Person scanning a QR code on a smartphone with visual cues for phishing, credential theft, mobile security, financial fraud, and suspicious payment risks.

QR Code Scams: How to Check Links Before You Scan, Log In, or Pay

Category: Cybersecurity

QR codes are everywhere, from restaurant menus and parking meters to packages, invoices, payment screens, and work logins. Most are harmless, but their design creates one awkward security problem: you cannot see the destination until your device reads the code. Scammers use that hidden step to steer people toward fake websites, stolen passwords, fraudulent payments, and malicious downloads. Knowing what to check first makes QR code scams much easier to spot.

What a QR Code Really Contains

A QR code may look complicated, but what it does is fairly simple. It is a two-dimensional barcode that stores information in a pattern your phone or scanner can read. According to DENSO WAVE’s explanation of QR codes, that information can include letters, numbers, symbols, and other types of data. In everyday life, a QR code often contains a web address, although it can also hold contact information, Wi-Fi details, payment data, or other instructions.

What it does not contain is some built-in stamp of trust. There is nothing about the black-and-white pattern itself that tells you whether a restaurant created it, a parking company printed it, or a scammer made it five minutes ago. Two QR codes can look almost identical while sending people to completely different places.

That is really the part worth remembering. The important security check is not the square you see on the sign. It is what appears on your phone after the code has been read.

Why QR Code Scams Work

QR code scams take advantage of something very ordinary: routine. People have grown used to scanning codes without thinking much about it. You sit down at a restaurant, scan the menu, and move on. A parking meter asks for a scan. You scan it. An email says there is a document waiting. Again, the action feels normal.

Scammers know that. The Federal Trade Commission warns that malicious QR codes can send people to fake websites designed to steal information or expose devices to malware. QR-based phishing is often called quishing, which is simply a mix of “QR” and “phishing.”

The trick works because the code removes something people normally rely on when judging a link: visibility. With a regular web address, you may notice that something looks strange before clicking. A QR code hides that information until after the scan.

Once the fake page opens, the scam itself may look very familiar. Sign in to verify your account. Enter a card number. Confirm your identity. Download this file. Nothing dramatic is required. The attacker only needs the request to feel believable for a few seconds.

Public QR Codes Can Be Swapped

A QR code does not have to be hacked to become dangerous. Sometimes the scam is surprisingly low-tech. Someone prints a different QR code on a sticker, walks up to a parking meter or public sign, and covers the real code.

The FBI has warned about tampered QR codes being used to redirect people to malicious websites that collect login credentials and financial information. The same basic trick can work on restaurant tables, kiosks, charging stations, posters, donation signs, payment terminals, and other places where people expect to find QR codes.

Before scanning a public code, take a quick look at the physical label. A few things are worth noticing:

  • A sticker has been placed directly over another label or QR code.
  • The edges are peeling, crooked, bubbled, or oddly positioned.
  • The colors or branding do not match the rest of the sign.
  • The payment page names a company you were not expecting.
  • The QR code looks added later instead of being part of the original display.

None of those signs proves a scam. A legitimate business can use stickers too. Still, something that looks off deserves a second check. If money is involved, use the company’s official app, enter its known website yourself, or ask an employee how payment is supposed to work.

Packages Can Hide QR Code Traps

Unexpected packages create a different kind of QR scam. Here, curiosity does most of the work.

A box may arrive with a card inside saying, “Scan to see who sent your gift,” “Scan for return instructions,” or “Register your item here.” The card may be glossy, professionally printed, and convincing enough that scanning it feels harmless.

That appearance is not proof of anything. The FTC has specifically warned about QR codes inside unexpected packages. The agency says these codes may lead to phishing websites that ask for usernames, passwords, credit card numbers, or other personal information. They may also expose the device to malicious software.

If something arrives that you never ordered, check your real shopping accounts first. Look at your purchase history. Contact the retailer through a website or app you already use. Do not let a mystery package choose the website you visit next.

A printed card can look official. So can a scam.

QR Phishing Can Jump Devices

Email QR scams have another advantage for attackers: they can move the victim from one device to another.

Imagine opening an email on a company computer. The message says your Microsoft password is expiring and includes a QR code. Instead of clicking a normal link, you scan the image with your phone. The suspicious website has now opened on a different device, possibly outside some of the protections used on the work computer.

Microsoft has documented QR code phishing in email as a growing attack method. In its Q1 2026 threat analysis, Microsoft reported that QR-code phishing was the fastest-growing email attack vector it observed during that quarter.

These messages do not need to be clever. A password is supposedly expiring. Payroll needs attention. A secure document is waiting. Your account must be verified. The language can be dull and routine, which is partly why it works.

Treat an unexpected QR code in an email or text the same way you would treat an unexpected link. A logo, company name, invoice number, or urgent warning does not prove the message came from the company it claims to represent.

