Are QR Codes Safe? QR Code Phishing ("Quishing") Explained
A QR code is not inherently dangerous — it's a pattern that encodes a link or text, nothing more. The risk that's led to the term "quishing" (QR phishing) isn't a flaw in the QR standard itself; it's the same trust exploit that email phishing has always used, applied to a format where the destination isn't visible until after you've already scanned it.
What "quishing" actually is
With a normal link — in an email, a text, a webpage — you can often see the destination URL before clicking, or at least hover to preview it. A QR code hides that until the scan happens, which is exactly what makes it useful for its legitimate purposes (a code doesn't need visible text to work) and exactly what a scammer can exploit: a malicious QR code looks identical to a legitimate one, and there's no way to tell where it leads just by looking at the pattern.
The most common real-world version of this attack: a scammer prints a sticker with a fake QR code and places it over a legitimate one — on a parking meter, a restaurant table tent, a poster — so someone scanning what they believe is the real code actually gets sent to a phishing site instead, often one designed to steal payment information or login credentials.
What a malicious QR code can actually do
Scanning a QR code by itself, using your phone's built-in camera, does nothing more than open a link — it doesn't install anything or hand over any data on its own. The risk comes from what happens after you land on the destination: a convincing fake payment page asking for card details, a fake login page harvesting credentials, or a link designed to trick you into downloading something you shouldn't. The QR code is just the delivery mechanism; the actual harm happens on whatever page it opens, the same as it would with a malicious link sent any other way.
Practical ways to protect yourself
Check the URL preview before tapping through. Most phone cameras show the destination URL in a notification banner before opening it — actually read it rather than tapping automatically. A URL that doesn't match the business or context you expect (a misspelled domain, an unusual subdomain, a URL with no relation to where the sticker is posted) is a clear warning sign.
Be suspicious of a QR code that looks stuck-on or replaces something that should be printed directly. A code on a sticker layered over a menu, sign, or parking meter is easier to swap than one printed as part of the original material — this is the single most common tell in real-world quishing reports.
Be extra cautious with codes asking for payment or login information, especially in places where you wouldn't normally expect to enter payment details from a scan — a parking meter or a random flyer asking you to "pay via this QR code" is a common scam pattern, since legitimate parking systems rarely rely solely on a QR code with no other payment option.
Avoid scanning codes from unsolicited mail, email attachments, or unfamiliar senders the same way you'd avoid clicking a suspicious link — the caution that applies to email phishing applies identically here.
What legitimate QR codes look like from a business's side
For any business generating QR codes for genuine use — menus, event signage, marketing — the same practices that protect against being impersonated matter: use a printed code that's part of the original material rather than a separately affixed sticker where possible, and consider a note near the code confirming what it's for, so customers have a way to sanity-check what they're about to scan.
The short version
QR codes aren't unsafe by design — the risk is entirely in what a scanned link leads to, exactly like any other link-based phishing attempt. Reading the URL preview before tapping through, treating suspiciously placed stickers with skepticism, and being cautious with any code requesting payment or login details covers the practical risk without needing to avoid QR codes altogether.
This is general safety information, not a substitute for your bank's or platform's own fraud-prevention guidance — if you believe you've been targeted by a QR code scam involving payment or financial information, contact your bank or card provider directly.