Skip to main content
QRSenBuilt for business
Are QR Codes Safe? QR Code Phishing ("Quishing") Explained — QR code guide cover illustration
Security

Are QR Codes Safe? QR Code Phishing ("Quishing") Explained

6 min readAugust 5, 2026By Editorial Team
Security Guide

QR codes are not inherently dangerous — the risk, known as "quishing," is the same trust exploit email phishing has always used, applied to a format where the destination isn't visible until after you've already scanned it. It isn't a flaw in the QR standard itself; scanning a code by itself does nothing more than open a link, the same as tapping any other URL.

What "quishing" actually is

With a normal link — in an email, a text, a webpage — you can often see the destination URL before clicking, or at least hover to preview it. A QR code hides that until the scan happens, which is exactly what makes it useful for its legitimate purposes (a code doesn't need visible text to work) and exactly what a scammer can exploit: a malicious QR code looks identical to a legitimate one, and there's no way to tell where it leads just by looking at the pattern.

The most common real-world version of this attack: a scammer prints a sticker with a fake QR code and places it over a legitimate one — on a parking meter, a restaurant table tent, a poster — so someone scanning what they believe is the real code actually gets sent to a phishing site instead, often one designed to steal payment information or login credentials.

What a malicious QR code can actually do

Scanning a QR code by itself, using your phone's built-in camera, does nothing more than open a link — it doesn't install anything or hand over any data on its own. The risk comes from what happens after you land on the destination: a convincing fake payment page asking for card details, a fake login page harvesting credentials, or a link designed to trick you into downloading something you shouldn't. The QR code is just the delivery mechanism; the actual harm happens on whatever page it opens, the same as it would with a malicious link sent any other way.

Practical ways to protect yourself

Check the URL preview before tapping through. Most phone cameras show the destination URL in a notification banner before opening it — actually read it rather than tapping automatically. A URL that doesn't match the business or context you expect (a misspelled domain, an unusual subdomain, a URL with no relation to where the sticker is posted) is a clear warning sign.

Be suspicious of a QR code that looks stuck-on or replaces something that should be printed directly. A code on a sticker layered over a menu, sign, or parking meter is easier to swap than one printed as part of the original material — this is the single most common tell in real-world quishing reports.

Be extra cautious with codes asking for payment or login information, especially in places where you wouldn't normally expect to enter payment details from a scan — a parking meter or a random flyer asking you to "pay via this QR code" is a common scam pattern, since legitimate parking systems rarely rely solely on a QR code with no other payment option.

Avoid scanning codes from unsolicited mail, email attachments, or unfamiliar senders the same way you'd avoid clicking a suspicious link — the caution that applies to email phishing applies identically here.

Parking payment is the single most commonly reported real-world setting for this scam — see our dedicated guide on QR codes for parking, tolls, and paid meters for how to tell a legitimate parking code apart from a sticker placed over one.

What legitimate QR codes look like from a business's side

For any business generating QR codes for genuine use — menus, event signage, marketing — the same practices that protect against being impersonated matter: use a printed code that's part of the original material rather than a separately affixed sticker where possible, and consider a note near the code confirming what it's for, so customers have a way to sanity-check what they're about to scan.

Quishing red flags at a glance

Warning sign Why it matters
Code is on a sticker, not printed with the original material Stickers are trivially easy to swap over a legitimate code
URL preview doesn't match the expected business/context The single clearest tell before you ever tap through
Code asks for payment or login info in an unusual setting Legitimate parking/payment systems rarely rely on QR-only entry
Code arrived via unsolicited mail, email, or an unfamiliar sender Same caution that applies to email phishing links applies here

The short version

QR codes aren't unsafe by design — the risk is entirely in what a scanned link leads to, exactly like any other link-based phishing attempt. Reading the URL preview before tapping through, treating suspiciously placed stickers with skepticism, and being cautious with any code requesting payment or login details covers the practical risk without needing to avoid QR codes altogether. For the mechanics of what does and doesn't get logged when you scan, see do QR codes track you.

Quick answers

Can a QR code install malware just by being scanned? No — scanning with a phone's built-in camera only decodes and opens a link, the same as tapping a URL. Any harm happens on whatever page the link opens, not from the scan itself.

How can I tell if a QR code has been tampered with? Look for a sticker placed over what should be a printed code — that's the most common real-world quishing method. Also check the URL preview your camera shows before tapping through; a mismatched or unfamiliar domain is a clear warning sign.

Is it safe to scan a QR code from an email or unsolicited mail? Treat it with the same caution as an unfamiliar link in that email — quishing via mail and email attachments is a known pattern, and the same skepticism that applies to phishing links applies here.

Are QR codes at parking meters a common scam target? Yes — parking payment is the single most commonly reported real-world quishing setting, since scammers can place a fake sticker over a legitimate meter code and few people question a QR-only payment flow.

This is general safety information, not a substitute for your bank's or platform's own fraud-prevention guidance — if you believe you've been targeted by a QR code scam involving payment or financial information, contact your bank or card provider directly.

For a related security comparison, see QR code login vs. password: which is more secure?

Ready to create your QR code?

Free, unlimited, no sign-up. Lifetime guarantee.

Open QR Generator