Check the Domain Before You Tap

When your phone reads a QR code, it may show a preview of the destination before opening it. That preview is easy to ignore, especially when you are in a hurry. It is also one of the best chances you have to catch a scam before anything else happens.

Suppose you expect PayPal, but the preview shows:

paypal-account-security.example.com

At a quick glance, the word “paypal” may be enough to look convincing. But in this example, the actual domain is example.com, not PayPal.

CISA’s phishing recommendations encourage users to inspect suspicious links and verify unusual requests through trusted methods. Scammers know people skim addresses, so they may add familiar words such as “secure,” “login,” “billing,” “account,” or “verification” to make a fraudulent domain look believable.

Those words are not automatically suspicious. Legitimate websites use long addresses and subdomains all the time. What matters is the actual domain and whether it belongs to the company you expected.

Misspellings, extra letters, odd domain endings, or very long addresses are also worth noticing. If the destination does not make sense, do not try to reason your way into trusting it. Close the preview and visit the company through its normal website or app.

HTTPS Does Not Prove a Site Is Real

HTTPS is useful, but it is often misunderstood.

When a website uses https://, the connection between your browser and that site is encrypted. That helps protect information while it travels between the two. What HTTPS does not automatically tell you is whether the website belongs to the company you think it does.

CISA’s information on website certificates and secure connections explains how certificates support encrypted web connections. For a regular user, the important distinction is straightforward: a secure connection and a trustworthy website are two different things.

A scam website can use HTTPS for its own domain. So can a fake login page. If you expected to reach your bank but ended up on a strange address, seeing a secure connection does not fix the problem.

Check the domain. HTTPS matters, but it is only one piece of the picture.

Short Links Hide Even More

Shortened URLs are common and often perfectly legitimate. Businesses use them for advertising, social media, analytics, and easier sharing. A QR code may point to one too.

The problem is visibility. A short link can hide the final website, which removes another clue you might otherwise use to judge the destination.

The University of Michigan’s shortened URL security advice notes that attackers can also use shortened links to send people to phishing pages or malware.

If a QR preview only shows something like bit.ly followed by a short string of characters, you may have no obvious way to tell where the link ends up. That does not mean the link is malicious. It does mean you know less about it.

For a restaurant menu, that may not bother you much. For a bank login, payment page, software download, or account-verification request, it should. When sensitive information is involved, going directly to the company’s known website is the cleaner choice.

Login Pages Deserve a Closer Look

A QR code that opens a sign-in page should get more attention than one that opens a menu or event schedule.

Before entering a password, ask yourself a few things. Did you actually start this process? Is the domain correct? Were you expecting to sign in? Can you reach the same page through the company’s normal app or website?

Fake Microsoft, Google, Apple, banking, payroll, and cloud-service login screens can be convincing. Some are built to look almost identical to the real thing. That makes visual appearance a poor security test.

Using multifactor authentication on important accounts can make a stolen password less useful to an attacker because another form of verification is usually required. Still, MFA is not a reason to trust a questionable login page. Some authentication methods can also be phished if someone is tricked into entering a one-time code or approving a login request.

If a QR scan unexpectedly lands you on a sign-in screen, close it. Open the service the way you normally would and check the account from there.

Check QR Payments Before Sending Money

Payment QR codes save time. Scan, confirm, pay. That speed is useful right up until the code points to the wrong recipient.

A replaced QR code or fraudulent payment request can send money somewhere you never intended. Before approving the transaction, look at what the payment app actually shows. Check the recipient, business name, payment provider, wallet information, and amount whenever those details are available.

The FBI has also warned about QR codes used in cryptocurrency payment scams. Its 2026 guidance cautions people about instructions from strangers telling them to scan a QR code and send money through a cryptocurrency kiosk.

Urgency should make you more suspicious, not less. A caller or message claiming that you must pay immediately to avoid arrest, utility shutoff, account closure, or some other disaster is creating pressure for a reason.

Before sending money, verify the request another way. Once certain payments leave your account, getting them back may be difficult or impossible.

What to Do After a Suspicious Scan

Scanning a questionable QR code does not automatically mean your phone has been infected or your accounts have been stolen. What happened after the scan matters.

Seeing a destination preview and closing it is very different from opening a page, typing in a password, installing software, approving permissions, or sending money. Your response should match what you actually did.

The FTC’s QR code scam recommendations offer practical steps for protecting accounts and devices after a suspicious interaction:

  • If you entered a password, change it through the legitimate website or app. Change it elsewhere too if you reused that password.
  • If you entered card information, contact the card issuer and review recent transactions.
  • If you sent money, contact the bank or payment provider as soon as possible.
  • If you installed an unfamiliar app, remove it and review the permissions it received.
  • If you gave away personal information, watch for follow-up scams or signs of identity theft.
  • If a work account or company device was involved, report it to the appropriate IT or security contact.

Start with what you know. If you handed over a password, deal with the password. If you sent money, contact the financial institution. That is far more useful than spending hours wondering whether the page looked suspicious enough to count as a scam.

Businesses Should Protect QR Codes

Businesses that publish QR codes have some responsibility here too. A code on a restaurant table, storefront, invoice, reception desk, event sign, or payment display can be copied or covered. If customers rely on those codes, someone at the business should occasionally check that they are still intact.

Businesses can also make QR codes easier to verify. A sign that says “Scan to order at restaurantname.com” gives the customer a destination to expect before the phone even reads the code. That small detail adds context.

Avoid unnecessary URL shorteners for sensitive actions. Remove codes that are no longer used. Test active codes from time to time to make sure they still lead to the correct page.

Employee training matters as well. CISA recommends that small and medium-sized businesses teach employees to recognize phishing, and QR codes belong in that conversation. Employees who handle invoices, payments, customer signs, or account logins should know that a QR code can carry the same kind of phishing risk as a suspicious link.

A QR-code policy does not need to be complicated. Employees should know who creates approved codes, where those codes belong, and what destination people should expect when they scan them.

How JENI® Fits Into the Picture

JENI® is not a QR-code scanner or phishing detector, and it does not replace mobile security tools. Its role is different. JENI® helps maintain supported Windows and macOS computers by cleaning unnecessary files, performing trusted operating system maintenance and repair tasks, and helping the computer run efficiently without a background service.

That distinction matters because QR-code scams are often social-engineering attacks. A maintenance program cannot decide whether the code on a parking meter was replaced by a scammer, or whether an email asking you to scan a Microsoft login code is legitimate.

Good device maintenance still has value. Keeping systems updated, stable, and properly maintained supports the device you use every day. But the human part of QR security remains just as important: checking destinations, questioning unexpected requests, and protecting account credentials before handing them over.

QR Code Scam FAQs

Can scanning a QR code infect my phone?

Simply reading or decoding a QR code does not automatically mean your phone has been infected. The risk rises if the code leads to malicious content and you then install software, approve permissions, enter sensitive information, or interact with something harmful.

How can I tell if a QR code is fake?

You usually cannot judge a QR code by looking at the black-and-white pattern alone. Check for signs of physical tampering, read the destination preview carefully, and make sure the actual domain matches the business or service you expected.

Are restaurant QR codes okay to scan?

Most restaurant QR codes are legitimate, but any public code can potentially be covered or replaced. Look at the physical label and confirm that the destination belongs to the restaurant before opening the page.

What does quishing mean?

Quishing is a form of phishing that uses a QR code to send someone to a deceptive or malicious destination. The attack may be designed to steal passwords, collect payment details, deliver malware, or trick the victim in another way.

Do I need a separate QR scanner app?

Most modern smartphones already include QR-reading features, so a separate scanner app is often unnecessary. Whatever scanner you use, the more important step is checking where the code wants to send you before continuing.

Know Where a QR Code Is Sending You

QR codes are useful because they remove friction. Instead of typing a long web address, you point a camera at a square and get there almost instantly. That convenience is exactly why people use them, and it is also why scammers like them.

The FBI’s QR code security recommendations include checking web addresses, avoiding suspicious downloads, protecting login and financial information, and verifying payment destinations before sending money. Those are simple precautions, but they cover a surprisingly large number of QR-code scams.

The main rule is easy to remember: a QR code is not proof that the destination is legitimate. Look at where it leads. Make sure the request makes sense. Pay closer attention when a scan leads to a login page, payment request, download, or form asking for personal information.

Most QR codes will never cause a problem. You do not need to be afraid of scanning them. You just need to stop treating the square itself as a reason to trust what comes next.

Related Articles

Phishing and Malware: Spot the Warning Signs

Learn how phishing and malware attacks fool users, which warning signs matter most, and what to check before entering passwords, opening links, or downloading files.

Social Engineering: How Scammers Trick You

See how scammers use urgency, trust, fear, and familiar brands to manipulate people, plus practical ways to recognize social engineering before it works.

Mobile Cyber Threats: Protect Your Phone

Understand common threats that target phones and tablets, including malicious links, risky apps, account theft, and simple steps that can reduce your exposure.

Fake Security Alerts: Spot Phishing Emails

Learn how fake security alert emails create urgency, imitate trusted companies, and steal credentials, plus what to check before clicking links or signing in.

Published on August 19, 2026 at 9:29 AM by:

Geoffrey has decades of hands-on experience in IT, software development, and cybersecurity, bringing expert technical insight to every article. He holds two IT bachelor’s degrees, a business degree, and a master’s degree in Cybersecurity and Information Assurance.