Why Now Daily.

Published

How to Scan QR Codes Safely and Spot QR Phishing

QR codes can conceal malicious destinations, so users should verify the source and previewed address, avoid unexpected payment or login prompts and respond quickly if credentials or money were exposed.

Timeline

  1. Before scanning: Check the context, inspect physical labels for overlays and verify unexpected messages through an independent channel.
  2. Before opening or paying: Preview the destination and confirm the exact domain, payment recipient and requested permissions.
  3. After suspected exposure: Close the site, change exposed credentials from a trusted route, contact affected financial providers and report the fraud.

A QR code is a machine-readable container, not a guarantee that its contents are safe. It can open a website, start an app download, join a Wi-Fi network, address a message or prefill a payment. Because the destination is hidden inside the image, a malicious code can send a phone to a convincing imitation site before the user has examined the address. [1][2][3]

Scammers can paste a replacement code over a legitimate parking meter or sign, place one in an urgent email or text, or include one with an unexpected package. This is often called QR phishing or quishing. The code may lead to a page that steals passwords or card data, requests dangerous permissions, downloads software or redirects a payment to an attacker's account. [1][2][4]

Before scanning, ask whether the code and request make sense. Look for a sticker covering another code, damaged packaging, a missing sender or a message that creates urgency. Verify a payment request, failed-delivery claim or account warning by opening the company's known app, typing its official address or calling a verified number. Do not use contact details supplied in the suspicious message itself. [1][2][3]

Use the phone's built-in camera or a trusted built-in reader instead of downloading an unfamiliar scanner app. Configure the device to preview the action rather than launching it automatically. Read the complete domain before continuing and watch for substitutions, misspellings or unexpected URL shorteners. HTTPS encrypts a connection, but a scam site can also use HTTPS, so the domain and context still matter. [1][2][3]

Do not enter credentials or financial information merely because the page resembles a known service. Avoid installing an app from a QR destination; use the platform's official app store and search for the verified publisher. For payments, confirm the merchant name and amount in the payment interface before approving. A QR code received from a friend should be verified through a known channel if the request is unusual. [1][2][3]

Scanning alone does not always mean an account is compromised. If the code only opened a page, close it, avoid downloads and permissions, and update the device. If a password was entered, change it through the real service, change reused passwords and enable strong multifactor authentication. If card or bank information was exposed or money was sent, contact the provider immediately and review transactions. [2][3][4]

Preserve the message, package, URL, receipts and transaction details before deleting anything. Report U.S. internet fraud to the FBI's Internet Crime Complaint Center and identity theft through the appropriate official recovery route; other countries have local cybercrime channels. Fast reporting may help a bank or payment service stop a transaction, but recovery is not guaranteed. The safest habit is to treat every QR code as an unverified link until its source, destination and requested action all check out. [2][3][4]

Sources

  1. Canadian Centre for Cyber Security — Security Considerations for QR Codes
  2. FBI IC3 — Cybercriminals Tampering with QR Codes
  3. FTC — Scammers Hide Harmful Links in QR Codes
  4. FBI — Unsolicited Packages Containing QR Codes Used in Fraud

Related stories