QR Code Scams (Quishing): What to Watch For

A QR code is just a link you cannot read with your eyes, which makes it a perfect hiding spot for scammers. "Quishing" (QR phishing) puts malicious codes on parking meters, flyers, emails, and stickers placed over real ones.

How QR code scams work

The trick is simple: you trust the code and scan it, landing on a fake site.

  • A sticker with a malicious QR code is placed over a legitimate one (on a parking meter or poster).
  • A phishing email includes a QR code to dodge link filters, you scan it with your phone.
  • The code opens a fake login or payment page, or prompts a malicious download.

How to scan safely

Treat a QR code like any other link:

  • Preview the URL before opening it, most phone cameras show the address first.
  • Check the domain for look-alikes and odd spellings.
  • Be suspicious of codes that lead to a login or payment page.
  • Prefer typing a known web address over scanning a code for anything sensitive.
  • On physical codes, look for a sticker placed over the original.

Test yourself

Test your quishing awareness, free.

Build a QR Scams quiz with AI

Frequently asked questions

Can scanning a QR code hack my phone instantly?

Simply scanning and previewing the link is generally safe. The risk comes from what you do next, opening the page and then entering credentials, making a payment, or installing something. Always preview the URL first.

Where do malicious QR codes usually appear?

Common spots include parking meters and payment terminals (stickers over the real code), flyers and posters, and phishing emails that use a QR code to slip past link scanners.

How do I preview a QR link before opening it?

Most modern phone cameras show the destination URL as a banner when you point at a code. Read that address and check the domain before tapping to open it.

← All guides