blog

How to Spot a Dangerous QR Code and Avoid Quishing Scams

QR codes are everywhere now — payments, restaurant menus, posters, flyers. Handy as they are, scams that target the “just scan it” habit are on the rise. Phishing that uses QR codes has a name: quishing (QR + phishing).

The tricky part is that a QR code hides its contents from your eyes. With a written URL you might think “that address looks off,” but a QR code is just a pattern of squares — you can’t tell where it leads until you scan it. That invisibility is exactly what makes it convenient for scammers.

Common tactics

1. Swapped payment QR codes A scammer sticks a fake QR sticker over the legitimate payment code at a counter or register. Money the customer thinks they’ve paid flows to the scammer’s account instead.

2. Fake campaigns and “you’ve won” notices Posters or messages saying “scan for a limited coupon” or “you’re a winner” send you to a fake site that harvests your personal or card details.

3. Fake parking or invoice codes Codes disguised as “parking payment” or “unpaid bill” notices have been slipped into public places and mailed documents.

Six checks to protect yourself

1. Be suspicious of stickers

A QR printed directly onto legitimate material is safer than a sticker-style QR stuck on afterward. Especially where money is involved — next to a register or a ticket machine — check whether a sticker has been layered over another or looks oddly raised.

2. Read the URL (the domain) first

Most phones show the destination URL once when you scan a code. Make it a habit to not open it immediately, but check the domain name.

If the real site is example.com, then look-alikes such as example-pay.net or example.com.xxx.ru are red flags. Be wary of unfamiliar country domains and absurdly long addresses too.

3. Treat shortened URLs with extra caution

Shorteners like bit.ly can hide the true destination. Not all of them are dangerous, but a shortened-URL QR stuck up in a public place carries more risk precisely because you can’t see where it goes.

4. Stop if you’re asked for personal or payment details

If the page a QR sends you to asks you to enter login credentials, a card number, or personal information, pause. A legitimate service generally won’t have you type sensitive details straight from a QR scan.

5. Log in from the official app or site, not a QR

When logging into a bank or service, it’s safer to enter through a site you bookmarked yourself or an official app you installed from the store — not via a QR code. QR codes are an easy way to disguise a fake entrance.

6. When unsure, check before you open

If any part of you thinks “is this QR okay?”, you can verify it before opening. An app like QR/URL AI Scanner, which uses AI to judge the safety of a scanned QR or URL, can warn you before you open a dangerous link.

That said, such a check is only a guide. In the end, combining it with the checks above and your own judgment is what keeps you safe.

Wrapping up

The core of quishing defense is a single beat: don’t open it the instant you scan. Read the URL, doubt stickered codes, and stop when you’re asked for sensitive details. Making those three a habit prevents most of the harm.

QR codes are a useful tool. That’s exactly why it’s worth understanding their “you can’t see the contents” nature and treating them with a little care.

← Back to all posts