facebook-pixel

QR Code Phishing Scams: How to Stay Safe in 2026

L
Lunyb Security Team
··10 min read

QR codes are everywhere in 2026: restaurant menus, parking meters, payment terminals, event tickets, and product packaging. Their convenience has made them one of the most trusted tools in modern life — which is exactly why cybercriminals love them. A rapidly growing threat called QR code phishing, or quishing, is targeting millions of consumers and employees each year, and most people don't know how to spot it.

This guide explains how QR code phishing scams work, the most common attack patterns, real examples reported in 2024–2026, and the practical steps you can take to protect yourself, your family, and your workplace.

What Is QR Code Phishing (Quishing)?

QR code phishing, often called quishing, is a social engineering attack where criminals use a QR code to trick victims into visiting malicious websites, downloading malware, or handing over sensitive information such as passwords, payment details, or two-factor authentication codes.

Unlike traditional phishing emails, QR codes hide the destination URL inside a pattern of black-and-white squares. A user cannot easily read where the code leads until after they scan it — and by then, many people simply tap through without checking. This trust gap is what makes quishing so effective.

Why QR Code Phishing Is Growing So Fast

  • Widespread adoption: After 2020, QR codes became a default interaction pattern in restaurants, retail, and public transport.
  • Email filters miss them: Most email security tools scan links and attachments, not images. A QR code embedded in a PDF or PNG can slip through undetected.
  • Mobile-first target: Scans happen on phones, which typically have fewer security layers than desktops.
  • Low user suspicion: People trust printed QR codes far more than links in emails.

How a QR Code Phishing Attack Works

Most quishing attacks follow a predictable playbook. Understanding the steps helps you recognize the warning signs before you scan.

  1. Attacker creates a malicious landing page that mimics a real login screen (bank, Microsoft 365, DHL delivery, parking payment, etc.).
  2. The URL is encoded into a QR code and placed in a location the victim will trust — an email, a printed poster, a flyer, or even a sticker placed over a legitimate code.
  3. The victim scans the code with their phone camera, which opens the fake page in a browser.
  4. The victim enters credentials, card details, or a one-time passcode believing the page is legitimate.
  5. The attacker harvests the data and either sells it, uses it to drain accounts, or launches follow-up attacks such as SIM swapping.

Common Types of QR Code Scams

1. Parking Meter Sticker Scams

Criminals print fake QR stickers and place them over real ones on parking meters. Drivers scan, land on a lookalike payment page, and enter their card details. This scam has been reported in dozens of U.S., U.K., and Australian cities since 2023.

2. Email-Based Quishing (Corporate Attacks)

An employee receives an email claiming their Microsoft 365 password is expiring, with a QR code to "verify." Because desktop email filters can't read QR codes, the message reaches the inbox. The employee scans on their phone — bypassing corporate security entirely — and enters credentials on a fake Microsoft login page.

3. Fake Delivery Notifications

Physical postcards or emails claiming a package is waiting ask you to scan a code to "reschedule delivery" or "pay a customs fee." The site collects card data and personal information.

4. Restaurant Menu Overlays

A sticker placed on top of a legitimate menu QR code redirects diners to a phishing site pretending to be the restaurant's ordering system or Wi-Fi login.

5. Cryptocurrency Wallet Draining

Scammers post QR codes claiming to give free airdrops or connect a wallet. Scanning triggers a transaction-signing prompt that empties the wallet.

6. Charity and Donation Fraud

After natural disasters, fake charity flyers with QR codes appear in public spaces. Donations flow directly to the scammer.

QR Phishing vs. Traditional Phishing: Key Differences

Attribute Traditional Phishing QR Code Phishing (Quishing)
Delivery channelEmail link, SMS, chatPrinted code, image in email, poster, sticker
URL visibilityVisible before click (usually)Hidden until scanned
Device targetedAny deviceAlmost always mobile
Detection by email filtersHighLow — codes are images
Physical world attack surfaceNoneHigh — stickers, flyers, packaging
Typical victim reactionCautiousHighly trusting

10 Ways to Stay Safe from QR Code Phishing

1. Preview the URL Before Opening

Modern iPhone and Android cameras show the destination URL as a small banner before you tap. Always read it. If the domain doesn't match the brand you expect (for example, micros0ft-verify.co instead of microsoft.com), close the camera immediately.

2. Check for Physical Tampering

Before scanning a code in public — on a menu, a meter, a poster, or a package — run your finger over it. If it feels like a sticker on top of another sticker, don't scan it. Report it to the venue.

3. Never Enter Credentials After Scanning a Code

This is the single most important rule. If a QR code takes you to a login page, close it and navigate to the service directly through your browser or app. Legitimate businesses almost never require you to log in via a scanned code.

4. Be Suspicious of QR Codes in Emails

If an email contains a QR code — especially one asking for account verification, password resets, or MFA re-enrollment — treat it as phishing until proven otherwise. Contact the sender through a known channel.

5. Use a Trusted URL Expander or Shortener You Control

If you're generating QR codes for a business, use a reputable shortener that shows analytics and lets you edit destinations. A trustworthy service like Lunyb lets you create branded short links and QR codes with click tracking, so you (and your customers) can spot suspicious redirects quickly. For a broader comparison of trustworthy providers, see our 2026 buyer's guide to URL shorteners.

6. Keep Your Phone's OS and Browser Updated

Many quishing attacks rely on outdated browsers to exploit rendering bugs or bypass warnings. Enable automatic updates on iOS and Android.

7. Enable Phishing Protection in Your Browser

Chrome, Safari, Firefox, and Edge all include Safe Browsing / Fraudulent Site Warning features. Make sure these are turned on. On iOS: Settings → Safari → Fraudulent Website Warning. On Android Chrome: Settings → Privacy and security → Safe Browsing → Enhanced protection.

8. Use Hardware Security Keys or Passkeys

Even if you fall for a phishing page, a hardware security key (YubiKey, Google Titan) or a passkey bound to the real domain will refuse to authenticate on a fake site. This is the strongest technical defense available in 2026.

9. Watch for Unusual App Install Prompts

If scanning a code prompts you to install an app, sideload an APK, or install a configuration profile, stop. Legitimate services direct you to the official app store, not a direct download.

10. Educate Your Team and Family

Quishing works because people don't know it exists. Share this article, run a quick training at work, and remind older or less tech-savvy family members that scanning is clicking — with all the same risks.

What to Do If You've Already Scanned a Malicious QR Code

Acting fast can dramatically reduce the damage. Follow these steps in order:

  1. Do not enter any information if the page is still open. Close the browser tab immediately.
  2. Disconnect from Wi-Fi and mobile data for a few minutes if you suspect a download occurred.
  3. Check for unfamiliar apps or profiles. On iOS: Settings → General → VPN & Device Management. On Android: Settings → Apps → check for anything you don't recognize.
  4. Change passwords for any account you may have entered credentials for — starting with email and banking.
  5. Revoke active sessions in each account's security settings.
  6. Contact your bank if you entered card or payment details. Ask for a card replacement.
  7. Enable multi-factor authentication everywhere, ideally with a hardware key or passkey.
  8. Report the scam to the FTC (US), Action Fraud (UK), ACCC Scamwatch (AU), or your local cybercrime unit.

How Businesses Can Defend Against Quishing

Organizations face a specific version of this threat: employees scanning malicious codes on personal phones, bypassing every corporate security control. Here's how to reduce the risk.

Technical Controls

  • Deploy email security that performs OCR on inline images and PDFs to extract and analyze QR code URLs.
  • Require passkeys or FIDO2 hardware keys for SSO logins — these are phishing-resistant by design.
  • Use mobile device management (MDM) with conditional access so scans on unmanaged devices can't reach sensitive apps.
  • Enforce DNS-level filtering that blocks known phishing domains for both office and remote workers.

Human Controls

  • Add QR phishing scenarios to your security awareness training program.
  • Run simulated quishing tests — printed posters in the break room work surprisingly well.
  • Publish a clear "never authenticate from a scanned code" policy.
  • If your marketing team generates QR codes, standardize on a single trusted provider with branded short links. Our review of Rebrandly and our honest Lunyb review can help you compare options.

The Future of QR Code Phishing

Expect quishing to grow more sophisticated through 2026 and beyond. Three trends to watch:

  • AI-generated lookalike sites: Attackers now spin up pixel-perfect clones of banking and enterprise login pages in minutes.
  • Dynamic QR codes: Codes that change destinations based on the scanner's location or device, making detection harder.
  • Hybrid attacks: Combining printed QR codes with follow-up phone calls ("vishing") to pressure victims through a fake support process.

The good news: the defenses that work today — URL previewing, passkeys, and healthy skepticism — will continue to work tomorrow. Awareness is 80% of the battle.

Frequently Asked Questions

Can simply scanning a QR code infect my phone?

In almost all cases, no. Scanning a QR code just opens a URL — it does not automatically install anything. The danger comes from what you do next: entering credentials, downloading an app, or approving a transaction on the page that opens. Keeping your OS updated closes the rare exploit-based edge cases.

How can I tell if a QR code is fake before scanning?

Check the physical medium for signs of tampering (stickers over stickers, misaligned edges, low-quality printing on official signage). For digital codes, be extra suspicious of emails, unexpected texts, and social media posts. Always preview the URL your camera shows before tapping it.

Are QR codes in emails always dangerous?

Not always, but they should raise your suspicion. Many legitimate businesses avoid QR codes in emails precisely because of quishing. If you receive one, verify by contacting the sender through an official channel or by logging into the service directly through your browser or app.

What's the safest QR code scanner app to use?

The built-in camera apps on iOS and Android are generally the safest choice because they show URL previews and receive regular security updates. Avoid third-party "QR scanner" apps from unknown developers — many are ad-heavy and some have been caught injecting their own redirects.

Does two-factor authentication protect me from QR phishing?

Standard SMS or app-based 2FA offers partial protection but can still be phished — attackers relay your code to the real site in real time. Passkeys and hardware security keys (FIDO2) are phishing-resistant because they cryptographically verify the domain, so they won't work on a fake site. These are the strongest option available.

Final Thoughts

QR codes aren't going away — they're too useful. But their convenience is exactly what makes them a phishing goldmine. Treat every scan like a click on a link from a stranger: preview the URL, question the context, and never enter credentials on a page you reached through a code. With a few new habits and the right technical safeguards, you can enjoy the speed of QR codes without becoming the next quishing statistic.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles