QR Code Scams (Quishing): What to Watch For
A QR code is just a link you cannot read with your eyes, which makes it a perfect hiding spot for scammers. "Quishing" (QR phishing) puts malicious codes on parking meters, flyers, emails, and stickers placed over real ones.
How QR code scams work
The trick is simple: you trust the code and scan it, landing on a fake site.
- A sticker with a malicious QR code is placed over a legitimate one (on a parking meter or poster).
- A phishing email includes a QR code to dodge link filters, you scan it with your phone.
- The code opens a fake login or payment page, or prompts a malicious download.
How to scan safely
Treat a QR code like any other link:
- Preview the URL before opening it, most phone cameras show the address first.
- Check the domain for look-alikes and odd spellings.
- Be suspicious of codes that lead to a login or payment page.
- Prefer typing a known web address over scanning a code for anything sensitive.
- On physical codes, look for a sticker placed over the original.
How it plays out in the real world
Based on real, widely reported incident patterns; names and details are illustrative.
The sticker on the parking meter
In widely reported cases across several US cities, drivers found QR codes on parking meters, scanned them, and paid on a convincing "quick pay" website. The codes were stickers placed by scammers over legitimate signage; the cities did not take payment by QR code at all.
Cards used on the fake site paid for parking that was never registered, then were charged again, elsewhere, days later.
- A QR code is just a link you cannot read. Stickers cost cents and can be placed anywhere that looks official. Physical location is not verification.
- Check the URL after scanning, before acting. Your camera shows the destination before you open it. quickpay-parking.co is not your city government. Pause at the preview.
- Pay through official apps instead. For parking, tolls, and utilities, the official app or a typed address skips the QR question entirely.
Test yourself
Test your quishing awareness, free.
Frequently asked questions
Can scanning a QR code hack my phone instantly?
Simply scanning and previewing the link is generally safe. The risk comes from what you do next, opening the page and then entering credentials, making a payment, or installing something. Always preview the URL first.
Where do malicious QR codes usually appear?
Common spots include parking meters and payment terminals (stickers over the real code), flyers and posters, and phishing emails that use a QR code to slip past link scanners.
How do I preview a QR link before opening it?
Most modern phone cameras show the destination URL as a banner when you point at a code. Read that address and check the domain before tapping to open it.