QR Code Scams: How to Spot Quishing Before You Scan
QR codes have become a normal part of daily life. People scan them to pay for parking, open restaurant menus, board flights, enter events, make payments, and sign in to accounts. That convenience has created a growing opportunity for criminals: QR code phishing, often called quishing.
A malicious QR code can hide a fake login page, a fraudulent payment request, or a link designed to download harmful software. Because the destination is hidden until after you scan, many people act before checking where the code leads.
What Is Quishing?
Quishing combines “QR code” and “phishing.” Instead of placing a visible malicious link in an email or text, the attacker turns the link into a scannable image. The QR code may send you to:
- A fake Microsoft 365, Google, bank, or delivery-company login page
- A counterfeit parking or restaurant payment portal
- A page that asks for credit card or identity information
- An app download outside the official Apple App Store or Google Play
- A cryptocurrency wallet controlled by a scammer
- A site that requests dangerous browser, camera, notification, or accessibility permissions
The U.S. Federal Trade Commission warns that scammers place fake codes on parking meters and send QR codes in unexpected messages to create urgency. The code may lead to a spoofed site or trigger a malicious download.
Why QR Code Scams Are So Effective
The real destination is hidden
A normal link gives you a chance to read the domain. A QR image makes the destination less obvious, especially on a small phone screen.
People trust physical signs
A code printed on a parking meter, restaurant table, event poster, or parcel can feel official. A criminal may simply place a sticker over the legitimate code.
Phones hold high-value accounts
The same device used to scan the code may also contain email, banking, payment apps, authenticator codes, photos, and saved passwords.
Urgency reduces careful thinking
Fake messages commonly claim that a package could not be delivered, a toll is overdue, an account will be suspended, or a payment must be completed immediately.
Seven Common QR Code Scam Examples
1. Fake parking payment codes
A sticker covers the real code on a parking meter or sign. The fake website copies the local parking operator’s branding and collects card details. Whenever possible, open the official city or parking app yourself instead of trusting a code on the street.
2. Package delivery messages
A text, email, or unexpected parcel says you must scan to reschedule delivery, confirm your address, or identify the sender. In 2025, the FBI warned about unsolicited packages containing QR codes that direct recipients to sites designed to steal personal and financial information or install malware.
3. Microsoft 365 or Google account verification
A work email says your password expires today and displays a QR code to “keep your account active.” The destination is a fake sign-in page. This tactic can bypass basic email link scanning because the malicious address is inside an image.
4. Restaurant menu replacement
A fraudulent sticker is placed over a menu code. The page may ask for payment, personal details, or an app installation when a menu should require none of those.
5. Cryptocurrency payment fraud
An impersonator tells you to buy cryptocurrency at an ATM and scan a wallet code. Government agencies, police, utilities, and legitimate prize promoters do not demand payment this way. Cryptocurrency transfers are usually difficult or impossible to reverse.
6. Fake event tickets and giveaways
A social post promises concert, football, festival, or travel tickets. The QR code leads to a counterfeit checkout or a page that steals a social-media login.
7. Public Wi-Fi sign-in codes
A sign in a café, airport, or hotel offers “free Wi-Fi” through a QR code. It may connect you to an attacker-controlled network or capture personal information. Ask staff for the exact network name instead.
How to Check a QR Code Safely
- Stop if the code was unexpected. A surprise email, text, parcel, or social message is a high-risk source.
- Inspect the physical code. Look for raised edges, a different paper texture, mismatched colors, or a sticker covering another code.
- Preview the URL. Most modern phone cameras show the destination before opening it. Read the domain carefully.
- Check spelling and structure. Watch for extra words, substituted letters, unusual subdomains, or a shortened link that hides the final destination.
- Open the official site yourself. If the code claims to come from a bank, delivery company, airline, employer, or public authority, use its official app or type the known address manually.
- Do not install unknown apps. Use the official app store and verify the developer.
- Never bypass a security warning. Leave immediately if your browser warns that the connection or download is unsafe.
Can an iPhone or Android Be Hacked Just by Scanning?
Usually, scanning only reads the code and displays or opens its destination. The most common danger begins when you enter information, authorize a payment, install an app, download a file, or grant permissions.
However, software vulnerabilities do exist. Keep iOS or Android and your browser updated so known security flaws are patched. Do not assume a page is safe simply because nothing obvious happened after it opened.
Warning Signs After the Page Opens
- The site requests a password immediately after an unexpected message
- The domain does not exactly match the organization
- The page asks for a small “verification” payment
- You are told to install an APK, profile, browser extension, or remote-support app
- The site asks for a one-time security code after taking your password
- A timer or threat pressures you to act
- Payment is limited to cryptocurrency, gift cards, wire transfer, or an unfamiliar app
- The browser asks for unusual notification, accessibility, device-admin, or screen-sharing access
What to Do If You Scanned a Suspicious QR Code
If you only opened the page
- Close the tab.
- Do not download anything or approve permissions.
- Clear the browser’s recent site data if you are concerned.
- Update your phone and browser.
- Watch for unusual notifications, pop-ups, or account alerts.
If you entered a password
- Go directly to the real service and change the password immediately.
- Change any other account using the same or a similar password.
- Sign out unknown sessions and review recent security activity.
- Check recovery email addresses, phone numbers, forwarding rules, and connected apps.
- Enable a passkey or app-based two-factor authentication.
Use a unique credential from a trusted password manager so one stolen password cannot unlock multiple accounts.
If you entered card or bank information
- Call the financial institution using the number on the card or official website.
- Lock or replace the card if advised.
- Dispute fraudulent transactions quickly.
- Monitor statements and turn on transaction alerts.
- In the United States, report identity misuse at IdentityTheft.gov. In Europe, contact the financial provider and the relevant national police or cybercrime reporting channel.
If you installed an app or file
- Disconnect from the network if the device behaves strangely.
- Remove the unknown app and any suspicious device-management profile.
- Review app permissions, especially accessibility, SMS, screen capture, and device administration.
- Run the built-in security scan or a reputable mobile security tool.
- Change important passwords from a different, trusted device.
- Consider a factory reset if malware is confirmed or you cannot restore control.
How Businesses Can Defend Against Quishing
- Train staff to treat QR codes like unknown links.
- Require employees to verify account alerts through the official portal.
- Use phishing-resistant MFA such as passkeys or hardware security keys.
- Inspect QR codes placed in public locations regularly.
- Print a short official domain beside each legitimate code.
- Protect email with image analysis, domain filtering, and user reporting.
- Create an easy process for reporting suspicious codes.
Employees should also review our complete guide on how to spot phishing emails, because quishing uses the same psychological triggers.
QR Code Scam FAQ
Is a QR code from a friend always safe?
No. Their account may have been compromised, or they may have forwarded the code without checking it. Confirm unusual requests through another channel.
Are QR code scanner apps safer?
The built-in camera on a fully updated phone is usually enough. Unknown scanner apps may collect unnecessary data or show aggressive ads. Always preview the destination.
Can antivirus block a malicious QR code?
Security software may block a known harmful website or app, but it cannot guarantee that every new phishing page will be detected. Verification remains essential.
Should I scan a QR code to receive money?
Only inside a trusted payment app and as part of a transaction you understand. A stranger who instructs you to buy cryptocurrency or scan a wallet address is a major warning sign.
The Bottom Line
A QR code is simply a hidden link. Treat it with the same caution you would apply to an unexpected email attachment or shortened URL. Preview the domain, use official apps and websites, and never let urgency push you into entering a password or payment information.
If something feels wrong, do not scan. Taking thirty seconds to verify the source can prevent an account takeover, fraudulent charge, or identity theft.
Comments
Post a Comment