Skip to main content
How to Spot Malicious QR Codes: The Complete Quishing and QR Scam Guide
qr code safetyquishingqr code scamfake qr codemobile securityphishing

How to Spot Malicious QR Codes: The Complete Quishing and QR Scam Guide

Malicious QR codes hide links you can't read. Learn how quishing works, the red flags of a fake QR code, how to preview URLs before opening them, and exactly what to do if you scanned a scam code.

V
· 10 min read
Updated on July 31, 2026

QR codes are everywhere — on menus, parking meters, posters, invoices, delivery slips — and scammers have noticed. This guide explains how QR code scams work, the red flags that give a fake QR code away, and the habits that make scanning essentially risk-free.

Quick answer: Malicious QR codes work by hiding a link you can't read — the square of pixels gives no clue where it actually leads. The defense is simple: always preview the decoded URL before opening it, and be suspicious of stickers, unsolicited codes, and anything demanding payment or a login. If the link looks wrong, don't tap it.

What Is Quishing and How Do QR Code Scams Work?

Quishing — short for "QR phishing" — is a phishing attack that uses a QR code instead of a clickable link. The scam works because a QR code hides its destination: you can read a suspicious URL in a text message, but you cannot read a QR code with your eyes. Attackers print a code leading to a fake login page, a fraudulent payment form, or a malicious download, then place it somewhere you would expect a legitimate code to be. When you scan it, your phone helpfully offers to open the link, and everything after that looks like a normal website visit. The attack succeeds not because scanning is dangerous, but because people open the decoded link without reading it first.

Quishing has a second advantage for attackers: it slips past technical defenses. Email filters are good at scanning text links, but a QR code embedded as an image is much harder to inspect automatically — which is why phishing emails increasingly say "scan the code below" instead of offering a button. The payloads themselves are rarely exotic: a fake login page that harvests credentials, a fraudulent payment form that takes your card details, or a download prompt for an app or configuration profile you should never install from a random link.

Where Do Fake QR Codes Show Up Most Often?

Fake QR codes appear wherever a real one would be trusted and unattended. The most commonly reported patterns are sticker overlays on parking meters and pay-by-phone signs, tampered codes on restaurant menus, fake payment codes in shops and on invoices, QR codes embedded in phishing emails to dodge link filters, and codes on bogus package-delivery notices. In every case the trick is the same: the attacker borrows the credibility of the surface the code sits on. A code on an official-looking parking sign feels safe, so people scan it and pay a "fine" straight into a scammer's account. Knowing these hot spots is half the defense — they are exactly the places to slow down and inspect the code first.

A few of these patterns deserve a closer look:

  • Parking meters and pay stations. A sticker with a fraudulent payment link is placed over the real code; drivers in a hurry scan, "pay," and hand over card details. If your city has an official parking app, use the app store instead.
  • Restaurant menus and counters. Table tents and decals sit unattended for hours, making them easy to re-sticker. If a "menu" asks for a card number or a login, walk away.
  • Phishing emails and letters. "Your account will be suspended" messages increasingly carry a QR code instead of a link, precisely because scanning bypasses your mail provider's link protection.
  • Package and delivery scams. A missed-delivery slip asks you to scan a code to reschedule or pay a small customs fee. Real carriers handle this through their official site or app — go there directly.

What Are the Red Flags of a Malicious QR Code?

Before you scan, check the physical code; after you scan, check the decoded link. Physically, the biggest red flag is a sticker placed over an original printed code — run a finger over it and look for misalignment, bubbling, or material that doesn't match the sign around it. Digitally, the giveaways live in the URL: a shortened link where a brand would use its own domain, a misspelled or lookalike domain, or a long chain of random characters. Finally, watch the request itself: urgency ("pay within 30 minutes"), threats of fines or suspension, and demands for passwords, card numbers, or app installs are classic phishing pressure tactics. One red flag is a reason to pause; two or more is a reason to walk away.

Use this checklist whenever something feels off:

  • Sticker over the original — edges, bubbles, or print quality that doesn't match the sign it's on.
  • Odd placement — a code on a lamppost, cash machine, or handwritten note where no official code belongs.
  • Shortened or mismatched URLs — a parking authority or bank pointing to a generic short link or an unrelated domain.
  • Lookalike domains — swapped letters, extra hyphens, or the brand name buried in a subdomain of a strange site.
  • Urgency and threats — countdown timers, "final notice" language, warnings that your account will be locked.
  • Requests for credentials or payment — a menu or Wi-Fi login has no business asking for your bank password.
  • Unexpected download prompts — any code that immediately tries to install an app or configuration profile.

How Do You Preview a QR Code's URL Before Opening It?

The single most effective safety habit is reading the destination before you visit it. Use a scanner that decodes the code and shows you the full URL first, instead of launching your browser automatically. QRBot (free on iOS and Android) is built around exactly this: every scan shows the decoded URL or content on screen before anything opens, so you can check the domain, spot a lookalike address, and decide whether to proceed — or simply close it. Built-in camera apps vary; some show only a truncated preview banner, and others open links on a single careless tap. Whatever tool you use, never let a scan go straight to a website you haven't read the address of.

When the preview appears, read it like a skeptic:

  1. Find the real domain — the part just before the first single /. pay.example-parking.com/session is controlled by example-parking.com, not by "pay."
  2. Match it to the context. A bank letter should lead to the bank's exact domain, not a variation of it.
  3. Distrust short links in official settings — legitimate organizations put payments and logins on their own domains.
  4. When unsure, don't open it. Type the organization's address into your browser yourself instead.

QRBot's searchable scan history also lets you review what you scanned later — useful if you hear about a scam after the fact. History stays on your device behind an optional Face ID/PIN lock, and the app doesn't log the URLs you open on any server. If you're comparing tools, our guide to the best QR code scanner apps covers which ones preview links properly.

What Should You Do If You Scanned a Malicious QR Code?

First, don't panic — scanning alone almost never causes harm. The danger begins with what you do on the page, so if you merely opened a suspicious link, close the browser tab and move on. If you typed anything in, act on what you shared: change that password immediately (and everywhere you reused it), and turn on two-factor authentication. If you entered card details, contact your bank, block or reissue the card, and watch your statements for small "test" charges. If you installed anything — an app, an APK, a configuration profile — remove it right away. Then report the scam so the next person doesn't fall for it.

A quick damage-control checklist:

  • Entered a password? Change it now, starting with email, and enable two-factor authentication.
  • Entered payment details? Call your bank, block the card, and dispute unfamiliar charges.
  • Installed something? Delete it. On iOS, remove any unknown profile under Settings → General → VPN & Device Management; on Android, review recent apps and run Play Protect.
  • Report it to the venue whose code was tampered with and to your local consumer-protection or cybercrime authority.
  • Keep watching. Phished data is often used weeks later — follow-up "your account was compromised" calls are frequently part two of the same scam.

Reviewing your scan history in QRBot makes this cleanup easier: you can look up exactly which URL you scanned and when, instead of guessing.

How Can Businesses Protect Their Printed QR Codes?

If your business prints QR codes, assume someone may eventually try to sticker over them. The strongest defenses are physical and visual. Place codes where tampering is obvious and swaps are hard: printed directly on menus and packaging rather than on stick-on labels, behind glass or laminate, at staffed counters instead of unattended tables. Inspect high-risk placements regularly — a ten-second glance catches most overlay attacks. Visually, a branded code with your logo and colors is meaningfully harder to counterfeit than a plain black-and-white square, because a generic sticker on top of it looks instantly wrong. Finally, keep destination URLs on your own domain and short enough that customers can sanity-check them.

Practical steps that cost almost nothing:

  • Print, don't stick. Codes printed into the design of a menu, poster, or label can't be peeled off and are harder to cover convincingly.
  • Brand the code. A QR code with your logo and brand colors gives customers something to verify — and makes a plain overlay sticker stand out.
  • Show the URL next to the code so careful customers can cross-check the destination.
  • Use your own domain, avoid generic short links for payments and accounts, and generate codes with a trustworthy QR generator that doesn't inject redirects.
  • Audit placements during opening or closing routines for meters, menus, and posters in public reach.

What Are the Safest QR Scanning Habits?

Safe scanning comes down to five simple habits: preview every link before opening it, be suspicious of codes in unattended public places, never enter credentials or payment details on a page you reached by scanning (go to the official site yourself instead), never install apps or profiles from a scanned link, and keep your phone and scanner app updated. None of these habits require technical skill — just the discipline to pause for two seconds between scanning and tapping. Treat every QR code exactly as you would treat a link from a stranger: fine to look at, unwise to trust blindly.

Make the pause automatic with a scanner designed for it. QRBot shows the decoded URL before anything opens, keeps a searchable scan history on your device behind an optional Face ID/PIN lock, and never logs your scans to a server. It's free on iOS and Android — download QRBot here and make "read first, tap second" your default.

Frequently Asked Questions

Can scanning a QR code hack your phone?

Scanning alone almost never hacks a phone. A QR code is just data — usually a web address — and decoding it doesn't run any program on your device. The real danger is what happens next: a convincing fake login page, a fraudulent payment form, or a prompt to install malicious software. The scan opens the door; you still have to walk through it. Preview the URL, refuse unexpected downloads, and never enter credentials on pages you reached by scanning, and the code itself can't do much. Keeping your phone updated closes the rare browser vulnerabilities that could change that.

How can I check a QR code before opening it?

Use a scanner that shows the decoded link before launching your browser. QRBot displays the full URL or content of every code first, so you can read the domain and decide whether to open it. Check that the core domain matches who the code claims to be from, and be wary of shortened links and lookalike domains. Inspect the code physically too: if it's a sticker sitting on top of another code, skip it and type the organization's address into your browser yourself.

What does a fake QR code look like?

Usually, exactly like a real one — that's the problem. The clues are contextual rather than visual: a sticker layered over an original printed code, mismatched print quality, codes in odd locations like ATMs or lampposts, and accompanying text that pushes urgency or payment. The decisive evidence is the decoded URL, which is why previewing before opening matters more than squinting at the pattern itself. Branded codes with logos are harder to counterfeit, which is one reason legitimate businesses increasingly use them.

Are QR codes on restaurant menus safe?

Mostly yes — menu codes are among the most common legitimate uses. The risk is tampering: table tents and decals sit unattended, so a scammer can cover the real code with a sticker leading to a phishing or payment page. The practical rule is simple: a menu should show you food. If a menu code leads to a login form, a payment request, or an app download, stop and tell the staff. Previewing the URL first removes nearly all of the risk.

Is it safe to scan QR codes in emails?

Be extra careful with these. Legitimate services occasionally use QR codes in email, but attackers love them because a code embedded as an image can slip past filters that would catch a suspicious text link — and it moves you onto your phone, away from your computer's protections. Treat any emailed code that leads to a login page, "verification," or payment as hostile until proven otherwise: go to the service directly through its official website or app instead. If you do scan, confirm the domain is exactly the company's own before proceeding.

Share this post

You might also like