facebook-pixel

QR Code Phishing Scams: How to Stay Safe in 2026

L
Lunyb Security Team
··9 min read

QR codes are everywhere in 2026 — on restaurant tables, parking meters, product packaging, event tickets, and even utility bills. Their convenience has made them a favorite target for cybercriminals. A new class of scam called QR code phishing, or quishing, is now one of the fastest-growing attack vectors worldwide. This guide explains exactly how QR code phishing scams work, how to spot them, and the practical steps you can take to stay safe.

What Are QR Code Phishing Scams?

QR code phishing (quishing) is a social engineering attack where criminals use malicious QR codes to redirect victims to fraudulent websites, trigger malware downloads, or trick them into revealing sensitive information. Because the destination URL is hidden inside a machine-readable image, victims cannot easily tell whether a code is safe before scanning it.

Unlike traditional phishing emails, quishing bypasses many corporate email filters and endpoint security tools. The QR image is often embedded in a PDF or displayed physically, so the malicious link never appears in plain text where security software can flag it.

Why QR Codes Are So Effective for Scammers

  • Trust by design: People associate QR codes with legitimate businesses and official processes.
  • Obscured destination: The URL is invisible until the code is scanned.
  • Mobile-first attack: Scans happen on phones, which often have weaker security than desktops.
  • Physical distribution: Attackers can print stickers and place them over real codes in public.
  • Low user awareness: Most people have never been trained to spot a malicious QR code.

How QR Code Phishing Attacks Work

Most quishing attacks follow a predictable pattern. Understanding the flow makes it much easier to identify and stop them.

  1. Preparation: The attacker registers a lookalike domain (for example, paypa1-secure.com) and builds a fake login or payment page that mirrors a legitimate brand.
  2. QR generation: They create a QR code that encodes this malicious URL, often shortened to hide the destination.
  3. Distribution: The code is sent via email, printed on flyers, placed as stickers over real codes, or posted on social media.
  4. Scan and redirect: The victim scans with their phone camera and is taken to the fraudulent site.
  5. Data theft: The victim enters credentials, card details, or personal information — which is captured by the attacker.
  6. Exploitation: Stolen data is used for account takeover, financial fraud, or sold on dark web marketplaces.

Common Types of QR Code Phishing Scams

1. Parking Meter and Transportation Scams

Fake QR stickers are placed on parking meters, EV chargers, or transit ticket machines. Victims think they are paying for parking but instead enter card details on a scammer's site. This scam has been reported in dozens of cities across the US, UK, and Europe.

2. Restaurant Menu Quishing

Attackers replace or overlay QR codes on restaurant tables. Instead of viewing the menu, customers land on a fake "loyalty program" or Wi-Fi login page designed to steal personal data.

3. Corporate Email Quishing

Employees receive an email that appears to come from HR, IT, or Microsoft, containing a QR code to "verify your account," "review a document," or "update your multi-factor authentication." Scanning takes them to a credential-harvesting page. This is the most common form of quishing in enterprise environments.

4. Package Delivery Notifications

Fake delivery notices — either physical postcards or emails — include a QR code to "reschedule delivery" or "pay a customs fee." The site asks for card details and personal information.

5. Cryptocurrency Wallet Scams

QR codes are commonly used to share crypto wallet addresses. Scammers substitute their own wallet code, causing victims to send funds directly to the attacker.

6. Charity and Donation Fraud

After major news events, criminals distribute QR codes claiming to raise money for victims. Donations go straight to the scammer's account.

Warning Signs of a Malicious QR Code

You can dramatically reduce your risk by learning to recognize the red flags before you scan.

  • Sticker over sticker: A QR code that appears to be pasted on top of another one, especially on parking meters or public signage.
  • Unsolicited emails: Any email containing a QR code that pressures you to act quickly ("verify within 24 hours").
  • Poor print quality or mismatched branding: Blurry logos, awkward fonts, or colors that don't match the real brand.
  • Requests for credentials after scanning: Legitimate businesses rarely ask you to log in via a QR code from an email.
  • Shortened or unfamiliar URLs: If the preview shows a strange domain, do not proceed.
  • HTTP instead of HTTPS: A missing padlock icon means the connection is not encrypted.
  • Typos in the domain name: Small character swaps like rn instead of m.

How to Stay Safe: 10 Practical Steps

  1. Preview the URL before opening. Modern iOS and Android cameras show the destination URL before you tap. Always read it carefully.
  2. Never scan codes from unsolicited emails. If your bank or employer needs you to take action, log in directly through their official app or website.
  3. Inspect physical codes for tampering. Look for stickers layered on top of the original, peeling edges, or codes that seem out of place.
  4. Type URLs manually when possible. For payments, especially parking, use the merchant's official app or type the URL yourself.
  5. Use a QR scanner with built-in URL checking. Some security apps warn you if a destination is on a known blocklist.
  6. Enable multi-factor authentication (MFA). Even if credentials are stolen, MFA can block account takeover. Prefer app-based or hardware key MFA over SMS.
  7. Keep your phone updated. Security patches close vulnerabilities that malicious sites might try to exploit.
  8. Use encrypted DNS or a privacy-focused browser. These can block connections to known phishing domains at the network level.
  9. Verify short links. Reputable link management platforms like Lunyb let recipients preview the destination before visiting, and they actively scan for malicious redirects. Learn more in our honest Lunyb review.
  10. Train your team. If you run a business, include quishing in your security awareness training and simulate quishing attacks periodically.

QR Code Phishing vs. Traditional Phishing: Key Differences

Attribute Traditional Phishing QR Code Phishing (Quishing)
Primary channel Email, SMS, chat Physical print, PDF, image in email
URL visibility Visible in message body Hidden inside an image
Device targeted Desktop and mobile Almost always mobile
Detected by email filters Often yes Rarely — image bypasses filters
User awareness Relatively high Low
Common goal Credential theft, malware Credential theft, payment fraud

What to Do If You've Scanned a Malicious QR Code

If you suspect you've fallen for a quishing scam, act quickly to limit the damage.

  1. Do not enter any more information. Close the page immediately.
  2. Disconnect from the internet if you suspect malware was downloaded.
  3. Change your passwords for any accounts you may have exposed, starting with email and banking.
  4. Enable MFA on all critical accounts if you haven't already.
  5. Contact your bank if you entered payment information. Ask them to monitor or freeze the card.
  6. Run a mobile security scan using a reputable app.
  7. Report the scam. In the US, file with the FTC (reportfraud.ftc.gov) and FBI IC3. In the UK, use Action Fraud. In the EU, contact your national CERT.
  8. Notify your employer if the code arrived through a work channel — they may need to alert other staff.

How Businesses Can Protect Employees and Customers

For Your Workforce

  • Include quishing scenarios in phishing simulations.
  • Deploy mobile threat defense (MTD) solutions on corporate devices.
  • Restrict scanning of QR codes on managed devices where practical.
  • Require MFA with phishing-resistant methods like FIDO2 hardware keys.

For Your Customers

  • Use tamper-evident printing for physical QR codes.
  • Publish official domains prominently and warn customers not to trust codes from other sources.
  • Choose a link management platform that offers link previews, malware scanning, and analytics. See our 2026 buyer's guide to URL shorteners for a comparison of the leading options, and read our Rebrandly review if you're weighing enterprise features.
  • Use branded short domains so customers can visually verify links.

The Future of QR Code Security

QR code usage will continue to grow, and so will the sophistication of quishing attacks. Expect to see more AI-generated phishing pages that adapt in real time, dynamic QR codes that change destination based on the scanner's device, and combined attacks that pair quishing with deepfake voice calls to add urgency.

On the defensive side, we'll see wider adoption of signed QR codes, browser-level warnings, and platform-level scanning of images inside emails. Regulatory bodies in the EU and North America are already drafting guidance on QR safety for consumer-facing businesses.

The bottom line: convenience and security must be balanced. A moment of caution before scanning is the single most effective defense you have.

Frequently Asked Questions

Can just scanning a QR code infect my phone?

Simply scanning a QR code and previewing the URL is generally safe. The risk begins when you open the link and either download a file, enter credentials, or your browser is exploited via an unpatched vulnerability. Keep your device updated and never install apps from unknown sources.

Are QR codes generated by well-known brands safe?

QR codes from reputable brands are usually safe, but the code itself is not proof of authenticity. Attackers can produce QR codes that look identical to legitimate ones. Always preview the destination URL and check that it uses the brand's official domain.

How can I check a QR code without scanning it on my phone?

You can use a decoder website on a desktop computer: upload or photograph the QR image and it will reveal the URL as text. This lets you inspect the link without your phone ever visiting it. Only use reputable decoder tools.

Why don't email filters catch QR phishing?

Traditional email security tools scan the text content and links inside emails. A QR code is an image, so the malicious URL is not readable by standard filters. Newer security platforms are beginning to include image analysis and OCR to detect quishing, but coverage is still inconsistent.

Is it safer to use my phone's camera or a dedicated QR scanning app?

For most users, the built-in camera on iOS or Android is the safest choice because it shows the destination URL before opening and doesn't require extra permissions. Many third-party scanner apps are laden with ads or trackers, and some have historically been caught redirecting through their own servers. Stick to your device's native scanner unless your organization provides a vetted enterprise tool.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles