phishing

QR Code Scams (Quishing): Think Before You Scan

The link you can't read

For years, the first rule of not being phished was to look at a link before you followed it — read the web address, check the spelling, make sure it goes where it claims. A QR code quietly deletes that rule. A little square of dots is not a web address you can read; it is a web address you cannot read, wrapped so your phone will open it the instant your camera lands on it. You are asked to trust a destination you have not been allowed to see.

That is the whole reason scammers love them. Fraud carried out through QR codes even has its own name now — quishing, a mash-up of "QR" and "phishing" — and it has spread with the codes themselves, which sit on restaurant tables, car park meters, posters, parking tickets, electric-vehicle chargers and the backs of leaflets. This article explains why the format is so useful to criminals, where the fake codes turn up, and how to put the missing step — reading the link — back before you scan.

Why a QR code is the perfect disguise

A phishing email at least shows you something to be suspicious of: a sender, a link, a tone. A malicious QR code shows you almost nothing. There is no readable address to inspect, no hover-to-preview, no spelling to check. To the eye, a fraudulent code and a genuine one are identical — both are just patterns of squares — so all the habits that protect you from a bad link are switched off before you start.

Two other properties make it worse. A QR code is physical: it can be printed on a sticker and slapped over a real one in the street, somewhere no website filter or spam folder can intervene. And it deliberately moves you from a device that might be protected — a work computer with security filtering — onto your personal phone, which is usually watching your back far less carefully. The code is not just hiding the link; it is choosing the ground on which you will meet it.

Where the fake codes turn up

Quishing lives in a handful of reliable settings. Knowing them turns "a QR code" from something neutral into something you evaluate.

A sticker over the real thing

The most physical version is also the simplest. A scammer prints a QR code on an adhesive label and sticks it on top of a legitimate one — on a parking meter, an EV charging point, a public notice, a table sign. You scan what looks like the official code to pay for parking or view a menu, and you are taken to a convincing fake that collects your card details and personal information. The giveaway, when there is one, is physical: a sticker sitting proud of the surface, a code that does not match the surrounding branding, or one that has plainly been added over something else. It is always worth a fingernail's worth of suspicion in a public place.

A code inside an email or letter

Increasingly, phishing messages carry a QR code instead of a clickable link, precisely to slip past the filters that inspect links and to push you onto your phone. An email supposedly from your bank, your employer's IT team or a delivery firm asks you to "scan to verify", "scan to reschedule" or "scan to reset your password". Stop there. There is almost never a legitimate reason an email needs you to point your phone's camera at it to do something you could do by going to the site directly. A QR code arriving in an unexpected message is a warning in itself — treat it exactly as you would a suspicious link, using the same instincts covered in how to spot a phishing email.

A fake fine or a missed-parcel card

Physical post and windscreen notices have joined in: a "parking charge" card, an "unpaid toll" notice, a "we missed you" delivery slip, each printed with a QR code that leads to a payment page run by nobody official. The design can be excellent, because copying a logo costs nothing. The same principle applies — the code decides where you go, and you have not been shown the address.

What happens after you scan

Scanning a malicious code rarely does anything dramatic on the spot. It simply opens a web page, and from that point on it is ordinary phishing. The page will look like a login screen, a payment form or a verification step, and it will ask for exactly the things a scam always wants: your card number, your bank sign-in, your personal details, or a one-time code. A padlock in the address bar will do nothing to save you — as the padlock myth explains, a fraudulent page can carry encryption as easily as a real one. Everything you already know about spotting a fake website still applies; the QR code just deprived you of the early warning.

That is the key mental shift. A QR code is not a magic action; it is a doorway to a website. The moment you think of it that way, the question becomes the same one you would ask of any link: is this genuinely the organisation it claims to be, and did I go looking for this, or did it come looking for me?

Scanning without getting caught

You do not have to swear off QR codes. You have to restore the step the format removed — seeing the address — and add a little physical suspicion.

| Where you meet a code | The risk | The safer move | | --- | --- | --- | | A public sign or meter | A sticker placed over the real code | Check for tampering; prefer the official app or a typed-in address | | An email or text | A code that dodges link filters | Don't scan; go to the organisation directly | | A parking or fine notice | A fake payment page | Pay through the official website or app you find yourself | | A restaurant or poster | A swapped or overlaid code | Fine for a menu; never enter card or login details |

The single most valuable habit is to preview the address before opening it. Most modern phone cameras show the web address a code points to as a small banner or pop-up before they open anything — pause and read it. Ask whether the domain is really the organisation's own, or a lookalike with extra words. If your camera opens links instantly without showing you where they lead, that setting is worth turning off so you always get the preview. And when a code wants money or a login, the safest path almost never runs through the code at all: open the parking app you already use, or type the company's known address into your browser, and arrive on your own terms.

If a QR code reached you inside a message and you suspect it, the National Cyber Security Centre still wants the email — forward it to [email protected] — and a scam you have run into in the physical world can be reported so others are warned — through Action Fraud if you are in England, Wales or Northern Ireland, or by calling Police Scotland on 101 north of the border.

Before you go

A QR code asks for a strange kind of trust: point your camera here, and go wherever this takes you, sight unseen. We would never accept that from a stranger who handed us a folded note and said "just ring whatever number is inside". A QR code is that folded note, and it deserves the same reflex — unfold it first. The camera preview is your unfolding. Read the address it reveals, decide whether you would have typed it in yourself, and only then, if at all, proceed.

Put that one step back and quishing loses almost all of its power, because its power was never in the code — it was in the second you skipped between scanning and landing. Once you have unfolded a code into a plain web address, that address is exactly the sort of thing the CheckAScam checker is being built to weigh, though the tool is still a work in progress and only ever as useful as your decision to look before you scan. The dots on the sticker are not the danger. Arriving somewhere without ever having chosen to go there is.

Frequently Asked Questions

Can scanning a QR code hack my phone straight away?

In almost all cases, no. Scanning a code normally just opens a web page, in the same way tapping a link does; it does not silently take over your phone. The danger is what that page then does — imitating a bank, a car park or a login screen and asking you to type in card details, passwords or a one-time code, which is ordinary phishing carried out through a channel you could not inspect first. Keeping your phone's software up to date reduces the small residual risk of a malicious page trying anything cleverer, but the realistic threat is what you are persuaded to enter, not the scan itself.

How do I check where a QR code leads before I open it?

Use your camera's preview. Most modern phones display the web address a code contains as a banner or pop-up before they open it, so you can read the destination and decide. Look at the domain — the main site name — and ask whether it is genuinely the organisation you expect or a lookalike with extra words attached. If your camera jumps straight to opening links without showing you the address, change that setting so it asks first. When the code claims to be for a payment or a login, the most reliable approach is to skip it and reach the organisation yourself through its official app or a web address you type in.

Why would a real company put a QR code in an email?

Usually it would not, at least not for anything sensitive like signing in, resetting a password or making a payment. Those are things you can and should do by going to the company's website or app directly, so a message insisting you scan a code to handle them is a strong warning sign that it is phishing trying to move you onto a less-protected phone. Codes in marketing emails that simply open a public page are less concerning, but the rule of thumb holds: never scan a code from an unexpected message to do something that involves your money, your login or your personal details.

More From CheckAScam

Want more ways to stay safe?

Browse our full library of plain-English guides — how to spot fake shops, safe ways to pay, and how to get your money back if something goes wrong.

Browse the Guides