QR codes are useful. They open menus, speed up payments, share Wi‑Fi details and connect physical spaces to digital services.
They are also easy for scammers to misuse.
A QR code scam is fraud that uses a QR code to send someone to a malicious or deceptive destination — often a fake website designed to steal information, push a payment or install unwanted software.
This guide explains how QR code scams work, the warning signs to look for, how quishing fits in, and what to do if you have already scanned something suspicious.
How QR code scams work
A QR code is essentially a machine-readable shortcut. When you scan it, your device usually opens a website, app action or other destination encoded in the code.
Scammers exploit that convenience:
- They create a fraudulent destination (often a convincing fake website).
- They encode that destination into a QR code.
- They place the code somewhere people expect to scan — or overlay it onto a legitimate one.
- They push urgency, authority or fear so people act before thinking.
The code itself can look ordinary. The risk is usually what happens after the scan.
Common goals include:
- Stealing login credentials
- Collecting card or banking details
- Capturing one-time verification codes
- Tricking people into paying the wrong account
- Encouraging risky downloads or app installs
- Harvesting personal information for further fraud
What is quishing?
Quishing is phishing delivered through QR codes.
Instead of asking you to click a link in an email or text message, a scammer encourages you to scan a code. The destination can still be a fake login page, payment portal or “verify your account” screen.
Learn more in our full explainer: What Is Quishing? QR Code Phishing Explained.
Where QR code scams appear
QR scam attempts can show up almost anywhere people already expect to scan:
- Parking meters and payment signs
- Parcel and delivery notices
- Restaurant menus and posters
- Emails and text messages
- Letters claiming to be from banks, government or utilities
- Payment terminals and “scan to pay” stickers
- Event tickets and venue materials
- Shared workspace or public noticeboards
Physical tampering is a recurring theme: a genuine printed code covered by a sticker leading elsewhere.
Common types of QR code fraud
Fake login pages
You scan a code and land on a page that looks like your bank, email provider, delivery company or workplace login. Anything you enter can be captured.
Fake payment or top-up flows
A code may claim you need to pay for parking, postage, a fine or an unpaid bill. The branding can look familiar while the destination is controlled by someone else.
Delivery and parcel scams
Notices may say a parcel is waiting, held or needs a fee. The QR code leads to a form asking for personal data, card details or a payment.
Account “verification” and support scams
Urgent messages claim your account will be locked unless you scan and verify. Genuine organisations rarely ask you to handle security emergencies through an unexpected QR code.
Malicious downloads
Some destinations push you to install an app or open a file. Treat unexpected download prompts after a scan as a serious warning sign.
Warning signs of a fake QR code
You can often reduce risk by pausing and checking context. For the full list with practical actions, see How to Spot a Fake QR Code: 10 Warning Signs.
Key signs include:
- You were not expecting the code
- You are being rushed
- It looks like a sticker placed over something else
- The destination URL looks wrong
- You are asked for sensitive information
- You are asked for an unexpected payment
- Branding looks almost right, but something feels off
- You are told to download something
- The code does not match its surroundings
- The story does not make sense
What to do if you scanned a suspicious QR code
Scanning alone is not the same as being “hacked.” What matters is what happened next.
If you are already worried, go straight to:
I Scanned a Scam QR Code — What Should I Do?
That guide covers scenarios such as:
- Only scanned the code
- Opened a suspicious website
- Entered a password
- Entered bank or card details
- Shared personal information
- Entered a verification code
- Downloaded something or installed an app
- Made a payment
How to stay safer with QR codes
Use this practical checklist:
Safer scanning checklist
Reporting and getting further help
If you believe you have been targeted or lost money:
- Contact your bank or payment provider immediately if money or card details are involved
- Change passwords on affected accounts from a device and site you trust
- Report suspicious messages or fraud through your local reporting channels where available
- Seek official guidance from recognised authorities
Useful starting points from recognised organisations include the UK National Cyber Security Centre, UK government cyber guidance, the US Federal Trade Commission, and CISA. Local banks and payment providers also publish fraud reporting advice.
Stop. Look. Verify.
QRaware’s principle is simple:
- Stop — don’t scan on autopilot
- Look — check source, context and destination
- Verify — confirm the request independently
QR codes will keep appearing in daily life. Safer scanning is not about fear. It is about a short pause and a few practical checks.
Next steps
- Need urgent next steps? Read I Scanned a Scam QR Code — What Should I Do?
- Want the definition and examples? Read What Is Quishing?
- Want prevention tips? Read How to Spot a Fake QR Code
Frequently asked questions
Does scanning a QR code automatically hack my phone?
No. Scanning a QR code does not automatically mean your phone has been hacked. The risk depends on where the code leads and what you do after you scan it — such as entering passwords, payment details or downloading software.
Are all QR codes dangerous?
No. QR codes have many legitimate uses. The risk comes from unexpected, tampered or poorly contextualised codes that lead to fraudulent destinations.
What should I do if I already scanned a suspicious QR code?
Don't panic. What matters is what happened after you scanned it. Follow the step-by-step guide for your situation — whether you only scanned, opened a site, entered details, downloaded something or made a payment.
Related guides
I Scanned a Scam QR Code — What Should I Do?
Scanned a suspicious QR code? Learn what to do if you entered a password, shared payment details, downloaded something or made a payment.
What Is Quishing? QR Code Phishing Explained
What is quishing? Learn how QR-code phishing works, where scammers use it and how to recognise and avoid QR-code phishing attacks.
How to Spot a Fake QR Code: 10 Warning Signs
Learn the 10 warning signs of a fake QR code, from suspicious URLs and unexpected payments to physical QR-code tampering.
QRaware provides educational information about QR-code scams and online fraud. It is not a substitute for professional cybersecurity, financial or legal advice.