facebook-pixel

QR Code Phishing Scams: How to Stay Safe in 2026

L
Lunyb Security Team
··10 min read

QR codes are everywhere in 2026 — on restaurant tables, parking meters, event posters, product packaging, and even utility bills. Their convenience has made them a favorite tool for businesses and, unfortunately, for cybercriminals. QR code phishing scams, often called "quishing," are one of the fastest-growing forms of social engineering, and they exploit the simple fact that you can't tell what a QR code contains until you scan it.

This guide breaks down exactly how QR code phishing works, the most common scams to watch for, and practical steps you can take to protect your accounts, your money, and your identity.

What Are QR Code Phishing Scams?

QR code phishing (quishing) is a type of cyberattack where criminals use malicious QR codes to trick people into visiting fake websites, downloading malware, or handing over sensitive information like passwords, payment details, or two-factor authentication codes. Because QR codes are machine-readable and opaque to the human eye, victims often scan them without any way to verify the destination in advance.

Unlike traditional phishing emails, QR code attacks bypass many email security filters. A QR code embedded as an image inside a PDF or email often passes right through URL scanners, because the malicious link isn't in plain text — it's encoded in a picture.

Why QR Codes Are So Effective for Attackers

  • They hide the destination URL. Users can't preview a link before scanning.
  • They shift the attack to mobile. Phones typically have fewer security tools than desktops.
  • They exploit trust. QR codes appear on official-looking materials — invoices, posters, packaging.
  • They bypass email filters. Image-based codes don't trigger link-scanning tools.
  • They feel modern and safe. Most users don't associate QR codes with fraud yet.

How a QR Code Phishing Attack Works

Most quishing attacks follow a predictable playbook. Understanding the steps helps you spot one before you become a victim.

  1. The lure. The attacker places a QR code somewhere you'll trust it — an email pretending to be from HR, a sticker over a legitimate parking meter code, a fake package delivery notice, or a poster in a public space.
  2. The scan. You point your phone camera at the code. Your device shows a shortened or unfamiliar URL, often one that looks close to a real brand (e.g., "microsft-login.com").
  3. The redirect. Tapping the link sends you to a convincing clone of a real login page, payment portal, or app store.
  4. The harvest. You enter credentials, card numbers, or one-time codes. The attacker captures them in real time and may immediately log in to your real account.
  5. The follow-up. Some scams also install spyware, drain crypto wallets, or use your stolen session cookies to bypass two-factor authentication.

The Most Common QR Code Phishing Scams

1. Fake Parking Meter and EV Charger Codes

Criminals print realistic stickers with malicious QR codes and paste them over legitimate ones on parking meters, EV chargers, and bike-share stations. Drivers scan, land on a fake payment page, and hand over credit card details. Cities across the US, UK, and Europe have reported hundreds of these cases.

2. "You Have a Package" Delivery Scams

A fake missed-delivery notice appears in your mailbox or inbox with a QR code to "reschedule." The code leads to a page that asks for a small redelivery fee — and captures your card details in the process.

3. Corporate Email Quishing

Employees receive an email supposedly from IT or HR: "Scan this QR code to review your updated benefits" or "Verify your Microsoft 365 account." Because the malicious URL is inside an image, corporate email filters often miss it. When the employee scans on their personal phone, corporate security tools have zero visibility.

4. Restaurant Menu Overlays

Attackers place stickers with malicious QR codes on top of legitimate menu codes. Diners scan expecting a menu and instead get a phishing page or a prompt to install a malicious "menu app."

5. Cryptocurrency Wallet Drainers

QR codes shared on social media promise airdrops, staking rewards, or NFT mints. Scanning connects your wallet to a malicious smart contract that drains your assets in one signature.

6. Fake Charity and Donation Codes

After natural disasters, scammers distribute posters and flyers with QR codes claiming to collect donations for real charities. The money goes straight to the attacker.

QR Code Phishing vs. Traditional Phishing

FeatureTraditional PhishingQR Code Phishing (Quishing)
Delivery methodEmail, SMS, chat linksPhysical signs, images, PDFs, emails
URL visibilityVisible before clickingHidden until scanned
Device targetedMostly desktopMostly mobile
Email filter detectionHighLow (image-based)
User awarenessGrowingStill low
Common defenseLink scanners, trainingCautious scanning, URL preview

Warning Signs of a Malicious QR Code

Before you scan, look for these red flags:

  • Stickers layered on top of other codes. Peel gently — if there's another code underneath, walk away.
  • Codes on unsolicited mail, flyers, or emails urging urgent action ("Your account will be closed in 24 hours").
  • No brand context. A QR code by itself with no logo, no explanation, and no printed URL alternative.
  • Requests to install an app from outside the official App Store or Google Play.
  • Payment or login requests immediately after scanning, especially on unfamiliar domains.
  • Slightly misspelled domains after the redirect (paypa1.com, arnazon-pay.net).
  • Codes distributed through unexpected channels — a QR on a printed "invoice" from a service you never signed up for.

How to Stay Safe: 10 Practical Steps

  1. Preview the URL before tapping. Modern iOS and Android cameras display the URL when you hover over a QR code. Read it carefully before opening.
  2. Never scan codes from unsolicited emails or physical mail. If your bank, HR, or a delivery service needs you to log in, go directly to their official app or website.
  3. Check for sticker tampering on public codes — parking meters, menus, posters, and charging stations are all common targets.
  4. Type sensitive URLs manually. For anything involving payment or login, don't rely on a QR code. Type the address yourself.
  5. Use a browser with phishing protection. Chrome, Safari, Firefox, and Brave all warn about known malicious sites. Keep these warnings enabled.
  6. Enable multi-factor authentication everywhere, ideally with an authenticator app or hardware key rather than SMS.
  7. Keep your phone updated. OS updates patch vulnerabilities that malicious pages try to exploit.
  8. Never install apps from links. Only install from official app stores, and check reviews and publisher names.
  9. Use encrypted DNS (like Cloudflare's 1.1.1.1 for Families or Quad9). These services block known phishing and malware domains at the network level.
  10. Trust your instincts. If something feels off — urgency, odd wording, unexpected payment requests — close the page and verify through a separate, trusted channel.

How to Verify a Shortened Link Safely

QR codes almost always contain shortened URLs, which makes verification harder. Before opening a suspicious link, you can use a URL expander or a link-inspection tool to see the final destination without visiting the page.

Reputable link management platforms like Lunyb provide transparent, scannable links with click analytics and — for creators and businesses — the ability to build branded short URLs your audience can actually recognize. Using a trusted shortener for your own QR campaigns also helps your customers distinguish real codes from spoofed ones. If you're evaluating shortener services for a business use case, our 2026 buyer's guide to URL shorteners compares the leading options.

Protecting Your Business from Quishing Attacks

Organizations face a growing wave of QR-based attacks aimed at employees. Here's how to defend your team.

Employee Training

  • Add quishing examples to your regular phishing awareness training.
  • Run simulated QR phishing tests to measure and improve awareness.
  • Establish a clear reporting channel for suspicious codes.

Technical Controls

  • Deploy email security that scans images and extracts QR code URLs (many next-gen gateways now do this).
  • Use mobile device management (MDM) to enforce browser security and app installation policies.
  • Enable phishing-resistant authentication (FIDO2 security keys, passkeys) so stolen passwords alone aren't enough.
  • Deploy DNS filtering across corporate networks and remote devices.

Brand Protection

  • Always pair your QR codes with a printed URL and short explanation.
  • Use branded short links (e.g., yourbrand.link/promo) so customers recognize legitimate destinations. Services like Rebrandly and Bitly are common in this space — see our Rebrandly review for a deeper look — and free alternatives like Lunyb (honest review here) work well for smaller campaigns.
  • Monitor for spoofed domains that impersonate your brand.

What to Do If You've Scanned a Malicious QR Code

If you suspect you've fallen for a QR phishing scam, act quickly:

  1. Disconnect from the internet if you downloaded anything suspicious. Turn on airplane mode.
  2. Do not enter any additional information on the page. Close the browser tab immediately.
  3. Change passwords on any accounts you may have exposed, starting with email and banking.
  4. Revoke active sessions in your account settings for services like Google, Microsoft, and Apple.
  5. Contact your bank if you entered payment details. Freeze or replace the card.
  6. Enable or reset multi-factor authentication using an authenticator app.
  7. Run a mobile security scan using a reputable app to check for malware.
  8. Report the scam to your local cybercrime authority (FTC in the US, Action Fraud in the UK, Scamwatch in Australia) and to the brand that was impersonated.

The Future of QR Code Security

QR codes aren't going away — they're too useful for payments, ticketing, menus, and marketing. Expect to see more security features built directly into scanning apps, including automatic URL reputation checks, warning banners for newly registered domains, and cryptographic signing of legitimate codes by trusted brands.

Until those protections become universal, the responsibility falls on individuals and organizations to scan skeptically, verify URLs, and treat every unexpected QR code with the same caution you'd give a suspicious email link.

Frequently Asked Questions

Can just scanning a QR code infect my phone?

Simply scanning a QR code is generally safe — the danger comes from what happens after you tap the link. Modern smartphones don't automatically execute code from a QR scan. However, if you tap the link and visit a malicious page, you could be prompted to download malware, enter credentials, or trigger a browser exploit on an outdated device. Always preview the URL first and never open unfamiliar links.

How can I tell if a QR code is fake in public?

Look for signs of tampering: stickers layered over other codes, poorly aligned print, or codes that don't match the surrounding branding. On parking meters, menus, and posters, legitimate codes are usually integrated into the printed design, not stuck on top. If in doubt, use the official app or website of the business instead.

Are QR codes in emails safe?

QR codes in emails should be treated with extreme suspicion, especially if they ask you to log in, verify an account, or make a payment. Attackers use them specifically to bypass email link scanners. If a message really is from your bank or employer, you can always log in through the official app or website directly instead of scanning.

What's the safest QR code scanner app?

The built-in camera apps on iPhone and modern Android devices are generally the safest choice because they show a URL preview before opening the link and receive regular security updates. Avoid third-party "QR scanner" apps loaded with ads — many have poor privacy practices and some have historically contained malware.

Should businesses stop using QR codes because of quishing?

No — QR codes remain highly valuable for customer engagement, contactless payments, and marketing. Instead, businesses should use branded short domains, always pair codes with a visible URL, educate customers about verifying destinations, and monitor for impersonation. Well-implemented QR campaigns give users more trust signals, not fewer.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles