facebook-pixel

QR Code Phishing Scams: How to Stay Safe in 2026

L
Lunyb Security Team
··10 min read

QR codes are everywhere in 2026 — on restaurant menus, parking meters, packaging, event tickets, and even utility bills. Their convenience has quietly made them one of the fastest-growing attack vectors for cybercriminals. This new wave of attacks, known as QR code phishing scams (or quishing), tricks people into scanning a malicious code that leads to fake login pages, malware downloads, or fraudulent payment requests.

This guide explains exactly how QR code phishing works, the most common scam patterns, and the practical steps you can take to keep your accounts, devices, and money safe.

What Are QR Code Phishing Scams?

QR code phishing scams are social engineering attacks that use a QR code to redirect victims to a malicious website, payment page, or app download. Because a QR code hides the actual destination URL behind a pattern of black-and-white squares, victims cannot see where the link goes until after they scan it — and often not even then.

The term quishing is a blend of "QR" and "phishing." Unlike traditional phishing emails, quishing bypasses many email security filters because the malicious URL is embedded inside an image, not written as text. That is why it has become a favorite technique of attackers in the last two years.

Why QR Codes Are Such an Effective Attack Tool

  • They hide the destination. You cannot preview a QR code URL the way you can hover over a link on a desktop.
  • They are trusted. People associate QR codes with legitimate businesses like restaurants, banks, and delivery services.
  • They are scanned on phones. Mobile browsers have smaller address bars, making fake domains harder to spot.
  • They bypass email filters. A QR code image inside a PDF or email often slips past spam detection.
  • They can be physically swapped. Attackers place stickers over legitimate codes in public places.

How a QR Code Phishing Attack Works

Most quishing attacks follow a predictable five-step pattern. Understanding this flow makes them much easier to spot.

  1. Attacker creates a fake landing page that mimics a bank, delivery service, workplace login, or payment portal.
  2. The URL is encoded into a QR code, often shortened or masked to look legitimate.
  3. The code is distributed via email, printed flyers, sticker overlays on real codes, parking meters, or fake invoices.
  4. The victim scans the code using their phone camera, which opens the malicious page in a mobile browser.
  5. Credentials, card details, or 2FA codes are harvested, or malware is silently downloaded.

The Most Common Types of QR Code Phishing Scams

1. Parking Meter and EV Charger Scams

Fraudsters print stickers with malicious QR codes and paste them over the legitimate payment codes on parking meters or electric vehicle chargers. Drivers scan, enter card details on a fake payment page, and lose money — sometimes with recurring charges added.

2. Fake Delivery Notifications

You receive a card in your mailbox or an email claiming a package could not be delivered. A QR code invites you to "reschedule" or "pay a customs fee." The link steals payment details and often your address for future scams.

3. Restaurant Menu Overlays

A criminal covers the legitimate menu QR code at a table with a sticker of their own. Customers scan expecting a menu but land on a phishing page asking to "log in with Google" or "pay a service fee."

4. Corporate Email Quishing

Employees receive an email that appears to come from IT, HR, or Microsoft 365. The email says they must scan a QR code to "verify their account" or "review a document." The code leads to a fake Microsoft or Okta login page that captures credentials and multi-factor codes.

5. Cryptocurrency Wallet Draining

Scammers post QR codes on social media claiming free tokens, airdrops, or giveaways. Scanning the code prompts the victim to connect their wallet — and signs a malicious transaction that empties it.

6. Fake Charity and Donation Codes

After natural disasters or during holiday seasons, criminals distribute fake charity QR codes in emails, flyers, and even on the streets. Donations flow directly to the attacker.

Real-World Examples of QR Code Phishing

Regulators and security firms have documented a sharp increase in quishing since 2023:

  • The FBI issued a public warning about tampered QR codes on parking meters in multiple U.S. cities.
  • UK's Action Fraud reported thousands of pounds lost per victim to fake parking payment sites.
  • Major security vendors reported that QR-code-based phishing emails to corporate inboxes grew by more than 400% in a single year.
  • Banks in Singapore, Germany, and Australia have issued alerts about fake banking QR codes distributed via SMS.

QR Phishing vs. Traditional Phishing: Key Differences

FeatureTraditional PhishingQR Code Phishing (Quishing)
Delivery methodEmail link, SMS, chatImage (QR code) in email, print, or public space
URL visibilityVisible before clickingHidden until after scan
Device targetedUsually desktop or mobileAlmost always mobile
Bypasses email filters?RarelyFrequently
Physical componentNoneOften uses stickers or printed materials
Detection difficultyModerateHigh

12 Ways to Protect Yourself from QR Code Phishing Scams

The good news is that most quishing attacks fail against informed users. Follow these habits to stay safe.

  1. Always preview the URL before opening. Modern iPhone and Android cameras show a URL preview before launching the browser. Read the domain carefully.
  2. Check for tampering. If a QR code is a sticker placed over another code — especially on parking meters, ATMs, or restaurant tables — do not scan it.
  3. Never enter credentials on a page reached via QR code. Instead, open the official app or type the website manually.
  4. Verify the domain character by character. Attackers use lookalikes like paypa1.com, micros0ft-login.com, or extra subdomains.
  5. Do not scan QR codes in unsolicited emails. Especially those claiming urgent account issues, missed deliveries, or IT verification.
  6. Use a trusted URL shortener with click analytics. Reputable shorteners like Lunyb allow you to preview and audit link destinations before sharing, reducing the risk of unknowingly spreading a malicious link.
  7. Enable phishing protection in your browser. Chrome's Safe Browsing, Safari's Fraudulent Website Warning, and Firefox's protection catch many known phishing sites.
  8. Keep your phone OS and browser updated. Many quishing kits rely on outdated mobile browsers.
  9. Use hardware security keys or passkeys. Even if attackers steal your password, they cannot replay a passkey login on a fake page.
  10. Turn on transaction alerts for your bank and credit cards. Instant SMS or push alerts help you catch fraudulent charges within seconds.
  11. Educate family members. Older relatives and children are frequently targeted with delivery and charity quishing scams.
  12. Report suspicious codes. Notify the business (restaurant, parking authority, bank) and file a report with your local cybercrime agency.

How Businesses Can Defend Against QR Code Phishing

Organizations face two threats: employees being tricked by quishing emails, and their own customers being deceived by fake versions of their branded QR codes.

For Employee Protection

  • Deploy email security tools that scan images and QR codes inside attachments.
  • Include quishing scenarios in phishing simulation training.
  • Enforce phishing-resistant multi-factor authentication (passkeys, FIDO2 keys).
  • Restrict corporate logins to managed devices where possible.
  • Block newly registered domains at the network level.

For Customer-Facing QR Codes

  • Use tamper-evident labels and laminate printed codes.
  • Use branded short links so customers can visually verify the domain (see our 2026 buyer's guide to URL shorteners for options).
  • Regularly inspect physical codes in public spaces for stickers or overlays.
  • Publish the official domain prominently near every QR code so users know what to expect.
  • Monitor for lookalike domains and typosquats.

The Role of URL Shorteners in QR Code Safety

URL shorteners are a double-edged sword in QR security. Attackers love them because a short link inside a QR code hides the destination even further. But legitimate businesses can use trustworthy shorteners with branded domains and analytics to make their codes more transparent, not less.

If you generate QR codes for marketing, events, or product packaging, use a shortener that:

  • Supports branded custom domains so customers recognize your name in the link.
  • Provides click analytics so you can spot unusual traffic patterns.
  • Allows you to edit or disable the destination if the code is ever compromised.
  • Has malware and phishing scanning at the redirect layer.

Platforms like Lunyb and other tools we cover in our Rebrandly review offer these protections and help legitimate senders stand out from scammers.

What to Do If You Scanned a Malicious QR Code

Acting quickly limits the damage. Follow these steps in order.

  1. Disconnect from the internet if you suspect malware — enable airplane mode.
  2. Do not enter any information on the page. Close the browser tab immediately.
  3. Change passwords for any accounts you may have exposed, starting with email and banking.
  4. Revoke active sessions in your Google, Apple, Microsoft, and social media accounts.
  5. Contact your bank if you entered card details. Ask them to freeze the card and reverse any transactions.
  6. Run a mobile antivirus scan from a reputable vendor.
  7. Enable a fraud alert with credit bureaus if you gave up personal identifiers.
  8. Report the incident to your national cybercrime authority (FTC in the US, Action Fraud in the UK, Scamwatch in Australia, etc.).

The Future of QR Code Phishing

QR code adoption is still growing, and so are the attacks. Expect these trends in 2026 and beyond:

  • AI-generated phishing pages that perfectly clone banks and workplaces in seconds.
  • Dynamic QR codes that change destination based on device, region, or time of day to evade scanners.
  • Deepfake-supported quishing where a fake video message includes a QR code from a "trusted" executive.
  • Hybrid attacks combining SMS (smishing) with QR codes to layer trust signals.

The defenses that work today — passkeys, verified domains, user awareness, and safer link infrastructure — will remain the strongest tools against these evolving threats.

Frequently Asked Questions

Can just scanning a QR code hack my phone?

Simply scanning a QR code will not install malware on a modern, up-to-date phone. The danger begins when you tap the link, enter information on the resulting page, or approve a download. Keep your OS updated, and always review the preview URL before opening it.

How can I tell if a QR code is fake?

Look for physical clues first: stickers placed over other codes, misaligned printing, or codes in unusual locations. After scanning, check the preview URL for misspellings, unusual domains, extra subdomains, or shortened links from unknown services. If anything looks off, do not proceed.

Are QR codes on restaurant menus safe?

Most are, but they are a growing target. Before scanning, glance at the code to make sure it is printed directly on the menu or laminated — not a loose sticker. If the resulting page asks you to log in with Google or pay a fee to view the menu, close it immediately.

Should I use a QR code scanner app instead of my camera?

Generally, no. The built-in camera apps on modern iPhones and Android phones are safer than most third-party scanner apps, which sometimes contain ads, trackers, or malware. Stick with your default camera and its URL preview feature.

What is the safest way to pay after scanning a QR code?

The safest path is to never enter card details on a page reached through a QR code you did not fully trust. Instead, open the official app of the merchant, bank, or parking provider and pay through it. If you must use the scanned page, verify the domain carefully and pay with a credit card that offers strong fraud protection.

Final Thoughts

QR code phishing scams succeed because they exploit trust and convenience — two things we rarely question in daily life. But with a few simple habits (previewing URLs, avoiding logins after scanning, using branded short links, and enabling passkeys), you can defuse almost every quishing attempt you encounter.

Whether you are an individual protecting your own accounts or a business protecting your customers, treat every QR code as an untrusted link until proven otherwise. That single mindset shift is the most powerful defense against this fast-growing threat.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles