facebook-pixel

QR Code Phishing Scams: How to Stay Safe in 2026

L
Lunyb Security Team
··9 min read

QR codes are everywhere in 2026 — on restaurant menus, parking meters, product packaging, event tickets, and even utility bills. Their convenience has made them a favorite tool of cybercriminals, who now exploit them in a growing attack category known as QR code phishing scams, or "quishing." This guide explains exactly how these scams work, how to spot them, and what steps you can take to keep your data, money, and identity safe.

What Are QR Code Phishing Scams?

QR code phishing scams (quishing) are attacks in which criminals embed malicious links inside QR codes to trick victims into visiting fake websites, downloading malware, or handing over sensitive information. Because a QR code looks like a harmless black-and-white square, users cannot see the destination URL until after they scan it — and by then, damage may already be done.

Unlike traditional email phishing, quishing bypasses many corporate security filters. Email gateways scan text and links but often ignore images, so a QR code embedded in an image sails right past detection. Once scanned on a personal smartphone, the target is outside the protection of any corporate firewall.

Why QR Code Attacks Are Exploding

  • Post-pandemic normalization: Contactless menus, payments, and check-ins have trained people to scan codes without hesitation.
  • Mobile-first targets: Phones typically have weaker security controls than corporate laptops.
  • Hidden destinations: Users cannot preview a URL the way they can hover over a hyperlink.
  • Cheap to deploy: Attackers can print stickers and place them over legitimate codes in seconds.

How QR Code Phishing Attacks Work

A typical quishing attack follows a predictable five-step process:

  1. Attacker creates a malicious landing page that mimics a trusted brand — a bank login, a parking payment portal, or a package delivery form.
  2. They generate a QR code pointing to that page, often using a shortened URL to further disguise it.
  3. They distribute the code via email attachments, printed flyers, stickers placed over real QR codes, or fake signage in public places.
  4. A victim scans the code with their smartphone camera and is redirected to the fraudulent site.
  5. The victim enters credentials, payment details, or personal information — which is instantly harvested by the attacker.

Common QR Code Scam Variations

  • Parking meter fraud: Fake QR stickers placed on real meters redirect drivers to bogus payment pages.
  • Email quishing: A message claims a document, voicemail, or MFA request requires scanning an attached QR code.
  • Restaurant menu swaps: Criminals paste malicious codes on top of legitimate menu QR codes.
  • Package delivery scams: A "missed delivery" flyer left at your door invites you to scan and reschedule.
  • Cryptocurrency donation scams: Fake charities or investment offers use QR codes that send crypto directly to attacker wallets.
  • Utility bill fraud: Letters claiming overdue payments include QR codes that lead to fake payment portals.

Real-World QR Code Phishing Examples

Understanding how quishing looks in practice makes it easier to recognize. Here are three widely documented patterns from 2024–2026:

1. The Fake Multi-Factor Authentication Email

Employees receive a message claiming their Microsoft 365 password has expired. To "re-authenticate," they must scan a QR code with their phone. The code leads to a pixel-perfect Microsoft login clone that captures credentials and MFA tokens in real time, allowing attackers to log in immediately.

2. The Parking Meter Sticker Scam

Cities across North America, Europe, and Australia have reported waves of fraudulent QR stickers placed over legitimate ones on parking meters. Drivers scan, enter card details on a fake portal, and lose money instantly. Some variants also install spyware apps disguised as "parking helper" downloads.

3. The Physical Mail Bank Scam

Victims receive a professional-looking letter appearing to come from their bank warning about "suspicious activity." A QR code invites them to verify their account. Scanning leads to a phishing page that harvests banking credentials, ID numbers, and security question answers.

Warning Signs of a Malicious QR Code

Before scanning any QR code, run through this quick checklist:

Red FlagWhat It Looks LikeRisk Level
Sticker over another codeBumps, peeling edges, mismatched print qualityHigh
Unsolicited email with QR code"Urgent" message asking you to scan for MFA, payroll, HR docsHigh
QR code in public with no brandingLoose flyer, unbranded sign, sticker on a lamppostHigh
Shortened URL after scanningPreview shows bit.ly, tinyurl, or unfamiliar domainMedium
Urgency or fear language"Pay within 24 hours to avoid fines"High
Request for login or paymentAny credential form after scanningCritical

10 Ways to Stay Safe from QR Code Phishing

Follow these practical habits every time you encounter a QR code:

  1. Preview the URL before opening it. Modern iOS and Android cameras display the destination link before you tap. Read it carefully — check for typos like "paypa1.com" or "bank-secure-login.co".
  2. Never scan codes from unsolicited emails. Legitimate companies almost never require QR scanning to log in.
  3. Inspect physical codes for tampering. Look for stickers layered over printed codes, especially on parking meters, ATMs, and public signs.
  4. Type known URLs manually. For banks, government sites, and payment portals, go directly to the official website instead of scanning.
  5. Avoid downloading apps from QR codes. Only install apps from official app stores.
  6. Enable phishing protection in your browser. Safari, Chrome, Firefox, and Edge all offer built-in warnings for known malicious sites — keep them on.
  7. Use trusted link shorteners only. If you must click a shortened link, use expander tools or platforms like Lunyb that publish transparent security practices and provide link previews.
  8. Keep your phone's OS updated. Many quishing payloads rely on unpatched mobile vulnerabilities.
  9. Use MFA that is not tied to QR scans. Prefer hardware keys or authenticator apps over SMS or scan-based flows.
  10. Report suspicious codes. Alert the property owner, your bank, or local authorities when you spot fraudulent codes in the wild.

