Skip to content
QRaware

QR Code Scams: How They Work, Warning Signs & What to Do

Learn how QR code scams work, the warning signs to look for, how quishing works and what to do if you've scanned a suspicious QR code.

QR codes are useful. They open menus, speed up payments, share Wi‑Fi details and connect physical spaces to digital services.

They are also easy for scammers to misuse.

A QR code scam is fraud that uses a QR code to send someone to a malicious or deceptive destination — often a fake website designed to steal information, push a payment or install unwanted software.

This guide explains how QR code scams work, the warning signs to look for, how quishing fits in, and what to do if you have already scanned something suspicious.

How QR code scams work

A QR code is essentially a machine-readable shortcut. When you scan it, your device usually opens a website, app action or other destination encoded in the code.

Scammers exploit that convenience:

  1. They create a fraudulent destination (often a convincing fake website).
  2. They encode that destination into a QR code.
  3. They place the code somewhere people expect to scan — or overlay it onto a legitimate one.
  4. They push urgency, authority or fear so people act before thinking.

The code itself can look ordinary. The risk is usually what happens after the scan.

Common goals include:

  • Stealing login credentials
  • Collecting card or banking details
  • Capturing one-time verification codes
  • Tricking people into paying the wrong account
  • Encouraging risky downloads or app installs
  • Harvesting personal information for further fraud

What is quishing?

Quishing is phishing delivered through QR codes.

Instead of asking you to click a link in an email or text message, a scammer encourages you to scan a code. The destination can still be a fake login page, payment portal or “verify your account” screen.

Learn more in our full explainer: What Is Quishing? QR Code Phishing Explained.

Where QR code scams appear

QR scam attempts can show up almost anywhere people already expect to scan:

  • Parking meters and payment signs
  • Parcel and delivery notices
  • Restaurant menus and posters
  • Emails and text messages
  • Letters claiming to be from banks, government or utilities
  • Payment terminals and “scan to pay” stickers
  • Event tickets and venue materials
  • Shared workspace or public noticeboards

Physical tampering is a recurring theme: a genuine printed code covered by a sticker leading elsewhere.

Common types of QR code fraud

Fake login pages

You scan a code and land on a page that looks like your bank, email provider, delivery company or workplace login. Anything you enter can be captured.

Fake payment or top-up flows

A code may claim you need to pay for parking, postage, a fine or an unpaid bill. The branding can look familiar while the destination is controlled by someone else.

Delivery and parcel scams

Notices may say a parcel is waiting, held or needs a fee. The QR code leads to a form asking for personal data, card details or a payment.

Account “verification” and support scams

Urgent messages claim your account will be locked unless you scan and verify. Genuine organisations rarely ask you to handle security emergencies through an unexpected QR code.

Malicious downloads

Some destinations push you to install an app or open a file. Treat unexpected download prompts after a scan as a serious warning sign.

Warning signs of a fake QR code

You can often reduce risk by pausing and checking context. For the full list with practical actions, see How to Spot a Fake QR Code: 10 Warning Signs.

Key signs include:

  1. You were not expecting the code
  2. You are being rushed
  3. It looks like a sticker placed over something else
  4. The destination URL looks wrong
  5. You are asked for sensitive information
  6. You are asked for an unexpected payment
  7. Branding looks almost right, but something feels off
  8. You are told to download something
  9. The code does not match its surroundings
  10. The story does not make sense

What to do if you scanned a suspicious QR code

Scanning alone is not the same as being “hacked.” What matters is what happened next.

If you are already worried, go straight to:

I Scanned a Scam QR Code — What Should I Do?

That guide covers scenarios such as:

  • Only scanned the code
  • Opened a suspicious website
  • Entered a password
  • Entered bank or card details
  • Shared personal information
  • Entered a verification code
  • Downloaded something or installed an app
  • Made a payment

How to stay safer with QR codes

Use this practical checklist:

Safer scanning checklist

Reporting and getting further help

If you believe you have been targeted or lost money:

  • Contact your bank or payment provider immediately if money or card details are involved
  • Change passwords on affected accounts from a device and site you trust
  • Report suspicious messages or fraud through your local reporting channels where available
  • Seek official guidance from recognised authorities

Useful starting points from recognised organisations include the UK National Cyber Security Centre, UK government cyber guidance, the US Federal Trade Commission, and CISA. Local banks and payment providers also publish fraud reporting advice.

Stop. Look. Verify.

QRaware’s principle is simple:

  • Stop — don’t scan on autopilot
  • Look — check source, context and destination
  • Verify — confirm the request independently

QR codes will keep appearing in daily life. Safer scanning is not about fear. It is about a short pause and a few practical checks.

Next steps

Frequently asked questions

Does scanning a QR code automatically hack my phone?

No. Scanning a QR code does not automatically mean your phone has been hacked. The risk depends on where the code leads and what you do after you scan it — such as entering passwords, payment details or downloading software.

Are all QR codes dangerous?

No. QR codes have many legitimate uses. The risk comes from unexpected, tampered or poorly contextualised codes that lead to fraudulent destinations.

What should I do if I already scanned a suspicious QR code?

Don't panic. What matters is what happened after you scanned it. Follow the step-by-step guide for your situation — whether you only scanned, opened a site, entered details, downloaded something or made a payment.

Related guides

QRaware provides educational information about QR-code scams and online fraud. It is not a substitute for professional cybersecurity, financial or legal advice.