QR Code Scams Are Real: How to Check a Code Before You Scan It

QR Code Scams Are Real: How to Check a Code Before You Scan It

QR codes are unreadable by design. That is the point of them — they hold more data than a human could usefully read, and a phone camera decodes them instantly. It is also the vulnerability, because a code gives you no indication of where it leads until you have already gone there.

Attackers noticed. The technique has a name now, quishing, and it is common enough that several national fraud agencies have issued warnings about it.

Why it works so well

The economics are lopsided in the attacker's favour. Printing a sheet of stickers costs a few pounds. Placing one over the legitimate code on a parking meter takes two seconds and looks like nothing. There is no email header to inspect, no sender address to check, no hovering over a link to see where it goes.

And the context does the persuading. Someone scanning a code on a parking meter already intends to enter their card details. The scam does not need to convince them of anything — it only needs to be there.

The common placements are parking meters and pay-and-display machines, restaurant tables, electric vehicle charging points, posters in transit stations, and parcel delivery notices posted through the door. All of them share the same property: you are expecting a code, so an unexpected one does not feel unexpected.

What usually happens next

A payment page. The most common outcome. A convincing copy of the parking operator's site, or a generic payment form. You enter your card details and they go to the attacker.

A credential page. A fake login for a service you use, harvesting your password.

A Wi-Fi network. QR codes can contain network credentials, and phones will join automatically. Joining an attacker-controlled network puts them between you and everything you do.

An app install prompt. Less common on iOS, more of a risk on Android where sideloading is possible.

The one habit that defeats most of this

Read the code before you act on it.

Most phone cameras show a preview of the URL before opening it. The problem is that the preview is small, it appears briefly, and the instinct is to tap it. Slowing down for two seconds and actually reading the domain catches the large majority of these attacks.

What to look for in the domain:

  • Does it match the organisation? A council parking code leading to a .xyz domain, or to a name you have never heard of, is the whole answer.
  • Is it a URL shortener? A legitimate business rarely needs to hide its own domain behind bit.ly on a printed sign. Shorteners on physical signage deserve suspicion.
  • Look for lookalike spellings. An rn that reads as an m. A digit 1 standing in for an l. An extra hyphen. These are designed to survive a quick glance.
  • Check where the real domain ends. In yourbank.com.secure-login.xyz, the actual domain is secure-login.xyz. Everything before it is decoration. Read from the right, starting at the last dot.

If you want to inspect a code properly rather than squinting at a preview, decode it as text first. Our QR Code Reader shows the full destination without opening it, and the decoding happens in your browser so nothing is transmitted anywhere.

Checking the physical code

Before scanning anything in public, run a finger over it. A sticker applied on top of a printed surface has an edge you can feel, and it often has a slightly different finish or a visible corner lifting. On a parking meter or a charging point, where the original code is usually printed directly onto the machine or under a laminate, any sticker at all is worth questioning.

If a code looks like it was added after the fact, it probably was.

Codes that arrive rather than codes you find

An increasingly common variant puts the QR code in an email or a letter, because a code in an image survives spam filters that would catch the same URL as text.

The usual pretexts are a delivery that needs rescheduling, an account requiring verification, a tax refund, or a payment that failed. All of them manufacture urgency, which is the tell.

The rule for these is the same as for any unexpected message: do not use the route provided. If your bank appears to need something, open the app you already have. If a parcel needs rescheduling, go to the courier's site directly. The legitimate version of the message will still be there when you arrive by your own route.

If you have already scanned one

Scanning alone is usually harmless — decoding a code does not run anything. The risk begins with what you do on the page it opened.

If you entered card details, contact your bank and freeze the card. If you entered a password, change it on the real site immediately and anywhere else you reused it. If you joined a Wi-Fi network, forget the network and treat anything you did while connected as potentially observed.

The short version

  • Read the domain before you tap, every time
  • Feel for a sticker on any code in a public place
  • Treat a shortener on printed signage as suspicious by default
  • Read a domain from the right, starting at the last dot
  • Never use a code from an unexpected message; go to the site yourself

Written by MUhammad Sabir Uppal

Muhammad Sabir Uppal is the creator of TU Web Tools, a growing platform offering over 21 free, browser-based utilities for developers, SEO professionals, and everyday users. Focused on speed, privacy, and mobile-friendly design, TU Web Tools provides instant solutions for text formatting, encoding, SEO analysis, and password management without requiring installation or signup. Muhammad is dedicated to building secure, accessible online tools that help people work faster and more efficiently, and he regularly shares practical guides and tutorials on developer and productivity topics.

Try the tools mentioned in this guide

All TU Web Tools utilities are free, browser based and need no signup.

Browse all tools

Related articles