QR code when the option exists
  • Use a contactless card tap at the terminal itself when that payment method is available
  • Report anything suspicious to the network’s customer service line immediately, before attempting the charge again

The workaround IONITY actually recommends

Rather than just telling customers to be more careful with their eyes, IONITY’s fraud alert pushes drivers toward a structurally safer option: skip the QR code step entirely. The company “strongly recommends users use the IONITY App instead of scanning a QR code” to start and pay for a charging session, since the app authenticates directly with IONITY’s own servers and never routes a driver through a scannable code that a stranger could have tampered with in the parking lot. As a secondary option, IONITY notes that “contactless card payment via a terminal (if available) is also a secure option” — again bypassing the vulnerable QR-to-webpage handoff altogether.

That app-first guidance matters more in the U.S. than it might seem at first glance. Charging networks here — Electrify America, EVgo, and the rest — increasingly lean on QR-triggered payment flows at unmanned stations, especially at older or lower-traffic sites where a card reader either was never installed or has since failed. Anywhere a payment code is sitting exposed on a public post with no attendant nearby, the same sticker-swap trick IONITY is warning about in Europe works just as well.

Why this keeps happening at unattended payment points

QR codes are cheap and simple to deploy, which is exactly why they’ve spread across parking meters, restaurant tables, and charging stations in the past few years — and exactly why they’re such an easy target. A fraudster doesn’t need to hack anything to run this scam; they need a sticker, a printer, and thirty seconds of privacy at a charger nobody happens to be using. IONITY’s decision to publish a standing fraud alert, rather than a one-off warning, suggests the network expects the tactic to keep recurring rather than fade out after a single crackdown.

None of this means public charging is unsafe to use. It means the QR code on the post in front of you deserves the same second look you’d give an ATM card slot that looks slightly off — because increasingly, that’s exactly what it is.

Leave a Reply

Your email address will not be published. Required fields are marked *