facebook-pixel

QR Code Phishing Scams: How to Stay Safe in 2026

L
Lunyb Security Team
··9 min read

QR codes are everywhere: on restaurant tables, parking meters, product packaging, event tickets, and even utility bills. Their convenience has made them a favorite tool for legitimate businesses and, unfortunately, for cybercriminals. QR code phishing scams, often called "quishing," have exploded in the past two years, tricking millions of people into handing over passwords, payment details, and personal data.

This guide explains how QR code phishing scams work, the most common tactics attackers use, real-world examples, and step-by-step actions you can take to stay safe. Whether you scan codes daily or only occasionally, understanding these threats is essential in 2026.

What Are QR Code Phishing Scams?

QR code phishing scams are attacks in which criminals use fake or tampered QR codes to redirect victims to malicious websites, fraudulent payment forms, or malware downloads. The technique combines traditional phishing with the visual trust people place in QR codes.

Because a QR code is just a pattern of squares, a human cannot tell whether it points to a legitimate site or a dangerous one until after scanning. Attackers exploit that blind spot. Once scanned, the code can launch a browser, prefill a payment app, or even trigger an app install prompt in seconds.

Why the Term "Quishing"?

"Quishing" is a blend of "QR" and "phishing." Security researchers adopted the term around 2023 as attacks scaled globally. Unlike email phishing, quishing often bypasses corporate email filters because the malicious link is embedded in an image, not text.

How QR Code Phishing Attacks Work

Most quishing attacks follow a predictable pattern. Understanding the flow makes the red flags easier to spot.

  1. Creation: The attacker generates a QR code linking to a phishing site, often a near-perfect clone of a bank, delivery service, or login page.
  2. Distribution: The code is placed where victims will encounter it: emails, printed flyers, stickers over legitimate codes, parking meters, or fake invoices.
  3. Scan: A victim scans with their phone camera, which opens the malicious URL in a mobile browser.
  4. Deception: The site mimics a trusted brand and asks for credentials, card details, or a small "verification" payment.
  5. Exploitation: Stolen data is used for account takeover, fraud, or resold on dark web markets.

Why Mobile Devices Make Quishing Worse

Phones are the primary target because mobile browsers hide parts of URLs, security warnings are smaller, and users are often distracted or in a hurry. A shortened link or an unfamiliar domain looks less suspicious on a 6-inch screen than on a desktop.

Common Types of QR Code Phishing Scams

1. Sticker Overlays in Public Places

Scammers print QR code stickers and place them directly over legitimate codes on parking meters, EV chargers, restaurant menus, and public transit signs. Victims believe they are paying for parking but are actually sending money to a fraudster.

2. Email-Based Quishing

Attackers send emails claiming your account needs verification, your MFA needs re-enrollment, or a document is waiting. Instead of a link, the email contains a QR code image. Corporate security filters often miss these because there's no suspicious URL in the text.

3. Fake Delivery Notifications

You receive a physical postcard or a text saying a package couldn't be delivered. A QR code invites you to reschedule. The site asks for a small redelivery fee, capturing your card details.

4. Fraudulent Invoices and Bills

Fake utility, tax, or subscription bills arrive by mail with a QR code for "quick payment." Small businesses are prime targets because accounts payable teams process invoices quickly.

5. Cryptocurrency and Investment Scams

QR codes in social media ads or Telegram groups promise instant crypto rewards, airdrops, or wallet verifications. Scanning connects a wallet to a malicious contract that drains funds.

6. Wi-Fi Quishing

A code labeled "Free Wi-Fi" in a cafe or airport connects your phone to an attacker-controlled network, enabling traffic interception and further attacks.

Real-World QR Phishing Examples

These incidents illustrate how varied and creative quishing attacks have become:

  • Parking meter scams (UK, US, EU): Cities including London, Austin, and Amsterdam reported thousands of complaints from drivers whose payment details were stolen from stickered meters.
  • Corporate credential theft: A 2024 Microsoft report documented a campaign that sent QR-code-laden PDFs to over 1,000 companies, harvesting Microsoft 365 credentials.
  • Chinese postal scam: Fake "customs fee" notices with QR codes hit millions of shoppers, especially those expecting international parcels.
  • Restaurant menu tampering: Diners scanning what they thought were menus were redirected to fake loyalty programs collecting personal data.

Red Flags: How to Spot a Malicious QR Code

Before scanning any QR code, ask yourself these questions:

Warning Sign Why It Matters
Sticker placed over another code Classic overlay attack; check for lifted edges or mismatched printing.
Unsolicited email with a QR image Legitimate services rarely require you to scan a code from your inbox.
Urgency or fear language "Verify within 24 hours or account will be suspended" is a phishing hallmark.
Shortened or unfamiliar domain after scan Always inspect the preview URL before tapping through.
Request for credentials or payment on a mobile site Type the URL manually instead when in doubt.
QR code with no context or branding Legitimate businesses label their codes clearly.

How to Stay Safe: A Practical Checklist

Before You Scan

  1. Inspect the physical code. Look for stickers layered over another code, poor print quality, or codes that seem out of place.
  2. Verify the source. If the code is on a bill or email, confirm through the company's official app or website.
  3. Use your phone's built-in camera rather than third-party scanner apps, which may themselves be malicious.
  4. Enable URL preview. Most modern phones show the destination link before opening it. Always read it.

After You Scan

  1. Check the domain carefully. Watch for typos, extra words, or unusual TLDs (e.g., "paypa1-secure.co" instead of "paypal.com").
  2. Never enter credentials on a page you reached via QR without independently verifying the URL.
  3. Refuse app install prompts triggered by scans. Install apps only from official app stores.
  4. Close the tab immediately if anything feels off. No legitimate site punishes you for leaving.

General Device Hygiene

  • Keep your phone's OS and browser updated.
  • Enable multi-factor authentication on every important account, ideally with an authenticator app or hardware key rather than SMS.
  • Use a password manager so you never reuse credentials across sites.
  • Turn on encrypted DNS (DNS-over-HTTPS) in your browser to reduce network-level tampering.
  • Review app permissions monthly and revoke access you no longer need.

Safer Ways to Share and Shorten Links

If you run a business or send links regularly, the way you generate and share URLs matters. Reputable link management platforms give recipients a level of trust and transparency that random QR codes cannot.

Services like Lunyb let you create branded short links and QR codes with click analytics, expiration dates, and password protection. Because the destination is tied to a consistent domain your audience recognizes, it's easier for them to spot impersonation attempts. If you're evaluating options, our 2026 buyer's guide to URL shorteners compares the leading tools, and our honest review of Lunyb covers its safety features in depth.

What Businesses Should Do

Quishing is not just a consumer problem. Companies increasingly face targeted attacks against employees and customers.

Employee Training

  • Add QR-specific scenarios to phishing simulations.
  • Teach staff that MFA re-enrollment should never happen through an emailed QR code.
  • Establish a clear reporting channel for suspicious codes, whether digital or physical.

Technical Controls

  • Deploy email security tools that scan image attachments and inline images for QR content.
  • Use mobile device management (MDM) to enforce browser safety settings.
  • Block newly registered domains at the DNS layer, since many quishing sites are only days old.

Customer-Facing Codes

  • Print codes with tamper-evident features and check them regularly.
  • Use branded, memorable short domains so customers can visually verify links.
  • Publish an official list of URLs and channels customers should expect from you.

What to Do If You've Been Scammed

If you suspect you've fallen for a QR phishing scam, act quickly:

  1. Disconnect: Turn off Wi-Fi and mobile data if you suspect malware.
  2. Change passwords: Start with the account you entered credentials for, then any accounts sharing that password.
  3. Contact your bank: Freeze cards used on the fraudulent site and dispute unauthorized charges.
  4. Enable MFA everywhere if you haven't already.
  5. Report the incident: File reports with your national cybercrime authority (FTC in the US, Action Fraud in the UK, ACSC in Australia, etc.).
  6. Scan your device with a reputable mobile security app if you installed anything after the scan.
  7. Monitor your credit and consider a fraud alert or freeze if personal data was exposed.

The Future of QR Phishing

QR phishing will keep evolving. Expect to see:

  • AI-generated lookalike sites that are harder to distinguish from the real thing.
  • Dynamic QR codes whose destinations change after posting to evade detection.
  • Voice-and-QR combinations where a scam call directs you to scan a code shown in a follow-up text.
  • More attacks on physical infrastructure: chargers, kiosks, and vending machines.

Staying safe is less about avoiding QR codes entirely and more about applying the same skepticism you'd use for any link. Treat every code as untrusted until proven otherwise, verify through official channels, and never let urgency override caution.

Frequently Asked Questions

Can simply scanning a QR code infect my phone?

Scanning alone typically just opens a URL, which is safe by itself. The danger comes from what happens next: entering credentials on a fake site, downloading a malicious app, or granting permissions. Keeping your OS updated and refusing unexpected install prompts blocks most attacks.

Are QR codes in restaurants and stores generally safe?

Most are legitimate, but always check for sticker overlays, verify the domain matches the business, and avoid entering payment details unless you're on the restaurant's official app or a trusted payment processor. When possible, order from the counter or use cash instead.

Should I use a QR scanner app instead of my phone camera?

No. Third-party scanner apps have historically been a source of adware and even malware. Modern iPhone and Android cameras scan codes safely and show a URL preview before opening. Stick with the built-in tool.

How can businesses prove their QR codes are legitimate?

Use branded short domains, add company logos inside the code, publish your official URLs on your website, and consider tamper-evident printing for physical codes. Platforms like Lunyb make it easier to create trusted, trackable QR codes that customers recognize.

What's the single most effective defense against quishing?

Multi-factor authentication. Even if attackers steal your password through a fake QR-driven site, MFA (especially with an authenticator app or hardware key) blocks account takeover in the vast majority of cases. Combine it with a password manager for maximum protection.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles