facebook-pixel

QR Code Phishing Scams: How to Stay Safe in 2026

L
Lunyb Security Team
··10 min read

QR codes are everywhere in 2026 — on restaurant tables, parking meters, product packaging, event tickets, and even utility bills. Their convenience has made them a daily habit for billions of people. Unfortunately, that same convenience has made them a goldmine for scammers. A rapidly growing threat called QR code phishing, or "quishing," is now one of the fastest-rising forms of online fraud, costing consumers and businesses hundreds of millions of dollars each year.

This guide explains exactly how QR code phishing scams work, how to recognize them, and the practical steps you can take to stay safe. Whether you're a casual smartphone user or a business owner deploying QR codes in your marketing, you'll walk away with a clear defense strategy.

What Is QR Code Phishing (Quishing)?

QR code phishing — often called "quishing" — is a social engineering attack in which criminals use QR codes to trick victims into visiting malicious websites, downloading malware, or handing over sensitive information such as passwords, payment details, or two-factor authentication codes.

Because a QR code is just a machine-readable image, you can't tell by looking at it where it leads. That opacity is exactly what makes it so dangerous. A scammer can print a convincing poster, sticker, or email that looks completely legitimate — but the embedded link quietly routes you to a fake login page or an attacker-controlled server.

Why Quishing Is Growing So Fast

  • Low cost, high reward: Printing a sticker costs cents; a single harvested bank login can be worth thousands.
  • Bypasses email filters: QR images embedded in emails often slip past security scanners that only look for suspicious text links.
  • Mobile-first attack surface: People scan with phones, which usually have weaker security tooling than desktop browsers.
  • Public trust: After the pandemic, consumers were trained to trust QR codes for menus, payments, and check-ins.

How QR Code Phishing Scams Work: The Attack Chain

Most quishing attacks follow a predictable pattern. Understanding each step helps you spot where the trap is set.

  1. Lure creation: The attacker designs a convincing physical sticker, flyer, email, or PDF featuring a QR code and a sense of urgency ("Verify your account," "Pay parking fee," "Claim refund").
  2. Placement: The lure is placed where targets will encounter it — pasted over a legitimate QR code on a parking meter, mailed as a fake invoice, or sent as an "HR document" to employees.
  3. Scan and redirect: The victim scans the code. The link often passes through several redirects to hide the final destination.
  4. Credential harvest or payload delivery: The victim lands on a pixel-perfect clone of a real login page or is prompted to install a "security app" that is actually spyware.
  5. Monetization: Stolen credentials are used to drain bank accounts, resell on dark markets, or launch deeper attacks against the victim's employer.

The Most Common Types of QR Code Scams

1. Parking Meter and EV Charger Stickers

One of the most widely reported scams of the last two years. Criminals print stickers that mimic city parking signage and paste them directly over the real QR code. Victims scan, enter card details to "pay for parking," and the fraudsters capture everything.

2. Fake Delivery Notifications

You receive a text or physical "missed delivery" slip with a QR code to reschedule. The site asks for a small redelivery fee — and your full card number, CVV, and address.

3. Email Quishing in Corporate Environments

Attackers send emails disguised as Microsoft 365, Google Workspace, or DocuSign notifications. The QR code bypasses URL scanners and leads to a credential-stealing page. This is especially effective because employees often scan on personal phones, outside corporate security controls.

4. Cryptocurrency "Verification" Scams

Codes posted on social media or crypto forums claim to let you "verify your wallet" or "claim an airdrop." Scanning them connects your wallet to a malicious smart contract that drains your assets.

5. Restaurant Menu Overlays

Scammers slap fake menu QR stickers over real ones. The page may show a menu — but it also loads a browser exploit or asks you to "sign in with Google" to view it.

6. Charity and Donation Fraud

After natural disasters, fake donation posters with QR codes pop up quickly, exploiting people's generosity before authorities can take them down.

Red Flags: How to Spot a Malicious QR Code

Before you scan, run through this quick mental checklist. If any item raises a flag, don't scan.

Warning Sign Why It Matters
Sticker placed over another QR codeClassic physical overlay attack
Code in an unsolicited email or SMSLegitimate companies rarely require QR scanning to log in
Urgency language ("Act now," "Account suspended")Pressure is the hallmark of social engineering
Preview URL uses shortener you don't recognizeCould be hiding the true destination
Landing page asks for passwords, OTPs, or card details immediatelyLegitimate services don't demand this from a cold scan
Misspelled domain or extra subdomains (login.microsoft.secure-check.co)Classic phishing domain pattern
Prompts to install an app from outside official storesLikely malware

How to Stay Safe: 10 Practical Rules

  1. Preview the URL before opening it. Modern iOS and Android cameras show a preview of the link. Read it carefully — don't just tap.
  2. Type sensitive URLs manually. For banking, email, or workplace logins, never reach the login page via a scanned code. Open your browser and type the address yourself.
  3. Inspect physical codes for tampering. Peel-test the corner of a QR sticker on a meter or sign. If it lifts away to reveal another code underneath, report it.
  4. Use a secure QR scanner app. Several reputable security vendors offer scanners that check URLs against threat databases before opening them.
  5. Enable encrypted DNS on your phone. DNS-over-HTTPS or DNS-over-TLS with a reputable filtering provider can block known phishing domains at the network level.
  6. Turn on phishing protection in your browser. Safari, Chrome, Firefox, and Edge all have built-in Safe Browsing or Fraudulent Website Warnings — make sure they're active.
  7. Use hardware-backed two-factor authentication. Even if a scammer harvests your password, a FIDO2 security key or passkey will stop them cold.
  8. Keep your phone and apps updated. Many QR-delivered exploits rely on patched browser or OS vulnerabilities.
  9. Never install apps prompted by a QR code. If you need an app, go to the official App Store or Play Store directly.
  10. Trust the source, not the code. A QR code is only as trustworthy as the surface it's printed on. A sticker in a public place deserves zero inherent trust.

Advice for Businesses Using QR Codes

If your organization deploys QR codes for marketing, payments, or operations, you have a responsibility to make sure customers aren't being set up for scams via your branding.

Best Practices for Deploying QR Codes Safely

  • Use branded, trackable short links. A reputable link management platform like Lunyb lets you generate branded, analytics-enabled QR codes so customers can recognize your domain in the preview URL. See our honest review of Lunyb for more detail on how it works.
  • Tamper-evident printing: Use laminated stickers, holograms, or print codes directly onto surfaces that can't be easily overlaid.
  • Monitor your short link analytics. Sudden traffic drops may indicate a sticker has been covered; sudden spikes from unexpected regions may indicate cloning.
  • Educate customers: Post signage near your QR codes telling users what the destination URL should look like.
  • Never ask for credentials via a QR flow. Design your payment and login journeys so a scanned link never asks for a password.

If you're evaluating link and QR platforms for your business, our 2026 buyer's guide to URL shorteners compares the leading options side by side, and our Rebrandly review breaks down one of the better-known competitors in detail.

What to Do If You've Already Scanned a Malicious QR Code

Don't panic — fast action dramatically reduces harm. Follow these steps in order.

  1. Disconnect from the internet if you suspect malware was installed. Enable airplane mode.
  2. Don't enter any further information on the suspicious page. Close the browser tab immediately.
  3. Change passwords for any account whose credentials you may have typed, starting with email and banking. Use a different device if possible.
  4. Revoke active sessions in the account's security settings and sign out of all devices.
  5. Enable or reset two-factor authentication, preferably with a hardware key or passkey.
  6. Contact your bank if any payment details were entered. Request card replacement and dispute any fraudulent charges.
  7. Scan your device with a reputable mobile security tool, or in severe cases, perform a factory reset after backing up only your personal files (not apps).
  8. Report the scam to local authorities, the FTC (US), Action Fraud (UK), or your national cybercrime agency, and to the brand that was impersonated.

The Future of QR Code Threats

Expect quishing to keep evolving in three directions over the next few years:

  • AI-generated lures: Perfectly worded emails and localized posters tailored to specific neighborhoods or job roles.
  • Dynamic malicious codes: Codes that behave differently depending on device, time, or IP — serving a harmless page to security researchers and a phishing page to real victims.
  • Deeper mobile exploitation: As browsers patch obvious tricks, attackers will focus on in-app browser quirks, WebView vulnerabilities, and clipboard hijacking.

The defense, fortunately, stays the same: skepticism, preview-before-tap, and strong authentication.

Frequently Asked Questions

Can simply scanning a QR code hack my phone?

In almost all cases, no — scanning only reveals a URL. The danger comes from what happens next: visiting the website, entering information, or installing something. However, if your phone's browser has an unpatched vulnerability, a malicious site could theoretically exploit it, which is why keeping your OS updated matters.

Are QR codes in emails more dangerous than in the real world?

They're dangerous in a different way. Email quishing often bypasses corporate security filters because scanners look for text links, not images. Physical quishing exploits public trust in signage. Both deserve the same skepticism, but email QR codes in particular should almost always be ignored — legitimate services rarely require you to scan an image to log in.

How can I tell where a shortened QR link really goes?

Most phone cameras show a URL preview before you open it. For deeper inspection, you can paste the URL into a link-expander or URL-checker tool, or use a secure QR scanner app that automatically resolves redirects and checks the final destination against threat databases.

Is it safer to use my phone's built-in camera or a third-party QR app?

For most people, the built-in camera on an up-to-date iPhone or Android is the safest choice because it's maintained by the OS vendor and shows URL previews. Third-party QR apps can add security scanning, but they can also request excessive permissions, so stick to well-known vendors if you choose one.

How can my small business reassure customers that our QR codes are safe?

Use branded short links so the preview URL clearly shows your domain, print codes directly onto durable materials rather than removable stickers, post the expected destination URL next to the code, and avoid asking customers for passwords or full card numbers in any QR-initiated flow. A reputable link management service makes branded, monitored QR codes easy to deploy.

Final Thoughts

QR codes aren't going away — they're too useful. But like email in the 1990s or SMS in the 2000s, their convenience has created a thriving criminal ecosystem that preys on habit and trust. The good news is that defending yourself doesn't require technical expertise. A two-second URL preview, a healthy skepticism of unsolicited codes, and strong authentication on your important accounts will stop the vast majority of attacks before they begin.

Teach the people around you — especially older relatives and younger family members — the simple rule: trust the source, not the code. That one habit will protect them from a scam category that's only going to grow.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles