QR Code Scams: How to Scan Safely and Avoid Fake Codes

QR code scams, sometimes called quishing, hide a malicious web address inside a square pattern you cannot read by eye. Preview the link before opening it, avoid entering payment or login details after a scan, and be wary of codes placed on top of other codes.
Why QR codes are attractive to scammers
A QR code is just a way to store a link or other text. You cannot tell by looking at it whether it leads to a real site or a fake one. Scammers use that blind spot to bypass email filters, since the link is inside an image, and to target people on phones, where security warnings are fewer and addresses are truncated.
QR codes also exist in physical places, so a criminal can put a fake one on a poster, parking meter or restaurant table with a printed sticker.
Where fake QR codes show up
- Stickers over real codes. A new label placed on a payment sign, parking meter or poster.
- Emails and PDFs. A message that says to scan a code to “verify your account” or “update your security”.
- Unexpected mail. Letters or parcel notes with a code and urgent message.
- Flyers and posters. Offers, giveaways or job ads in public spaces.
- Messaging apps and social media. Codes sent by unknown contacts.
- Fake customer support cards. Cards that tell you to scan to claim a refund.
What the scam does after the scan
After scanning, the code may lead to one of several outcomes. A fake login page copies a real service to steal your password. A payment page asks for card details for a fee that does not exist. A download link pushes an app you did not request. Some codes start a payment to the scammer’s account directly if your phone supports payment links.
The page may look convincing, with correct logos and colors, so judge by context and web address, not design.
How to scan safely
- Preview the link. Most phone cameras show the web address before opening it. Read it carefully.
- Check the domain. Look for misspellings, extra words or an unrelated ending.
- Inspect physical codes. Is it a sticker on top of something? Does the surface look tampered with?
- Ask whether you expected it. A code in an unexpected email or letter is a warning.
- Avoid entering passwords or payment details after a scan unless you are sure of the site. Open the official app instead.
- Do not install apps from codes. Use the official app store.
Extra precautions for businesses and organizations
If you display QR codes, place them in tamper-resistant spots, check them regularly, and print the address in text beside them so customers can verify. Avoid sending codes in emails that ask people to log in, and teach staff to treat unexpected codes as suspicious.
If you scanned a suspicious code
Close the page without entering information. If you did enter a password, change it on the official site and enable multi-factor authentication. If you gave card details, contact your card issuer. If an app was installed, remove it and run a scan. Report the fake code to the business whose name it used.
Adjusting your phone settings
A few small settings changes make scanning safer. Make sure your camera app or scanner shows the full web address before it opens anything, rather than opening links automatically. Keep your operating system and browser updated so that known weaknesses are patched. If your browser offers safe browsing or phishing warnings, leave them switched on, since these can flag known malicious pages after a scan.
Consider using a password manager. Most can fill in credentials only on the exact site you saved them for, so if a QR code leads to a lookalike page, the manager will not offer your password. That mismatch is a useful signal that something is wrong.
Quick comparison: safe and risky QR situations
- Safer: scanning a code inside an app you opened yourself, or one printed in a booklet from a source you trust.
- Riskier: scanning a code from an unsolicited email, a random poster or a message from an unknown contact.
- Riskier: scanning a code that asks you to sign in, pay a fee or download something immediately.
The rule of thumb is that you should be able to explain why you are scanning the code and what you expect to see. If you cannot, skip it and find the information another way.
Frequently asked questions
Can scanning a QR code alone infect my phone?
It is uncommon, as most harm comes from what you do after the page opens. Keep your phone updated and do not approve downloads or permissions prompted by a scan.
Are QR codes in official apps safe?
Codes generated inside a trusted app, for example to pair a device, are generally safe because you started the process. Be cautious with codes received from elsewhere.
How can I tell if a QR code was tampered with?
Look for stickers, uneven edges, or a code that sits over a different design. When in doubt, use the business’s official website.
Key takeaways
- A QR code hides its destination, so always preview the link.
- Be suspicious of codes pasted over other codes or sent unexpectedly.
- Do not log in or pay on a page reached through an unverified code.
- Use official apps and typed web addresses when anything feels off.


