Scanning a QR code does not automatically mean your phone has been hacked. The risk depends on where the code led and what you did next. Use the sections below to find the steps that match your situation.
This page is for people who have already interacted with a suspicious QR code. If you want the broader explanation first, read the full QR Code Scams guide.
Quick orientation
Ask yourself:
- Did I only scan, or did I open a website?
- Did I enter a password, code, personal details or payment information?
- Did I download a file or install an app?
- Did I send money or approve a payment?
Then jump to the matching section.
I only scanned it
If you scanned the code and immediately closed the camera or preview without opening a site, entering information or downloading anything, your risk is usually lower.
Suggested steps
I opened the website
If a page opened but you did not enter information, download files or approve payments:
Suggested steps
Check whether the address looked legitimate. Fake sites often use lookalike domains, odd spellings or unexpected redirects. Learn more about quishing.
I entered my password
If you entered a password on a page reached through the QR code, treat that password as compromised for that account.
Password exposure checklist
I entered bank or card details
If you typed card numbers, banking login details or other payment credentials:
Payment details checklist
I entered personal information
Personal information can include your full name, address, date of birth, national identifiers, or answers to security questions.
Personal information checklist
I entered a verification code
One-time passcodes (OTPs), SMS codes and authenticator codes are often used to take over accounts.
Verification code checklist
I downloaded something
If a file downloaded after the scan:
Download checklist
If you already opened the file, continue to the next section and consider device security checks.
I installed an app
Unexpected apps installed after a QR scan can be risky.
App install checklist
If you cannot remove the app or your device behaves strangely, contact official support channels for your phone platform or a trusted technician.
I made a payment
If you paid money, transferred funds or approved a payment request:
Payment checklist
What not to do
- Do not send more money to fix the first payment
- Do not give remote access to your device to unexpected callers
- Do not reuse the suspicious page to “check whether it was real”
- Do not ignore account alerts hoping they will go away
After you stabilise the situation
Once the immediate steps are done:
- Review how the QR code was presented so you can spot similar attempts later
- Read How to Spot a Fake QR Code: 10 Warning Signs
- Learn how quishing works so urgent “scan to verify” messages are easier to question
- Return to the main QR Code Scams pillar for the wider context
A calmer way to think about it
You are not alone. QR codes are designed to be fast, and scammers rely on that speed.
The useful response is not shame. It is a clear sequence:
Stop. Look. Verify. — and if something already went wrong, take the next practical step for your situation.
Related guides
QR Code Scams: How They Work, Warning Signs & What to Do
Learn how QR code scams work, the warning signs to look for, how quishing works and what to do if you've scanned a suspicious QR code.
What Is Quishing? QR Code Phishing Explained
What is quishing? Learn how QR-code phishing works, where scammers use it and how to recognise and avoid QR-code phishing attacks.
How to Spot a Fake QR Code: 10 Warning Signs
Learn the 10 warning signs of a fake QR code, from suspicious URLs and unexpected payments to physical QR-code tampering.
QRaware provides educational information about QR-code scams and online fraud. It is not a substitute for professional cybersecurity, financial or legal advice.