QR code scams: what to check before you scan
Published on
A QR code is nothing more than text encoded into a picture. That simplicity is its virtue and also the reason it became a convenient tool for fraud: nobody can see where a code leads until they've already scanned it.
The technical name for this is quishing, a blend of QR and phishing. The mechanics are the same as ever, luring a victim to a fake site to hand over data or money, except the link travels hidden inside a square.
The three most common formats
The first and most widespread is the sticker on top. Someone sticks their own code over the legitimate one on a parking meter, a car park, an electric vehicle charger, or a shop's payment sign. The victim pays believing they're paying the business, and the money goes to another account. It's cheap to pull off, requires no technical skill, and has happened in dozens of cities.
The second is paper deliberately left in the wrong place: a supposed parking ticket on a windscreen, an undelivered parcel notice at the door, a prize survey on a bar table. The code leads to a page imitating the real institution and asks for card details.
The third is email with a QR code instead of a link. This variant grew because it solves a problem for the attacker: corporate security filters analyse the links in an email, but a QR code is an image and many filters don't look at it. It also forces the victim off the company computer and onto their personal phone, which almost never has the same protections.
Why it works better than a fake link
With a text link, anyone can hover over it and see where it goes before clicking. With a QR code that's impossible: the destination is only known after scanning.
Add to that the physical context. A code stuck on a parking meter looks like part of the parking meter. A sticker on an official sign inherits the sign's credibility. The victim isn't evaluating a suspicious link in their inbox, they're out on the street sorting something out in a hurry.
And there's a screen factor: on a phone the address bar is short and shows only part of the domain. A long, well-crafted address can look legitimate on mobile even when the deception would be obvious on a large screen.
What to check, in order
Before scanning, look at the code physically. If it's a sticker on top of something else, if the edges are lifting, if the paper doesn't match the rest of the sign, or if it partly covers printed text, don't scan it. Legitimate codes are usually printed with the design, not stuck over it.
After scanning and before opening, read the full address the phone shows. The part that matters is the one right before the first slash: that's the real domain. A domain similar but not identical to the brand's, with extra hyphens, a swapped letter, or the brand appearing as a subdomain of another site, is the clearest sign of fraud.
Be wary of shorteners. A code leading to a short address from a link-shortening service hides the final destination, and while there are legitimate uses, on a payment sign there's no reason for one.
And the rule that covers nearly everything: never enter card details, passwords or verification codes on a page you reached by scanning a code you weren't expecting. If the notice looks real, go to that company's site by typing the address yourself, or call the number on your account statement.
The other side: protecting your own codes
If you run a business with QR codes on display, you're a target. The most effective defence is the most boring one: physically checking the codes often to make sure nothing has been stuck over them, especially the ones left unattended.
Then, make sticking harder. A laminated code, one behind acrylic, or one printed directly onto an uneven surface is far less convenient to cover than a sheet taped up.
And one measure that helps with everything: put the business name clearly beside the code. If the customer scans and the screen shows a different name, they'll stop. Without that reference, they have nothing to compare against.