QR Code Scams and Quishing
QR codes have a built-in trust problem: the pattern hides its destination until you scan it. You see a small square, but you can't tell whether it opens a menu, a payment page, or a fake login form designed to steal your password. Criminals have noticed, and QR-based phishing — nicknamed "quishing" — is now a routine tactic. The good news is that the defences are simple and don't require you to distrust every code you see.
How QR phishing actually works
The classic attack is physical tampering. A scammer prints a malicious QR code on a sticker and places it over a legitimate code — on a parking meter, a restaurant table, a poster, a package. When you scan, the code opens a convincing fake page: a payment screen for a parking fine, a login for your email, a survey that "rewards" you. Enter your details and they're captured.
The digital version arrives in email. A message that looks like it's from your bank, your courier, or your boss contains a QR code you're urged to scan — perhaps because "the link is blocked". Scanning moves the action from a computer to a phone, which bypasses many corporate security filters and, conveniently for the attacker, out of sight of trained email users.
Why do these work? Because scanning a code is a habit now. People tap "Open" almost reflexively, never glancing at the address that appears. The entire scam depends on that reflex — which means one small pause defeats it.
Preview the link before you open it
When a phone scans a QR code that points to a website, it shows a preview: the URL and the message "Open in browser?" in most camera apps. This preview is your checkpoint. Before tapping open:
- Read the domain. Does it match who you expected? A parking code should open the parking operator's site, not "pay-now-today.top".
- Check for typos. "paypa1-login.com" or "amaz0n-support.com" are red flags even when the real name is present.
- Distrust shortened links. Codes that resolve to
bit.ly/...or other shorteners hide the real destination. Legitimate services sometimes use them, but combined with an unexpected prompt, they're suspicious. - Unexpected prompt? Stop. If the page asks for a password, card number, or one-time code out of nowhere, close it. No organisation you're a customer of needs your password through a QR code on a parking meter.
SajiloQR's scanner makes this even easier: it shows you the decoded text before you decide whether to open anything, so a URL is visible in full rather than hidden behind a camera-app preview.
Look for tampering
Physical codes deserve a two-second inspection before scanning:
- A sticker on top of a sticker. The tell-tale sign of the classic swap. If a code looks raised, glossy, or misaligned over an older code, don't scan it.
- A code that looks out of place. A fresh, odd-looking code on a grubby meter or a poster you've seen for months is worth questioning.
- Cover the existing code? Legitimate replacement codes are usually installed cleanly, not slapped over the old one.
Email and messaging codes
- Never scan a code from an unexpected email or text that pressures you with urgency — "act now", "your account is locked", "verify within 24 hours". Urgency is the scammer's favourite tool.
- Verify the sender by another channel. If a "bank" email asks you to scan a code, call the number on your card, not the one in the email.
- Remember: real companies rarely need a QR code to get you to log in. They can just put a link on their own site.
Business owners: protect your own codes
If you run a venue, a shop, or anything with printed codes, you have a stake in this too. A customer scammed through a code in your business is bad for them and worse for your reputation:
- Check codes regularly, especially in busy, high-foot-traffic spots.
- Print codes that are hard to cover. Embed them inside a branded card or stand rather than as a loose sticker.
- Use a URL you own and keep it short, so a replacement code pointing elsewhere is easy to spot.
- Tell staff what to look for and how to report a suspicious sticker.
What to do if you think you've been scammed
- Don't panic and don't delete evidence. Screenshot the page and note where the code was.
- Change the password you entered immediately — and anything that uses the same one.
- If you entered card details or payment information, contact your bank or card issuer right away.
- Report it. Tell the business if the code was on their premises, and consider reporting to the local cybercrime unit or consumer protection authority.
The balanced view
None of this means QR codes are dangerous. They're a hugely useful technology — and they're also just text in a box. The safety rule is the same one that applies to every link on the internet: look before you open. Scan, read the destination, then decide. A single second of attention removes almost all the risk.
For a hands-on look at what a code actually contains, scan one with SajiloQR's scanner — it shows you the decoded text first, no page-opening required. If you'd like to understand the technology these scams rely on, see how QR codes work.