QR codes have become a convenient way to open menus, make payments, access parking services and visit websites. That convenience has also made them attractive to scammers.
A QR-code scam—sometimes called “quishing”—uses a misleading or altered code to direct you to a fraudulent website. The website may then attempt to steal login details, collect payment information or install malicious software.
Where fake QR codes may appear
Fraudulent codes can be distributed through:
-
Emails claiming that an account requires verification
-
Fake invoices or delivery notices
-
Posters, flyers and printed letters
-
Stickers placed over legitimate codes
-
Parking meters and payment stations
-
Restaurant tables and public noticeboards
-
Social media advertisements
-
Unexpected parcels
Because the destination is hidden inside the code, it can be harder to recognise a suspicious link before opening it.
Check before continuing
Most smartphones display the destination address before opening a QR-code link. Take a moment to inspect it.
Look for misspellings, unusual domains or addresses that do not match the organisation named on the sign or message. A padlock symbol does not prove that a website is genuine—it only indicates that the connection is encrypted.
If a code asks you to sign in or make a payment, consider visiting the organisation’s website directly instead.
Be careful with QR-code login requests
A scanned code may open a convincing copy of a Microsoft, Google, banking, hosting or social media login page.
Do not enter your password simply because the page contains familiar branding. Check the full website address first and use a password manager, which may refuse to autofill credentials on an imitation domain.
You should also reject any unexpected multi-factor authentication request generated after scanning a code.
Businesses should inspect public QR codes
Businesses using QR codes in customer areas should check them regularly for replacement stickers or tampering.
Printed codes should include the expected website address nearby so customers can confirm the destination. Avoid directing customers straight to a payment or login screen without providing context.
What to do after scanning a suspicious code
If you only opened the page, close it without downloading anything or entering information.
If you entered a password, change it immediately through the organisation’s genuine website. Sign out other sessions and check the account’s recovery details. Contact your bank promptly if payment information was provided.
Suspicious activity can be reported to Scamwatch or ReportCyber.
QR codes are useful, but they should be treated like any other link: check where they lead before trusting them.
petak, rujan 11, 2026
