facebook-pixel

QR Code Phishing Scams: How to Stay Safe in 2026

L
Lunyb Security Team
··10 min read

QR codes are everywhere in 2026 — on restaurant tables, parking meters, product packaging, event posters, and email signatures. Their convenience has made them a favorite tool for marketers, but it has also made them one of the most effective weapons in a cybercriminal's arsenal. Welcome to the era of QR code phishing scams, also known as quishing.

This guide explains exactly how QR code phishing scams work, why they bypass traditional security filters, and — most importantly — how to protect yourself, your family, and your organization from becoming the next victim.

What Are QR Code Phishing Scams?

QR code phishing scams (quishing) are attacks in which criminals embed malicious URLs inside QR codes to trick victims into visiting fraudulent websites, downloading malware, or handing over credentials, payment information, or personal data. Because the destination URL is hidden inside a pixelated image, the victim cannot see where the link actually leads until it's too late.

Unlike traditional phishing emails, quishing attacks weaponize a physical or visual element — a printed sticker, a PDF attachment, or an image in an email — which allows them to slip past most email security gateways that scan for suspicious text links.

Why QR Code Phishing Exploded

Three factors made 2024–2026 the golden age of quishing:

  1. Post-pandemic normalization — People became conditioned to scan QR codes for menus, tickets, and payments without a second thought.
  2. Security gap — Most corporate email filters cannot read text inside images, so a QR code embedded in a PNG or PDF bypasses URL reputation scanners.
  3. Mobile trust — Scans happen on personal phones, which typically have weaker security controls than corporate desktops.

How a QR Code Phishing Attack Works

Almost every quishing scam follows the same five-step pattern:

  1. Lure creation — The attacker designs a convincing pretext: a fake parking fine, a package delivery notice, a Microsoft 365 authentication request, or a restaurant menu.
  2. QR code generation — A malicious URL is encoded into a QR code, often shortened or disguised to look like a trusted brand.
  3. Distribution — The code is placed on a physical surface (sticker over a real code), sent via email, printed on flyers, or shared on social media.
  4. Scan and redirect — The victim scans with their phone camera and is taken to a spoofed login page, a fake payment portal, or a malware download.
  5. Data harvest — Credentials, credit card numbers, or one-time passcodes are captured and immediately used for account takeover or fraud.

Real-World Examples of QR Code Phishing

1. The Parking Meter Scam

In cities across the US, UK, and Australia, criminals have placed counterfeit stickers over legitimate parking meter QR codes. Drivers scan, enter their card details on a spoofed payment page, and lose hundreds of dollars — while their car still gets ticketed.

2. Microsoft 365 Credential Theft

Employees receive an email claiming their multi-factor authentication needs to be re-enrolled. The email contains a QR code — bypassing email URL scanners — that leads to a perfect clone of the Microsoft login page.

3. Fake Delivery Notifications

A printed "missed delivery" card is left on the door with a QR code to "reschedule." The link installs banking trojans on Android devices or harvests card data on iOS.

4. Restaurant Menu Overlays

Attackers place sticker QR codes on top of restaurant menus. Diners are directed to a fake "pay your bill" page that steals payment information.

5. Crypto Wallet Drainers

QR codes on posters, YouTube thumbnails, or Twitter posts promise airdrops or NFT mints but connect victims' wallets to drainer contracts.

Why QR Code Phishing Bypasses Traditional Security

Security LayerTraditional Phishing LinkQR Code Phishing
Email URL scannerBlocks known bad URLsCannot read URLs inside images
Corporate web proxyFilters browsing on company networkScan happens on personal mobile data
Endpoint protectionWarns on suspicious downloadsMobile endpoints often unprotected
User awarenessUsers trained to hover over linksNo hover option on QR codes
Multi-factor authenticationBlocks credential-only theftReal-time proxy pages steal MFA tokens

Warning Signs of a Malicious QR Code

Before you scan any QR code, look for these red flags:

  • Stickers layered over other codes — Check whether a QR code has been placed on top of another. Peel back a corner if you can.
  • Unsolicited codes in email — Legitimate companies rarely require you to scan a QR code from your phone to log into a work account.
  • Urgency or fear language — "Your account will be suspended in 24 hours — scan to verify."
  • Codes in public places with no branding — A random QR code taped to a lamppost is almost never safe.
  • Shortened or misspelled preview URLs — Modern phone cameras show the URL before opening it. Read it carefully.
  • Requests for credentials after scanning — A menu should never ask for your Microsoft password.

10 Ways to Stay Safe From QR Code Phishing Scams

1. Always Preview the URL Before Opening

Modern iOS and Android cameras display the destination URL as a preview. Read the entire domain — not just the beginning. Attackers use lookalikes such as micros0ft-login.com or paypa1-secure.net.

2. Never Enter Credentials After a QR Scan

Treat any login page reached through a QR code with extreme suspicion. Instead, close the page and log in directly through your bookmarked URL or official app.

3. Inspect Physical QR Codes for Tampering

Before scanning parking meters, menus, or posters, check for stickers layered over the original. Legitimate QR codes are usually printed directly onto the surface.

4. Use a QR Scanner With Built-in URL Reputation

Several security-focused scanner apps check destination URLs against threat intelligence databases before opening them. This adds a critical extra layer beyond your camera's built-in preview.

5. Enable DNS-Level Filtering on Your Phone

Encrypted DNS services with malware and phishing protection (such as Cloudflare 1.1.1.1 for Families, NextDNS, or Quad9) will block known malicious domains at the network level — even if you accidentally tap a bad link.

6. Keep Your Mobile OS and Browser Updated

Many quishing payloads exploit unpatched mobile browser vulnerabilities. Enable automatic updates on iOS and Android.

7. Use Passkeys and Phishing-Resistant MFA

Passkeys and hardware security keys (FIDO2/WebAuthn) cannot be phished — even by a real-time proxy site — because they cryptographically bind to the legitimate domain.

8. Verify Emails With QR Codes Out of Band

If an email from IT asks you to scan a QR code, call or message the sender through a trusted channel first. Attackers count on you not verifying.

9. Use a Trusted Link Shortener for Your Own Campaigns

If you generate QR codes for marketing or business, use a reputable link management platform like Lunyb that provides branded short links, click analytics, and the ability to disable or replace destinations if a code is abused. You can learn more in our honest review of Lunyb or compare options in our 2026 buyer's guide to URL shorteners.

10. Train Your Team Regularly

Organizations should run quishing simulations alongside traditional phishing training. Employees who have never seen a quishing attempt are far more likely to fall for one.

What to Do if You've Scanned a Malicious QR Code

If you suspect you've been targeted, act quickly:

  1. Disconnect from the internet — Enable airplane mode to stop any active data exchange.
  2. Do not enter any information — If you're already on the page but haven't submitted anything, close the tab immediately.
  3. Change passwords — If you entered credentials, change them right away on a different, trusted device. Start with email and financial accounts.
  4. Revoke active sessions — In your account security settings, sign out of all devices.
  5. Contact your bank — If you entered payment details, freeze the card and dispute any transactions.
  6. Run a mobile security scan — Use a reputable mobile antivirus to check for installed malware.
  7. Report the scam — Report to your national cybercrime authority (FTC in the US, Action Fraud in the UK, ACSC in Australia) and to the brand being impersonated.

Protecting Your Business From QR Code Phishing

Organizations face outsized risk from quishing because a single compromised employee can lead to a full network breach. Here's a practical checklist:

ControlWhat It DoesPriority
Image-aware email securityScans QR codes inside attachments and imagesHigh
Passkey or FIDO2 rolloutEliminates credential phishing entirelyCritical
Mobile device management (MDM)Enforces OS updates and security policiesHigh
Quishing simulation trainingBuilds real-world detection skillsHigh
Branded short links for marketingHelps customers verify legitimate codesMedium
Incident response playbookFast containment when a scan occursHigh

The Future of QR Code Phishing

Expect quishing to become more sophisticated through 2026 and beyond. Emerging trends include:

  • AI-generated lures — Personalized quishing emails written by large language models, tailored to each victim's role and industry.
  • Dynamic QR codes — Codes that display safe content when scanned by security tools and malicious content when scanned by real users.
  • Deepfake reinforcement — Voice or video messages from "the CEO" instructing employees to scan a specific code.
  • QR codes in physical mail — A resurgence of postal fraud using printed codes on fake official letters from tax authorities or utilities.

The defensive playbook, however, remains consistent: verify, preview, and never trust a QR code you didn't expect.

Frequently Asked Questions

Can just scanning a QR code hack my phone?

In almost all cases, no. Simply scanning a QR code only displays a URL preview. The danger begins when you tap the link, visit the site, download a file, or enter data. However, if your mobile browser has an unpatched vulnerability, visiting a malicious page could theoretically deliver a drive-by exploit — which is why keeping your OS updated is essential.

Are QR codes on restaurant menus safe?

Usually yes, but always check that the code hasn't been covered with a sticker. Preview the URL before opening — it should point to a recognizable restaurant or menu platform. Never enter payment details on a page reached from a menu QR code unless the restaurant confirms that's how they take payment.

How can I tell if a QR code is fake?

Look for physical tampering (stickers over other codes), unusual placement (random codes in public spaces), and always read the preview URL for misspellings, unfamiliar domains, or suspicious redirects. In email, be wary of any QR code that asks you to authenticate a work account on your phone.

Does my iPhone or Android warn me about malicious QR codes?

Both iOS and Android show a URL preview before opening, and Safari and Chrome will warn about known phishing sites. However, brand-new phishing domains often go undetected for hours. Additional DNS filtering and a security-focused scanner app significantly improve protection.

Should businesses stop using QR codes because of quishing?

No — QR codes remain a valuable marketing and operational tool. The solution is to use a trusted link management platform with branded short domains, monitor click patterns for anomalies, and educate customers to verify the preview URL before tapping. Abandoning QR codes would simply cede the channel to attackers.

Final Thoughts

QR code phishing scams thrive on convenience, trust, and the invisibility of the destination URL. The good news is that the defenses are simple and largely free: preview every URL, never log in through an unexpected QR code, use phishing-resistant authentication, and treat any code that asks for credentials or payment as guilty until proven innocent.

For businesses, combining branded short links from platforms like Lunyb, phishing-resistant MFA, and image-aware email security dramatically reduces exposure. For individuals, a few seconds of skepticism before every scan is the single most powerful defense you have.

Stay curious, stay cautious — and when in doubt, don't scan.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles