facebook-pixel

QR Code Phishing Scams: How to Stay Safe in 2026

L
Lunyb Security Team
··10 min read

QR codes went from niche marketing gimmick to everyday utility almost overnight. We scan them to pay for parking, view restaurant menus, board flights, and authenticate accounts. Unfortunately, scammers noticed the shift too — and "quishing" (QR code phishing) is now one of the fastest-growing social engineering threats of the decade.

This guide explains exactly how QR code phishing scams work, where you're most likely to encounter them, and the concrete steps you can take to protect yourself, your family, and your organization.

What Are QR Code Phishing Scams?

QR code phishing scams — often called "quishing" — are attacks where criminals use malicious QR codes to trick victims into visiting fraudulent websites, downloading malware, or handing over sensitive information. Because a QR code is just a machine-readable image, users can't tell where it leads until they've already scanned it, making it a uniquely effective phishing vector.

Unlike a suspicious email link where the destination URL can be hovered over and inspected, a QR code hides its payload behind an unreadable pattern of squares. That opacity is exactly why attackers love it.

Why QR Code Phishing Works So Well

  • Trust by association: QR codes are printed on official-looking flyers, invoices, parking meters, and packaging — contexts we're conditioned to trust.
  • Mobile-first attacks: Scans happen on phones, where URLs are truncated, security tooling is weaker, and users are often distracted.
  • Email filter bypass: A QR code embedded in an image evades link-scanning gateways that would normally flag a phishing URL.
  • Low friction: Scanning is faster than typing, so users act before thinking.

How a QR Code Phishing Attack Actually Works

Most quishing campaigns follow a predictable five-step pattern:

  1. Attacker creates a lookalike landing page that mimics a bank, Microsoft 365 login, DHL tracking portal, or payment processor.
  2. They generate a QR code pointing to that page, often routed through a shortened or obfuscated URL.
  3. They distribute the code via email attachments, physical stickers placed over legitimate codes, fake letters, or forged invoices.
  4. The victim scans the code and lands on the fake page, where they enter credentials, card details, or approve a multi-factor authentication prompt.
  5. The attacker harvests the data in real time and either drains accounts, resells the credentials, or pivots into a wider corporate breach.

Common Types of QR Code Phishing Scams

Not all quishing attacks look the same. Recognizing the category helps you spot them faster.

1. Email-Based Quishing

An email arrives claiming your Microsoft 365 password is expiring, your DocuSign contract is ready, or your voicemail is waiting. Instead of a clickable link, the email contains a QR code image with instructions to "scan with your phone." The goal is to move you off a monitored corporate device onto an unmanaged personal phone where credential theft is easier.

2. Sticker Overlay Attacks

Criminals print malicious QR code stickers and place them over legitimate codes on parking meters, EV chargers, restaurant tables, and public posters. In 2023 and 2024, cities across the US, UK, and Europe reported waves of fake parking-payment QR codes that drained victims' cards within minutes.

3. Fake Invoice and Delivery Scams

A physical letter or PDF invoice arrives with a QR code for "quick payment" or "package redelivery." The code leads to a payment page that captures card details or triggers a bank transfer to the attacker's account.

4. Crypto and Wallet Draining

Scammers post QR codes on social media, forums, or fake giveaway sites that, when scanned by a crypto wallet app, authorize a malicious smart contract or send funds directly to an attacker-controlled address.

5. Wi-Fi Quishing

QR codes can encode Wi-Fi credentials. A poisoned code in a café or hotel connects your device to a rogue access point, letting attackers intercept unencrypted traffic.

Comparison: QR Phishing vs. Traditional Phishing

AspectTraditional PhishingQR Code Phishing (Quishing)
Delivery ChannelEmail, SMS, chatEmail images, physical stickers, print, posters
URL VisibilityVisible on hoverHidden until scan
Device TargetedDesktop or mobileAlmost always mobile
Security Filter DetectionHigh — link scanners work wellLow — image bypasses most filters
User Suspicion LevelModerate to highLow — QR codes feel legitimate
Common PayloadFake login pageFake login page, malware, payment fraud

Real-World Examples of QR Code Phishing

The Microsoft 365 Credential Campaign

Starting in mid-2023, security researchers tracked a massive campaign in which attackers emailed employees a PNG image containing a QR code and a message like "Your MFA setup expires today." Scanning the code on a personal phone led to a pixel-perfect Microsoft login clone. The attack disproportionately targeted executives and finance teams.

Parking Meter Scams

In Texas, Florida, and multiple UK cities, drivers scanned QR codes on parking meters that turned out to be counterfeit stickers. Victims lost hundreds of dollars each, and in some cases their card details were resold on the dark web.

Fake Bank Letters

Attackers mailed physical letters on convincing bank letterhead asking customers to "reverify" their account by scanning an enclosed QR code. The letters were expensive to produce — a strong signal that quishing has moved beyond low-effort spam into organized fraud.

How to Spot a Malicious QR Code

Before you scan, run through this mental checklist:

  1. Consider the source. Is the code in an unsolicited email, an unexpected letter, or slapped onto public infrastructure with a sticker? All are red flags.
  2. Look for tampering. On physical signage, check whether the QR code is a sticker placed over an original code. Peel gently if it's safe to do so.
  3. Preview the URL. Modern iOS and Android cameras show the destination URL before opening it. Read the full domain carefully — micros0ft-login.com is not Microsoft.
  4. Watch for urgency. "Scan now or your account will be locked" is a classic pressure tactic.
  5. Check the domain reputation. If the URL uses an unfamiliar shortener or a domain you've never seen, treat it as hostile until proven otherwise.

How to Stay Safe: Practical Defenses

For Individuals

  • Never scan QR codes in unsolicited emails. If your "bank" or "IT department" wants you to log in, navigate directly to the site in your browser.
  • Use a QR reader that previews URLs. Both iOS Camera and Google Lens display the destination before opening. Don't disable this.
  • Type payment URLs manually for parking, tolls, and public services rather than scanning printed codes.
  • Enable multi-factor authentication everywhere — ideally with an authenticator app or hardware key, not SMS.
  • Keep your mobile OS and browser updated. Many QR-delivered exploits rely on unpatched vulnerabilities.
  • Use encrypted DNS (DNS over HTTPS) on your phone so malicious domains can be blocked at the resolver level.

For Businesses

  • Train employees specifically on quishing — many awareness programs still focus only on email links.
  • Deploy image-analysis email security that can decode QR codes inside attachments and inspect their destinations.
  • Enforce conditional access policies so credentials stolen via a personal phone still can't authenticate from an unmanaged device.
  • Audit physical signage in offices, retail locations, and public-facing spaces for tampered QR codes.
  • Publish an internal QR policy stating that IT will never ask staff to scan a code to log in.

The Role of Trusted URL Shorteners

Because most QR codes encode a URL, the underlying link infrastructure matters enormously. Reputable shortening platforms give both scanners and creators important safety guarantees: link scanning against malware databases, the ability to disable a compromised link instantly, and analytics that can flag anomalous traffic.

If you're creating QR codes for your own business — for menus, marketing campaigns, or event check-ins — use a reputable, transparent link platform like Lunyb that lets you monitor scans, rotate destinations, and revoke links if a printed asset is compromised. For a broader look at how different providers stack up, see our 2026 URL shortener buyer's guide and our honest review of Lunyb.

What to Do If You've Scanned a Malicious QR Code

Act fast — the earlier you respond, the smaller the damage.

  1. Disconnect the device from Wi-Fi and mobile data if you suspect malware was installed.
  2. Do not enter credentials if you're already on the suspicious page. Close the tab immediately.
  3. Change passwords for any account you may have exposed, starting with email and banking.
  4. Revoke active sessions in your account's security settings and re-enable MFA.
  5. Contact your bank if you entered card or payment details, and request a card reissue.
  6. Run a mobile security scan from a reputable vendor and check for unfamiliar apps or profiles.
  7. Report the scam to your national cybercrime authority (FTC in the US, Action Fraud in the UK, ACSC in Australia).
  8. Notify your employer's security team if the incident touched a work account or work device.

The Future of QR Code Phishing

Expect quishing to evolve in three directions over the next few years:

  • AI-generated lookalike sites that are visually indistinguishable from the real thing and can be spun up in seconds.
  • Dynamic QR codes whose destinations change based on time, geography, or device fingerprint — making detection harder for researchers.
  • Deeper integration with voice and SMS attacks, where a phone call convinces you to scan a code sent via text.

The defensive playbook doesn't change fundamentally: verify the source, preview the URL, and never authenticate through a link you didn't initiate.

Frequently Asked Questions

Can simply scanning a QR code infect my phone?

Scanning alone almost never installs malware directly. The risk comes from what happens next — visiting a malicious site, entering credentials, downloading an app, or approving a permission prompt. That said, if your phone's OS or browser is severely out of date, a scan could open a page that exploits an unpatched vulnerability, so keep everything updated.

How can I check where a QR code leads without opening it?

Both the default iOS Camera app and Google Lens on Android preview the full URL before opening it. Read the domain carefully — attackers rely on lookalike characters (like "rn" instead of "m") and unfamiliar top-level domains. You can also use dedicated QR-scanner apps that check links against threat intelligence databases before opening them.

Are QR codes in restaurants and cafés safe?

Usually yes, but not always. Check that the code isn't a sticker placed over another code, and be cautious if it asks you to log in, download an app, or enter payment details on a page you don't recognize. Legitimate menu QR codes should lead to a simple web page — nothing more.

What's the difference between quishing and smishing?

Smishing is phishing via SMS text messages — you receive a malicious link in a text. Quishing uses QR codes as the delivery mechanism, often in email, print, or physical settings. Both aim to steal credentials or money, but quishing is harder to detect because the URL is hidden inside an image.

Should businesses stop using QR codes altogether?

No — QR codes remain incredibly useful. The answer is to use them responsibly: generate codes through a reputable platform that supports link monitoring and revocation, print them on tamper-evident materials, and educate customers about how you'll (and won't) communicate with them. Abandoning QR codes would only push customers toward attackers' fake ones.

Final Thoughts

QR code phishing is effective because it exploits a gap in our security instincts. We've spent years learning to distrust suspicious links in emails, but we haven't yet built the same reflex around printed squares of black and white. Closing that gap — for yourself, your family, and your team — is the single most valuable thing you can do to stay ahead of quishing in 2026 and beyond.

Treat every QR code the way you'd treat a stranger handing you a login page: verify the source, preview the destination, and when in doubt, type the URL yourself.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles