facebook-pixel

QR Code Phishing Scams: How to Stay Safe in 2026

L
Lunyb Security Team
··10 min read

QR codes have quietly become one of the most convenient ways to move information from the physical world to a phone. They pay parking meters, open restaurant menus, log people into Wi-Fi, and authenticate banking apps. But that same convenience has created a new attack surface that criminals are exploiting at scale: QR code phishing scams, also known as "quishing."

This guide breaks down exactly how these scams work, where they show up, and the practical habits that keep you and your organization safe.

What Are QR Code Phishing Scams?

QR code phishing scams are attacks in which a threat actor uses a QR code to trick a victim into visiting a malicious website, downloading malware, or handing over sensitive information. The QR code acts as a disguise: unlike a suspicious link, a black-and-white square gives no visual clue about where it leads.

The term "quishing" is a blend of "QR" and "phishing." It has exploded since 2022 because QR codes bypass many traditional email and web filters. A security gateway can scan a link in an email body, but it often cannot read the URL embedded inside an image of a QR code. That gap is exactly what attackers exploit.

Why QR Codes Are So Effective for Attackers

  • Opaque destinations: Users cannot preview the URL before scanning.
  • Mobile-first: Scans usually happen on phones, which have smaller screens and fewer security tools than desktops.
  • Trust by context: A QR code on a poster, invoice, or menu feels legitimate because of where it is placed.
  • Filter evasion: Images sail past most email security engines.
  • Easy to deploy: Anyone can generate a QR code in seconds and print it on a sticker.

How a Typical QR Code Phishing Attack Works

Most quishing campaigns follow a predictable five-step pattern. Understanding it makes the red flags much easier to spot.

  1. Lure creation: The attacker builds a convincing pretext, such as a parking ticket, package delivery notice, HR document, or multi-factor authentication reset.
  2. QR code generation: A QR code is generated pointing to a lookalike domain (for example, a Microsoft 365 login clone).
  3. Distribution: The code is delivered via email attachment, PDF, printed flyer, sticker over a legitimate code, or SMS.
  4. Scan and redirect: The victim scans, lands on a phishing page, and enters credentials, card details, or one-time passcodes.
  5. Exploitation: The attacker uses those credentials to access accounts, move laterally in a corporate network, or resell the data.

Common Types of QR Code Phishing Scams

1. Fake Parking and Traffic Fines

Fraudsters print convincing citations and place them on windshields or on parking meters, instructing drivers to scan and pay. The QR code opens a card-skimming page that mirrors the city's real payment portal.

2. Restaurant Menu Overlays

Attackers stick a malicious QR code sticker directly over the legitimate one on a table tent or menu. Customers scan expecting a menu and instead land on a page requesting a "service fee" payment or app download.

3. Corporate Email Quishing

Employees receive an email that appears to be from IT, HR, or a benefits provider, containing a QR code to "reactivate multi-factor authentication" or "review a document." The code leads to a credential harvesting page tuned for Microsoft 365 or Google Workspace.

4. Fake Package Delivery Notices

A physical postcard or SMS claims a delivery attempt failed and asks the recipient to scan a QR code to reschedule. The destination is a phishing site that collects address details and a small "redelivery fee."

5. Cryptocurrency Wallet Drainers

Codes posted in public places or shared on social media promise airdrops or free tokens. Scanning connects a wallet to a malicious contract that drains funds instantly.

6. Charity and Donation Fraud

After disasters, scammers post flyers and social ads with QR codes leading to fake donation pages that impersonate well-known charities.

Warning Signs That a QR Code May Be Malicious

Before you scan, run through this mental checklist. Any single red flag should make you pause; two or more should stop you completely.

  • The QR code is on a sticker that appears to be placed over another code.
  • The code arrived in an unexpected email, especially one that pressures you to act fast.
  • The surrounding message uses urgency: "account will be closed," "final notice," "payment overdue."
  • The email contains only an image with almost no text (a common evasion tactic).
  • The preview URL uses a strange top-level domain or long random subdomain.
  • You are asked to log in, install an app, or approve a wallet connection right after scanning.
  • The page requests multi-factor codes, recovery phrases, or full card details.

How to Safely Scan a QR Code

You do not need to swear off QR codes; you just need a safer scanning routine.

  1. Use your phone's built-in camera instead of third-party scanner apps, which sometimes bundle adware or open links automatically.
  2. Preview the URL before tapping. Both iOS and Android show the destination as a banner or notification. Read the full domain, not just the first few characters.
  3. Check the domain carefully. Watch for typos, extra hyphens, and lookalike characters (rn vs m, 0 vs O).
  4. Never enter credentials on a page you reached through a QR scan. Open the app or type the official URL directly.
  5. Avoid installing apps from a link produced by a scan. Go to the official app store and search for the app manually.
  6. Use a reputable link checker if you are unsure. Pasting the previewed URL into a URL inspection tool can reveal redirects and known phishing indicators.

Quishing vs. Traditional Phishing: A Quick Comparison

FeatureTraditional PhishingQR Code Phishing (Quishing)
Delivery channelEmail links, SMS, chatEmail images, printed materials, stickers, SMS
Visibility of URLUsually visible on hoverHidden until scanned
Device targetedDesktop and mobileAlmost always mobile
Detection by email filtersHighLow (image-based)
Physical world attacksRareCommon (stickers, flyers, posters)
Common goalCredential theft, malwareCredential theft, payment fraud, wallet draining

Protecting Your Business From QR Code Phishing

Individuals can dodge most attacks with awareness, but organizations need layered defenses because a single compromised employee can lead to a full breach.

