Wednesday, July 7, 2026

QR Code Scams: How to Spot and Avoid Quishing

QR codes are everywhere—on restaurant tables, parking meters, posters, and payment terminals—and scammers have noticed. “Quishing” (QR code phishing) uses a fake or tampered code to send you to a malicious website that steals your passwords and card details, or tries to install malware. The good news: a QR code is just a link in disguise, so a few simple habits keep you safe. Here's how QR code scams work, the red flags to watch for, and exactly what to do if you scan a bad one—based on current FBI and FTC guidance.

What is quishing (QR code phishing)?

Quishing is phishing that hides its bait inside a QR code instead of a clickable link. A normal phishing email shows a web address you can inspect before clicking. A QR code hides that address completely until your camera opens it—which is exactly why scammers like it. The code itself is harmless; the danger is where it points and what the page asks you to do next.

Because the destination is invisible until you scan, QR codes can also slip past email security filters that would normally flag a suspicious link. That has made quishing a fast-growing tactic in both inboxes and the physical world, according to the FBI's Internet Crime Complaint Center (IC3).

Are QR codes safe to scan?

Yes—scanning a QR code, by itself, cannot install anything on your phone or hack your device. A QR code is just encoded text, almost always a web address. The risk starts after you scan: if the code opens a fake login page and you type your password, prompts you to download an “app” that is really malware, or sends you to a payment page controlled by a scammer. Treat a scanned QR code exactly like a link a stranger handed you.

How QR code scams work

Most QR scams fall into a handful of patterns. Once you know them, the fakes are easy to spot.

Tampered codes on real signs

The classic version—flagged by the FBI back in 2022—is a sticker. Scammers print a malicious QR code on a sticker and place it over a legitimate one: on a parking meter, an EV charger, a bike-share dock, or a table tent. You think you're paying for parking; you're actually entering your card details on a scam site. The FBI documented criminals tampering with QR codes to steal victim funds this way.

Unexpected packages with a QR code

In 2025, the FBI and FTC both warned about a newer twist: an unsolicited package you didn't order arrives with a QR code and a note telling you to scan it to find out who sent it or to arrange a return. Scanning leads to a page that harvests personal and financial information—or asks you to install data-stealing software. It's a spin on the “brushing” scam, now weaponized with QR codes, per the FBI's 2025 IC3 alert and the FTC's consumer warning.

Quishing emails and texts

The same trick lands in your inbox: an email claiming your account is locked, a package needs “redelivery,” or a document is waiting—with a QR code to scan “to verify.” Scanning opens a convincing fake login page. Because the malicious link is buried inside an image, these messages often sail past spam filters that would catch an ordinary text link.

Fake payment, prize, and donation codes

Scammers also post codes promising a refund, a prize, a discount, or a charitable donation, then route you to a payment or credential-harvesting page. If a code pressures you to act fast or pay immediately, that urgency is the scam.

8 warning signs of a QR code scam

  • The code is a sticker placed over another code, or looks added after the fact.
  • It arrived unexpectedly—on a package you didn't order, or in an email or text you weren't expecting.
  • Scanning it opens a login page and asks for your password, especially for a bank, email, or work account.
  • The web address that appears is misspelled, uses a look-alike domain, or doesn't match the business it claims to be.
  • It tells you to download an app from a link instead of the official App Store or Google Play.
  • The page demands immediate payment or threatens a penalty if you don't act now.
  • It requests information the situation doesn't call for—Social Security number, full card details, or a two-factor code.
  • The destination is a shortened link you can't verify before opening.

How to scan QR codes safely

The FTC's advice comes down to a few simple habits:

  1. Preview the web address before you open it. Most phone cameras show the destination first—read it, and don't open anything that looks off. Our guide on how to scan a QR code walks through the preview step on iPhone and Android.
  2. Check for tampering. On a physical code, feel for a sticker layered over the original, and skip it if anything looks added.
  3. Be skeptical of unexpected codes. Don't scan one from an email, text, or package you weren't expecting—especially if it urges quick action.
  4. Verify before you pay. For parking or a restaurant, confirm the code goes to the official website (or ask a staff member) before entering card details.
  5. Never type passwords or payment details into a page you reached by scanning an unfamiliar code. Navigate to the site yourself instead.
  6. Keep your phone updated and turn on multi-factor authentication, so a stolen password alone can't open your accounts.

What to do if you scanned a malicious QR code

  1. Don't enter anything. If a page asks you to log in or pay and you're unsure, close it.
  2. If you already entered a password, change it immediately—and change it anywhere you reused it. Turn on two-factor authentication.
  3. If you shared card or bank details, call your bank or card issuer, flag the account, and ask about a replacement card.
  4. If you downloaded anything, delete it, run a security scan, and watch for unusual activity. Consider a factory reset if the device starts behaving strangely.
  5. Report it. File a complaint with the FBI's IC3 at ic3.gov and report the scam to the FTC at reportfraud.ftc.gov. Reporting helps investigators and warns other people.

For businesses: protect the QR codes you publish

If your business uses QR codes on signage, packaging, or flyers, you're a target too—a scammer who covers your code with theirs harms your customers and your brand. A few practices lower the risk:

  • Inspect your printed codes regularly for stickers or tampering, especially unattended ones on doors, tables, and parking areas.
  • Design codes as part of the surrounding artwork—with your logo and brand colors—so a plain sticker overlay looks obviously wrong.
  • Use a dynamic QR code you control, so if a printed code is ever reported compromised you can repoint it without reprinting.
  • Monitor scans. A dynamic code's scan analytics let you spot unusual spikes or scans from unexpected locations.
  • Always send scanners to your own verified domain, not a random short link, so customers can confirm they're in the right place.

No tool can stop someone from printing a malicious sticker out in the world, but controlling and monitoring your own codes—and designing them to be hard to imitate—makes tampering far easier to catch. If one of your codes stops working or behaves oddly, our guide on why a QR code isn't working can help you diagnose it.

Frequently asked questions

Can a QR code give you a virus?

Not on its own. A QR code can't install malware just by being scanned—it only contains data, usually a link. Infection requires a further step: visiting a malicious site and then downloading and installing a file. Don't install anything a scanned code prompts you to.

Can someone hack your phone through a QR code?

Scanning alone won't hack your phone. The attacker's goal is to trick you into an action afterward—entering credentials, approving a login, or installing an app. Keeping your operating system updated and using multi-factor authentication closes most of these paths.

How can I tell if a QR code is safe?

Preview the URL before opening it, make sure it matches the business and isn't a look-alike domain, check the physical code for sticker tampering, and never scan codes that arrive unexpectedly. When in doubt, type the address yourself instead of scanning.

Are the QR codes I create with a generator safe?

Yes. A QR code you generate simply encodes the destination you choose—it adds no risk of its own. The safety question is always about where a code points and whether it's been tampered with after printing. Design your codes to be recognizably yours, and use a dynamic QR code if you want the option to update or disable the destination later.

The bottom line

QR codes are convenient and, used carefully, perfectly safe. Quishing works by hiding a malicious link where you can't inspect it and adding a dose of urgency. Preview every URL, ignore codes you didn't expect, and never enter a password or payment on a page you reached by scanning an unfamiliar code—and you'll sidestep virtually every QR scam out there.

Sources