How Businesses Can Defend Against Quishing

Organizations face amplified risk because a single scanned code can lead to a full network breach. Effective defense requires a mix of technology and training.

Technical Controls

  • Image-aware email security: Deploy filters that extract and analyze QR codes embedded in attachments and images.
  • Mobile device management (MDM): Restrict which browsers and apps can process scanned links on corporate devices.
  • DNS filtering: Block known malicious domains at the network layer so even a scanned link cannot resolve.
  • Zero-trust access: Require device posture checks before granting access to sensitive apps, even after successful login.
  • Branded link management: Use trusted shortening platforms with click analytics and revocation. Compare options in our 2026 URL shortener buyer's guide.

Human Controls

  • Include QR phishing scenarios in security awareness training.
  • Run simulated quishing campaigns to test employee readiness.
  • Establish a clear reporting channel for suspicious codes.
  • Ban unauthorized printing of QR codes on customer-facing materials without security review.

QR Code Phishing vs. Traditional Phishing

Understanding the differences helps security teams tune defenses accordingly:

AttributeTraditional PhishingQR Code Phishing (Quishing)
Primary channelEmail, SMSPhysical signage, embedded images, email attachments
Target deviceDesktop / laptopPersonal smartphone
Link visibilityVisible before click (hover)Hidden until scanned
Detection by email filtersStrongWeak — codes evade text scanners
User exposure to corporate defensesFull protectionOften bypasses corporate network
Attack costLowVery low (stickers, images)

What to Do If You Scanned a Malicious QR Code

If you suspect you have fallen victim to a quishing attack, act quickly:

  1. Disconnect from Wi-Fi and mobile data if you downloaded anything unusual.
  2. Do not enter any information on the destination page — close the browser tab immediately.
  3. Change passwords for any account you may have entered credentials into, starting with email and banking.
  4. Enable or reset multi-factor authentication on affected accounts.
  5. Contact your bank to freeze cards or dispute charges if payment details were shared.
  6. Run a mobile security scan using a reputable antivirus app.
  7. Report the incident to your national cybercrime authority (e.g., IC3 in the US, Action Fraud in the UK, ACSC in Australia).
  8. Monitor your credit for signs of identity theft in the following months.

The Future of QR Code Security

QR code phishing will continue evolving as attackers experiment with dynamic codes, AI-generated fake brands, and hybrid attacks that combine QR scans with deepfake voice calls. Expect to see:

  • Signed QR codes: Emerging standards that cryptographically verify code authenticity.
  • Camera-level warnings: Native OS features that flag known malicious destinations before users tap.
  • Regulatory pressure: Rules requiring businesses to secure customer-facing QR codes with tamper-evident designs.
  • Better link intelligence: URL shorteners increasingly offering phishing detection at the redirect layer.

Until these defenses mature, awareness remains your strongest tool. Every scan is a decision — treat it with the same caution as clicking a link in an unsolicited email.

Frequently Asked Questions

Can simply scanning a QR code infect my phone?

Scanning alone rarely installs malware, because a QR code is just a container for text or a URL. The real risk begins when you tap the resulting link, download an app, or enter data on a fraudulent page. However, some attackers do exploit browser vulnerabilities on outdated phones, so keeping your OS updated is essential.

How can I preview a QR code's link before opening it?

Both iOS and Android show a preview of the destination URL when you scan with the native camera app. Do not tap the notification until you have read the domain carefully. If your camera does not preview links, adjust settings or use a reputable QR reader app that always displays URLs before opening them.

Are QR codes in restaurants safe?

Most restaurant QR codes are legitimate, but they are a common target for sticker overlay attacks. Before scanning, check whether the code looks like a printed part of the menu or a separately applied sticker. If in doubt, ask staff for the direct website address or a paper menu.

Do shortened URLs make QR codes more dangerous?

Shortened URLs can hide the true destination, which attackers exploit. However, reputable shortening services scan destinations for malicious content and offer link previews. When creating your own QR campaigns, choose a transparent provider — you can compare options in our URL shortener buyer's guide or read our Rebrandly review for feature-by-feature analysis.

What should businesses print on customer-facing QR codes to build trust?

Add clear branding, a short human-readable URL next to the code, and a tamper-evident laminate or seal. Consider using a branded short domain so customers can visually confirm the destination. This transparency reduces both fraud risk and customer hesitation to scan.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles