Skip to content
Guide

QR Code Security: How to Spot and Avoid QR Scams

A QR code is not dangerous in itself – the risk is the page it sends you to. Before opening a scanned link, check the domain in your camera's preview, take extra care with codes that ask for payments or logins, and look for stickers placed over the original code.

What is quishing?

Quishing is phishing through a QR code. Instead of a suspicious link in an email, the attacker hides the link inside a code. Nobody can read a QR code with the naked eye, so you only see the destination after you scan it.

The code itself is just a container for text, usually a web address. Scanning it does not install anything on its own. The danger starts on the page it opens: a fake login form, a copied payment page or a prompt to download an app.

Consumer protection agencies and police in several countries have published warnings about QR scams. The reassuring part: a few simple habits protect you against the most common tricks, and none of them require special apps.

Why scammers like QR codes

A printed code looks official, and people trust the place where it hangs – a parking meter, a restaurant table, a letter with a logo. Email filters also have a harder time checking a link that is stored inside an image.

What a scammer is after

Usually one of three things: your login details, your card details, or a way to get unwanted software onto your phone. Every tip in this guide blocks at least one of those routes.

Common QR code scams to know

Most QR scams follow a handful of patterns. Recognising them is already half the protection.

Stickers over real codes

A fraudster prints a code and sticks it over the genuine one on a poster, meter or menu. The sticker leads to a look-alike page. Raised edges, a second layer or a code that sits slightly crooked are warning signs.

Fake payment and parking codes

Codes on parking meters, charging stations or invoices are popular targets, because you already expect to pay. The fake page collects your card details and sometimes quietly adds a recurring charge.

QR codes in emails and letters

A message claims your account is locked, a parcel is waiting or a fine is unpaid, and asks you to scan a code. Urgency, threats and deadlines are classic phishing signs, whether the link is typed or hidden in a code.

Codes that start downloads

A code that opens a file download or an unfamiliar app page can lead to unwanted software. Install apps only from the official app store, and only when you were looking for that app anyway.

Too-good-to-be-true offers

A code on a lamp post or flyer that promises a prize, a free gift card or a refund deserves the same suspicion as an email promising the same thing.

How to check a QR code before you open it

Your phone gives you a moment between scanning and opening. Use it. If you want to see a code's full content without visiting the page, decode it first with a QR code reader.

  1. Look at the code itself

    Is it printed as part of the sign, or stuck on top? Is the surface peeling or misaligned? If something looks off, don't scan it – ask staff or find another way to reach the service.

  2. Read the link preview

    iPhone and Android cameras show the web address before opening it. Check the domain, the part right before the first single slash: “pay.cityparking.example” is not the same as “cityparking-pay.example”.

  3. Check the page before typing

    Does the page clearly belong to the place where you found the code? Does the address start with HTTPS? Be wary of pages that immediately ask for passwords, card numbers or an app install.

  4. When in doubt, go direct

    Type the company's web address yourself or open its official app. You lose a few seconds instead of your card details.

Red flags in a scanned link

  • A domain that is almost right

    Swapped or doubled letters, extra hyphens, or added words such as “secure”, “verify” or “login” next to a brand name.

  • An unfamiliar short link

    Short links hide the final destination. Many legitimate codes use them, so this alone is not proof of fraud – but check the page it lands on even more carefully.

  • Instant requests for data

    A menu, a timetable or a product page never needs your password. A login or card form right after a scan should make you stop and think.

  • Pressure and countdowns

    “Pay within 10 minutes or your car will be towed” is designed to stop you thinking. Genuine operators give you time and official channels.

  • Unexpected downloads or permissions

    A page that starts a download or asks to install a profile, certificate or app is a strong reason to close it.

Extra care with QR payments and parking meters

Payment codes deserve the most attention, because the damage is direct.

  • Prefer the official app or the machine

    If the meter takes cards or the operator has an app, use it instead of a code whose origin you can't confirm.

  • Compare with the signage

    Operators usually print their name and website on the sign. The domain in the scanned link should match it.

  • Read the payment page

    A one-off parking fee should not come with a membership, a monthly plan or a pre-ticked subscription box.

  • Check your statement afterwards

    Look for the exact amount in your banking app. Report any charge you don't recognise to your bank as soon as possible.

  • Ask at restaurants

    A table code that opens the menu is normal. If a code asks for payment, check with staff that it belongs to the venue's own ordering or payment system.

QR code security tips for businesses

If you put QR codes in front of customers, you can make them much harder to abuse – and easier for people to trust.

Use a branded domain

A link on your own domain, such as go.yourbrand.com, is easier to recognise in the phone preview than a generic short link. With a custom domain, your dynamic codes use your own address, so customers see a name they already know.

Make tampering visible

Print codes directly on the material instead of adding stickers, place them behind glass or under lamination, and position them where staff can see them. A line such as “Our code only opens yourbrand.com” tells customers what to expect.

Check your codes regularly

Add QR codes to routine rounds, such as opening or cleaning checks. Look for stickers, scan each code and confirm it opens the right page.

Use dynamic codes you can switch off

A dynamic QR code points to a short link you control. If a code is copied, damaged or misused, you can deactivate it or change its destination without reprinting everything else.

Keep an eye on scan data

Scan statistics help you notice changes. A sudden drop in scans at one location can mean a code has been covered. QR code analytics show scans over time, by operating system and by approximate location.

Never ask for sensitive data straight after a scan

Design your flows so a scan leads to useful content first. If you take payments, use a checkout your customers recognise and explain it on the sign.

Static vs dynamic QR codes: the security angle

Both kinds are equally safe to scan. The difference is how much control you keep once the code is printed. Our guide to static and dynamic QR codes explains the rest.

Static Dynamic
Works without any third-party service Yes No
Deactivate the code if it is misused No Yes
Fix a wrong destination after printing No Yes
Scan statistics to spot unusual changes No Yes
Link can use your own domain Yes Yes

What to do if you scanned a malicious code

Opening a suspicious page is rarely the real problem. What matters is what happened next, so act according to how far you got.

  • You only opened the page: close the tab and don't go back to it.
  • You entered a password: change it right away on the real website, plus anywhere you reused it. Turn on any extra sign-in protection the service offers.
  • You entered card details: contact your bank or card issuer immediately and ask them to block the card.
  • You installed something: remove it, run your phone's built-in security check and install pending system updates.
  • Tell the owner: let the shop, venue or operator know so they can remove the fake code. You can also report it to the police or your national cybercrime or consumer protection authority.

Make your QR codes easy to trust

Put dynamic QR codes on your own domain and switch any code off from your dashboard if it is ever misused.

See custom domains
FAQ

Frequently asked questions

Still have a question? Read our guides or contact us .

Can scanning a QR code hack my phone?

Scanning only reads text, usually a link. The risk comes from the page it opens, such as fake forms, payment pages or downloads. Keep your phone updated and check the link before you open it.

What is quishing?

Quishing is QR code phishing: a scam that hides a malicious link inside a QR code. It often appears in emails, letters or as stickers placed over genuine codes.

How can I tell if a QR code is safe?

Check that the code isn't a sticker on top of another one, read the domain in the preview and make sure the page matches the place where you scanned it. Be wary of instant requests for passwords or payment.

Are QR code payments safe?

They can be, when the code really belongs to the merchant or operator. Compare the link with the name on the official signage, and use the machine or the official app when you are unsure.

Do I need a special app to scan QR codes safely?

No. The built-in camera on iPhone and Android shows the link before opening it, which is the key safety check. Our guide on how to scan a QR code covers each phone.

How can a business protect its QR codes from tampering?

Print codes directly on materials, place them where staff can see them, check them regularly and use a branded domain. Dynamic codes can be switched off if one is ever misused.

Are dynamic QR codes less safe than static ones?

No. Both are equally safe to scan. A dynamic code adds a short-link redirect, which also lets the owner fix or deactivate it after printing.

What should I do if I entered my details on a fake page?

Change the affected password on the real site, contact your bank if you entered card details, and report the code to the place where you found it.

Qdestera

QR codes your customers can trust.

Create dynamic QR codes on your own domain, keep an eye on scans and deactivate a code whenever you need to.

Start free