1. Update Security Awareness Training

Add quishing-specific modules that include real screenshots, printed sticker examples, and simulated QR phishing tests. Employees who have only seen link-based phishing training will not recognize the new format.

2. Deploy Image and OCR Scanning in Email

Modern email security tools can decode QR codes inside attachments and inline images, extract the URL, and evaluate it against threat intelligence feeds. Confirm your provider has this capability enabled.

3. Enforce Phishing-Resistant MFA

Hardware security keys and passkeys defeat most credential-harvesting sites even if an employee submits their password. This is one of the highest-leverage controls you can deploy.

4. Control Corporate QR Code Usage

Standardize on a single trusted platform for generating official QR codes. Publish a short-domain policy so employees, customers, and partners know what a real company link looks like. A branded, transparent shortener such as Lunyb can help by producing consistent short URLs behind your QR codes, giving recipients a recognizable domain to verify against.

5. Monitor Physical Locations

If your business displays QR codes in public (menus, posters, payment terminals), inspect them regularly for stickers or tampering. Consider using tamper-evident labels.

6. Log and Analyze Scans

Trackable short links behind QR codes give you scan analytics. Sudden spikes, geographic anomalies, or scans from unexpected user agents can signal that your code has been cloned or abused.

What to Do If You Scanned a Malicious QR Code

Do not panic. Simply landing on a phishing page rarely causes harm on its own. The damage usually happens when you enter data or approve something.

  1. Close the page immediately without tapping any buttons.
  2. Do not install any prompted app or profile. If one installed automatically, remove it from Settings.
  3. If you entered credentials, change that password everywhere it was reused and enable phishing-resistant MFA.
  4. If you entered card details, call your bank, freeze the card, and dispute any charges.
  5. If you connected a crypto wallet, transfer remaining assets to a new wallet with a fresh seed phrase.
  6. Report the incident. Notify your IT team, the impersonated brand, and local consumer protection or cybercrime authorities.
  7. Run a mobile security scan with a reputable tool if you are worried about malware.

The Role of URL Shorteners in QR Code Safety

URL shorteners are a double-edged sword in the quishing conversation. Attackers sometimes use free shorteners to hide destinations, but reputable, branded shorteners actually improve safety by providing:

  • Consistent domains customers can learn to trust.
  • Scan analytics that make abuse detection possible.
  • The ability to disable a link if a printed QR code is compromised, without reprinting materials.
  • Malware and phishing filtering at the redirect layer.

If you are evaluating providers, our 2026 buyer's guide to URL shorteners compares the leading options across security features, analytics, and pricing. For a deeper look at specific tools, see our Rebrandly review and our honest review of Lunyb.

Best Practices Checklist for Everyday Users

  • Treat unexpected QR codes the way you would treat unexpected email links.
  • Always preview the URL before tapping.
  • Type sensitive URLs (banking, work login) manually rather than scanning.
  • Keep your phone's operating system and browser up to date.
  • Enable phishing-resistant MFA on every important account.
  • Use a password manager so credentials only autofill on the real domain.
  • Avoid scanning codes on stickers in public unless you can verify the source.

Frequently Asked Questions

Can simply scanning a QR code infect my phone?

In almost all cases, no. Scanning only shows you the destination URL. The risk begins when you tap the link and interact with the resulting page, install an app, or approve a permission prompt. Keeping your phone updated and previewing URLs before tapping mitigates the vast majority of risk.

Are QR codes on official documents like bank statements safe?

Usually yes, but treat them with the same caution as email links. Attackers have been known to intercept mail or overlay stickers on printed statements. When possible, log into your bank by typing the URL or opening the official app rather than scanning.

How can I tell if a QR code sticker has been tampered with?

Look for a second sticker layered over an original, misaligned edges, a code that looks freshly printed on cheap paper attached to an otherwise professional sign, or a URL preview that does not match the business you are dealing with. When in doubt, ask staff to confirm the code.

Do email security tools catch quishing attempts?

Increasingly, yes. Leading email security platforms now perform optical character recognition on inline images and attachments to decode QR codes and evaluate the embedded URLs. Older or basic filters, however, still miss them. Confirm with your provider that QR decoding is enabled and complement it with user training.

Should businesses stop using QR codes because of quishing?

No. QR codes remain a powerful engagement tool. The right response is to use a trusted, branded short URL under your control, monitor scan activity, protect physical codes from tampering, and educate customers on what your legitimate links look like. A managed shortener with analytics, like Lunyb, makes this dramatically easier.

Final Thoughts

QR code phishing scams work because they exploit a small blind spot in how we evaluate trust: we scan first and think later. Closing that gap does not require avoiding QR codes entirely. It just requires the same skepticism you already apply to email links: preview the destination, question the context, and never enter sensitive data on a page you reached through an unverified scan.

For businesses, the takeaway is clear. Combine phishing-resistant authentication, image-aware email filtering, tamper checks on physical codes, and a branded short-link strategy. Quishing will keep evolving, but organizations that treat QR codes as a first-class security concern will stay well ahead of the curve.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles