facebook-pixel

QR Code Phishing Scams: How to Stay Safe in 2026

L
Lunyb Security Team
··9 min read

QR codes are everywhere in 2026 — on restaurant menus, parking meters, product packaging, event tickets, and even printed on flyers taped to lamp posts. That convenience has a dark side: attackers have discovered that a small black-and-white square is one of the most effective phishing delivery mechanisms ever invented. This attack style, often called quishing (QR + phishing), has exploded across email inboxes, physical spaces, and social platforms.

This guide explains exactly how QR code phishing scams work, why they bypass so many traditional security tools, how to spot the warning signs, and what to do if you've already scanned a malicious code.

What Is a QR Code Phishing Scam?

A QR code phishing scam is a social engineering attack in which criminals use a QR code to redirect victims to a fraudulent website, malware download, or payment page. Because the destination URL is hidden inside the visual pattern, victims cannot easily see where they are being sent before their phone opens the link.

The attack succeeds by exploiting three things: trust in printed or emailed materials, the small screens of mobile devices (which truncate URLs), and the fact that most enterprise email filters do not decode images or QR patterns.

Why Attackers Love QR Codes

  • They bypass email security gateways. Most filters scan links in text and attachments, not pixels inside an image.
  • They shift the attack to a personal device. Your phone often lacks the endpoint protection your work laptop has.
  • They look modern and legitimate. Users have been trained during the pandemic to scan codes without hesitation.
  • URLs are hidden by design. There is no visible link to inspect before scanning.

How QR Code Phishing Attacks Actually Work

Most quishing campaigns follow a predictable playbook. Understanding the steps helps you interrupt the attack before it succeeds.

  1. Lure creation: The attacker crafts a message or physical sign that creates urgency — a parking ticket, an MFA reset, a package delivery notice, or a bonus payslip.
  2. QR code embedding: A QR code pointing to a look-alike domain is inserted into the lure. The domain often mimics Microsoft 365, DocuSign, a bank, or a courier.
  3. Distribution: The lure is emailed, printed on stickers, mailed as a letter, or posted in a public space over a legitimate code.
  4. Redirect chain: Once scanned, the URL often bounces through multiple redirectors and cloaking services to evade detection.
  5. Credential or payment harvest: The victim lands on a pixel-perfect fake login page or checkout, and their credentials, MFA codes, or card details are stolen in real time.
  6. Account takeover: Stolen credentials are used immediately — sometimes within seconds — thanks to automated attacker-in-the-middle kits.

Common Types of QR Code Phishing Scams

1. Email-Based Quishing

An email arrives claiming your Microsoft 365 password is expiring, your voicemail is waiting, or a shared document requires your signature. The message contains a QR code and instructs you to scan it "for security reasons." This is currently the most common corporate variant.

2. Sticker Overlay Attacks

Criminals print malicious QR codes on stickers and place them over legitimate codes on parking meters, EV chargers, restaurant tables, or public transit posters. Victims think they're paying for parking; they're actually handing card details to a scammer.

3. Fake Delivery and Postal Notices

A card is left in your mailbox or slipped under your door claiming a parcel could not be delivered. The QR code takes you to a convincing courier site demanding a small "redelivery fee" — plus your full card and address details.

4. Cryptocurrency Wallet Drains

Fake giveaways, airdrops, or "wallet verification" pages ask users to scan a QR code that connects their wallet to a malicious smart contract, silently draining funds.

5. Wi-Fi Quishing

A poster in a café advertises free Wi-Fi via QR code. The code either joins you to an attacker-controlled network or opens a captive portal that steals login credentials for popular services.

Real-World Warning Signs

Before you scan any QR code, run through this quick mental checklist. If two or more items apply, do not scan.

Warning SignWhy It's Suspicious
Sticker placed over another codeClassic overlay attack — look for uneven edges or misaligned printing.
Urgency or threats in the surrounding text"Pay within 24 hours or face a fine" is a hallmark of social engineering.
QR code inside an unexpected emailLegitimate services rarely require you to scan a code from your inbox.
Request to install an app after scanningSideloaded apps are a common malware vector.
Landing page asks for password + MFA codeAttacker-in-the-middle kits harvest both simultaneously.
Shortened or unfamiliar domain in previewAttackers use lookalike domains such as micros0ft-login.co.

How to Stay Safe: A Practical Defense Checklist

For Individuals

  1. Preview the URL before opening. Modern iOS and Android cameras show the destination URL before launching the browser. Read it carefully.
  2. Type sensitive URLs manually. For banking, email, or work logins, never rely on a scanned code — open a fresh browser tab and type the address yourself.
  3. Use a hardware security key or passkey. These are phishing-resistant even if you land on a fake site.
  4. Keep your phone's OS updated. Many QR-driven exploits rely on unpatched browser bugs.
  5. Enable encrypted DNS. Services like Cloudflare 1.1.1.1 or NextDNS can block known phishing domains at the network level.
  6. Never install apps from links inside a scanned page. Only use the official App Store or Play Store.
  7. Inspect physical codes for stickers. Gently pick at the corner — a genuine printed code will not peel off.

For Organizations

  1. Deploy image and QR-aware email security. Newer gateways decode QR patterns and analyze the destination URL.
  2. Roll out passkeys or FIDO2 keys company-wide. This eliminates credential phishing almost entirely.
  3. Run quishing simulations. Include QR codes in your phishing awareness training — most legacy programs don't.
  4. Block newly registered domains at the proxy. The vast majority of quishing sites are less than 48 hours old.
  5. Publish a clear reporting workflow. Employees should have a one-click way to flag suspicious QR codes.

The Role of Trusted URL Shorteners

Not every short link or QR code is malicious — in fact, reputable link management platforms are one of the best defenses against being tricked. Trusted shorteners provide destination previews, malware scanning, click analytics, and the ability to disable a compromised link instantly.

If you generate QR codes for your business, using a platform that gives recipients confidence in the destination matters. Services like Lunyb allow you to create branded short links and QR codes with built-in link integrity checks, so your customers know a code from your brand actually leads where it says it does. For a broader look at options, our 2026 buyer's guide to URL shorteners compares the leading platforms side-by-side.

If you're evaluating specific tools, we've also published a detailed Rebrandly review and an honest review of Lunyb to help you choose a provider that takes link safety seriously.

What to Do If You've Already Scanned a Malicious QR Code

Speed matters. The average time between credential theft and account takeover is now under ten minutes. Take these steps immediately:

  1. Do not enter any information on the page that opened. Close the browser tab immediately.
  2. Disconnect from the network if you suspect malware — turn on airplane mode.
  3. Change the affected password from a different, trusted device. Prioritize email first, then banking, then everything else.
  4. Revoke active sessions in your account security settings. This kicks the attacker out even if they have your password.
  5. Enable a phishing-resistant second factor (passkey or hardware key) if you haven't already.
  6. Contact your bank if payment details were entered. Ask for a card reissue and enable transaction alerts.
  7. Report the scam to your local cybercrime authority (FTC in the US, Action Fraud in the UK, Scamwatch in AU) and to the brand that was impersonated.
  8. Scan your device with a reputable mobile security app if you installed anything after scanning.

The Future of QR Code Phishing

Expect quishing to get worse before it gets better. Three trends are converging:

  • AI-generated lures make phishing emails and printed notices grammatically flawless and highly personalized.
  • Dynamic QR codes allow attackers to change the destination after the code is printed, evading initial scans by security researchers.
  • Deepfake voice follow-ups are increasingly used after a QR scan — a "bank fraud team" calls minutes later to walk victims through "resolving" the fake incident.

The good news: defenses are catching up. Passkeys, on-device URL analysis, encrypted DNS filtering, and QR-aware email gateways are all becoming mainstream. Individuals who develop the simple habit of previewing every URL before opening — and never entering credentials from a scanned link — are already well protected.

FAQ: QR Code Phishing Scams

Can simply scanning a QR code infect my phone?

In almost all cases, no. Scanning a QR code just reveals a URL — you still have to open it and typically interact with the destination page for any harm to occur. However, an unpatched browser could theoretically be exploited by a malicious page, which is why keeping your device updated is essential.

How can I preview a QR code's URL before opening it?

Both iOS and modern Android cameras display the destination URL at the top or bottom of the screen when a QR code is detected. Read the full domain carefully before tapping. If the preview is truncated, use a dedicated QR scanner app that shows the full expanded URL, including any redirects.

Are QR codes in restaurants and cafés safe?

Usually yes, but check for stickers placed over the original code. Peel-off overlays are the most common physical quishing technique. If the code is on a laminated menu or etched into the table, it's almost certainly legitimate. Codes on loose paper or fresh stickers deserve more scrutiny.

What's the safest way to pay via a QR code?

Use codes generated inside a trusted app rather than scanning random codes in the wild. For example, opening your bank or payment app and scanning a merchant code from within it is much safer than scanning a code with your camera and being redirected to a web page asking for card details.

Should businesses stop using QR codes because of quishing?

No — the convenience and marketing benefits are significant. Instead, use branded short links from a reputable provider, keep destination URLs consistent so customers can recognize them, and educate your audience about what your legitimate codes look like. Trust and consistency are the best defenses against impersonation.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles