facebook-pixel

QR Code Phishing Scams: How to Stay Safe in 2026

L
Lunyb Security Team
··9 min read

QR codes are everywhere in 2026 — on restaurant tables, parking meters, product packaging, event tickets, and even street posters. But their explosive popularity has created a new frontier for cybercriminals: QR code phishing scams, often called "quishing." These attacks trick users into scanning malicious codes that redirect them to fake websites, steal credentials, or install malware on their devices.

In this comprehensive guide, we'll explain exactly how QR code phishing scams work, show you real-world examples, and give you a practical checklist to stay safe — whether you're an everyday smartphone user or a business owner protecting your customers.

What Are QR Code Phishing Scams?

QR code phishing (quishing) is a social engineering attack where cybercriminals use fraudulent QR codes to redirect victims to malicious websites or trigger harmful downloads. Because QR codes are just visual encodings of URLs, users cannot read the destination with the naked eye — making them the perfect disguise for phishing links.

Unlike traditional email phishing, where a suspicious URL might be visible on hover, a QR code hides the destination entirely until it's scanned. By the time the victim sees the fake login page, they've already trusted the physical or digital context in which the code appeared.

Why Quishing Is Growing So Fast

  • Pandemic normalization: Contactless menus, payments, and check-ins trained users to scan without question.
  • Bypasses email filters: QR codes embedded in images sail past most text-based phishing detection.
  • Mobile-first attacks: Phones often have weaker security than desktops and smaller screens that hide URL details.
  • Low cost, high reach: Printing a sticker costs pennies, but can harvest thousands of credentials.

How QR Code Phishing Attacks Work

Most quishing scams follow a predictable five-step pattern. Understanding this flow helps you spot the red flags before you tap.

  1. Creation: The attacker generates a QR code pointing to a malicious URL — often a cloned login page for a bank, delivery service, or workplace tool.
  2. Placement: The code is placed where victims expect legitimacy — stuck over a real parking meter QR, emailed as a fake MFA setup, or printed on counterfeit flyers.
  3. Scan trigger: The victim scans with their phone camera, trusting the surrounding context.
  4. Redirection: The phone opens a fake site that looks identical to a real one, prompting login credentials, payment info, or app installation.
  5. Harvest and exploit: Stolen data is used immediately for account takeover, drained wallets, or sold on dark web marketplaces.

Real-World Examples of QR Code Scams

1. Parking Meter Sticker Scams

In cities across the US, UK, and Australia, criminals have placed fake QR stickers over official parking meter codes. Drivers scan, enter card details on a convincing-looking payment page, and lose hundreds of dollars before realizing their car was never registered as paid.

2. Corporate Email Quishing (MFA Reset Scams)

Attackers email employees a PDF or image containing a QR code, claiming it's required to "re-enroll in multi-factor authentication" or "view a secure document." Scanning it on a personal phone — outside corporate security controls — leads to a fake Microsoft 365 or Google Workspace login page.

3. Fake Delivery Notifications

A card is left at your door claiming a missed package. The QR code "to reschedule delivery" leads to a page requesting a small redelivery fee and your card details. The fee is a lure; the real goal is the card number.

4. Restaurant Menu Overlays

Scammers slap a sticker on top of a legitimate menu QR. Patrons scan, land on a fake Wi-Fi login or "loyalty signup" page, and hand over email, phone, and sometimes payment details.

5. Cryptocurrency Donation Scams

Fake charity posters display QR codes that lead to attacker-controlled wallets. The money is irreversible once sent.

Warning Signs of a Malicious QR Code

Before you scan — or immediately after your camera previews the URL — look for these red flags:

  • Stickers over existing codes: If a QR code looks like it's been pasted over another one, don't scan it.
  • Mismatched domains: The preview URL doesn't match the brand (e.g., "paypa1-secure.com" instead of "paypal.com").
  • Shortened or obfuscated links: Not all shortened links are bad, but combined with other red flags they warrant caution.
  • Urgent language nearby: "Scan now to avoid fine," "Account locked — scan to verify."
  • Unexpected app download prompts: Legitimate QR codes almost never ask you to install an app directly.
  • Requests for credentials immediately after scanning: Especially if you weren't expecting a login screen.
  • Poor print quality or crooked placement: A sign the code was added later and isn't official.

Quishing vs. Traditional Phishing: Key Differences

FactorTraditional PhishingQR Code Phishing (Quishing)
DeliveryEmail, SMS, chatPhysical signs, posters, emailed images
URL visibilityVisible on hover (desktop)Hidden until scanned
Primary deviceDesktop or mobileAlmost always mobile
Email filter detectionHigh — text-based scanningLow — image embedded
Victim contextSuspicious by defaultTrusting (physical environment)
Typical goalCredentials, malwareCredentials, payment data, wallet drain

10 Ways to Protect Yourself from QR Code Phishing

  1. Preview the URL before opening. Most modern phone cameras show a URL preview after scanning. Read it carefully before tapping.
  2. Check the domain spelling. Watch for lookalike characters (0 vs O, 1 vs l, rn vs m).
  3. Inspect physical QR codes for stickers. Try gently peeling a corner — if it lifts, it's an overlay.
  4. Never enter credentials from a scanned link. Instead, open the official app or type the URL manually.
  5. Use a secure DNS provider. Services like Cloudflare 1.1.1.1 or Quad9 block known phishing domains at the network level.
  6. Enable browser phishing protection. Chrome Safe Browsing, Safari Fraud Warnings, and Firefox phishing protection catch many malicious sites.
  7. Keep your phone OS and apps updated. Patches close vulnerabilities that malicious pages try to exploit.
  8. Use multi-factor authentication (MFA) everywhere. Even if credentials leak, hardware keys and app-based MFA stop account takeover.
  9. Don't scan codes from unsolicited emails or printed mail. Treat them with the same suspicion as unknown attachments.
  10. Verify with the source. For parking, delivery, or payment codes, use the official app or call the business directly.

How Businesses Can Prevent QR Code Phishing

If your company uses QR codes for customer engagement, menus, payments, or marketing, you have a duty to make them tamper-resistant and trustworthy.

Use Branded, Trackable Short Links

Generic black-and-white QR codes are easy to counterfeit. Codes that resolve to a branded short domain (like yourbrand.co/menu) give users a trust signal in the URL preview. Platforms such as Lunyb let you create branded short links with analytics, so you can monitor scan activity and detect anomalies that may indicate a cloned code circulating in the wild.

For a broader comparison of link management tools, see our 2026 buyer's guide to URL shorteners and our Rebrandly review.

Tamper-Evident Placement

  • Laminate or seal physical codes with branded holographic stickers.
  • Inspect customer-facing codes daily for overlays.
  • Avoid printing QR codes on removable paper slips in public places.

Train Employees

Add quishing to your security awareness program. Many employees still believe phishing only arrives via email. Run simulated QR phishing campaigns to measure and improve awareness.

Monitor Your Brand

Set up alerts for domain lookalikes and typosquats. If attackers are impersonating your checkout page, you want to know before customers do.

What to Do If You've Scanned a Malicious QR Code

Acting fast limits the damage. Follow these steps immediately:

  1. Disconnect from the internet to stop any in-progress downloads or data exfiltration.
  2. Don't enter any information on the page that opened. Close the browser tab.
  3. Change passwords for any accounts you entered credentials into — starting with email and banking.
  4. Enable or reset MFA on affected accounts.
  5. Contact your bank if you entered payment details. Request a card freeze or replacement.
  6. Run a mobile security scan with a reputable mobile security app.
  7. Report the scam to local authorities (FTC in the US, Action Fraud in the UK, ScamWatch in Australia) and the brand being impersonated.
  8. Monitor your accounts and credit report for suspicious activity over the next 90 days.

The Future of QR Code Security

As quishing attacks grow more sophisticated, we're seeing promising defenses emerge:

  • Signed QR codes: Cryptographically signed codes that phones can verify before opening.
  • AI-based URL analysis: On-device machine learning that evaluates destinations in milliseconds.
  • Dynamic rotating codes: Codes that change frequently and expire, making static counterfeits useless.
  • Browser-level warnings: Mobile browsers increasingly flag QR-origin traffic for extra scrutiny.

Expect regulatory pressure in 2026 and beyond, particularly around payment-related QR codes, as governments respond to rising consumer losses.

Frequently Asked Questions

Can scanning a QR code hack my phone?

Simply scanning a QR code and viewing the preview URL will not hack your phone. The danger comes from what happens next — visiting a malicious website, entering credentials, or downloading an app. Modern phones require user action before any harmful code can execute, so always pause and read the previewed URL before tapping.

Are QR codes in restaurants safe to scan?

Most are safe, but check for signs of tampering. Legitimate restaurant QR codes are usually printed directly on menus or laminated table toppers. Be suspicious of stickers added to tables, especially if the URL doesn't match the restaurant's name or asks for login credentials or payment information just to view a menu.

How can I tell if a QR code is legitimate before scanning?

Look at the physical context: is it an official-looking print, or a sticker that could have been applied by anyone? After scanning, read the URL preview carefully — check the domain spelling, watch for suspicious subdomains, and never enter credentials unless you've independently verified the site through the brand's official app or website.

Do antivirus apps protect against QR phishing?

Reputable mobile security apps can block known malicious URLs and warn you about phishing sites, but they can't catch every brand-new scam domain. Combine them with secure DNS, browser phishing protection, cautious scanning habits, and multi-factor authentication for layered defense.

Is it safer to use the camera app or a dedicated QR scanner?

Your phone's built-in camera is generally safer because it only previews the URL without automatically opening it, and it benefits from OS-level security updates. Third-party QR scanner apps may auto-open links, display intrusive ads, or request excessive permissions. Stick with the native camera whenever possible.

Final Thoughts

QR code phishing scams exploit a simple human weakness: we trust what we can't easily inspect. The next time you reach for your phone to scan a code, take two extra seconds to preview the URL, question the context, and verify through official channels when stakes are high. Those two seconds can save you from drained accounts, stolen identities, and compromised workplace credentials.

For businesses, investing in branded short links, tamper-evident placement, and employee training isn't just good security hygiene — it's a competitive trust signal in a world where customers are rightfully growing more cautious about every scan.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles