How to Spot and Avoid QR Code Scams
QR code scams are simple in concept and ugly in practice. A code that looks harmless can send you to a fake site, a payment request or malware. That is why criminals use “quishing”: they rely on the fact that many people scan first and inspect later.
Key takeaways
- QR scams hide phishing pages, fake payments and malware behind a normal-looking code.
- Check the destination link and the context before you scan, especially on signs, emails and parcels.
- If you opened a suspicious code, close it, change passwords and review account activity fast.
- Use trusted apps and official websites for payments and logins instead of scanning blindly.
What QR code scams are, and why they work
A QR code scam is a fraud that hides a risky destination until you scan it. That destination might be a phishing page, a fake delivery notice, a bogus login screen or a request for card payment details. The FTC has warned that scammers hide harmful links in QR codes to steal information, and the risk comes from what the code opens, not from the square itself. FTC
These scams work because QR codes are now part of ordinary life: restaurant menus, parking signs, parcel slips, posters and charity notices. People have been trained to trust the shortcut, so they often skip the checks they would normally make on a web address. Both Apple iPhone and Android devices can be targeted, so this is not limited to one brand or one operating system.
The term quishing comes from QR code phishing. In practice, it means the code is being used to imitate a trusted service and push you into handing over login credentials, card details or other personal information. The University of Illinois Chicago notes that malicious QR codes can also trigger malware downloads, which means the scam can move beyond a fake login page. UIC
Common QR code scam setups to look out for

- Unsolicited QR codes sent by email or text message, especially when the message creates urgency about a missed payment, delivery or account problem.
- Fake stickers placed over real codes on posters, menus, parking signs, transport notices or package labels.
- Offers built around a ‘free’ gift, prize, parking fine, charity appeal or refund request that push you to scan immediately.
- Codes that route you to a page asking for login details, card payment information or a file download instead of a normal service page.
The United States Postal Inspection Service has warned about QR codes sent from unfamiliar email addresses or text messages that tell you to scan them immediately. It has also flagged package-based scams, where a small gift arrives with a card and the recipient is told to scan the code to register the present or find out more about the sender. That combination of curiosity and urgency is exactly what scammers count on. USPIS
How to check a QR code before you open it
- Preview the destination link before opening it, if your phone allows that, and look closely at the web address. A genuine address should match the brand or service you expect.
- Ask whether the QR code makes sense in context. A code on a café table, a courier label or a parking notice should connect to the venue or service you are already dealing with.
- Watch for spelling errors, odd domain names, login prompts, payment requests and any message that tries to rush you into action.
- If the code feels doubtful, go to the official website or app yourself instead of scanning it. That simple detour removes most of the risk.
A useful check is to compare where the code sends you with the official site or app you would normally use. A page with a convincing logo is not enough if the address is wrong, the wording is clumsy or the site asks for details the real service would never need. If the page uses HTTPS, that only means the connection is encrypted. It does not tell you whether the site is genuine, because scammers can also use encrypted connections on fake pages.
What to do if you scanned a suspicious QR code
- Close the page straight away and do not type anything else into it.
- If you entered passwords or other credentials, change them quickly and switch on extra account protection where it is available.
- Check your bank and card activity for unfamiliar transactions, then contact your bank if payment details may have been exposed.
- Run a security check on the device, remove any app or file you did not mean to install, and review recent downloads.
If you have shared credit card details or login credentials, act as though the information may already be in the wrong hands. Change the password on the affected account straight away, and then review any other accounts that reuse the same password. The faster you reduce the number of places that password works, the less useful it is to a scammer.
Some malicious QR codes are built to do more than steal a password. UIC says they can lead to malware downloads that may monitor activity, extract messages or open the door to device compromise. If your phone starts behaving oddly after a scan, treat that as a warning sign rather than a coincidence. UIC
How to reduce your risk day to day
- Use official apps and bookmarked websites for payments, logins and support instead of scanning a code under pressure.
- Keep iOS and Android software updated so your phone has the latest mobile security fixes.
- Be cautious with codes on unsolicited parcels, car parks, adverts, takeaway menus and charity appeals.
- Treat urgent wording as a warning sign, not a reason to move faster, and pause before you tap or scan.
For South Africans who use QR payments regularly, the safest habit is to slow the process down by a few seconds. Check who put the code there, decide whether the request fits the moment, and use the official app if you need to pay, sign in or get support.
If you are in a café, a taxi rank, a market stall or a parking area, be especially careful with stickers placed over existing codes, because that is a common way to swap in a fake one.
The pattern is familiar across the most common scams. A code is used to borrow trust, urgency is used to override judgement, and the end goal is usually access to money, accounts or personal data. A QR code that arrives by text out of the blue, or a code on a pasted-on sticker, deserves more suspicion than one in a place you already recognise.
Frequently asked questions
What is a QR Code Scam?
It is a scam that uses a QR code to hide a risky destination until you scan it, such as a fake login page, a payment request or a malware download. The goal is usually to steal passwords, card details or other personal information, and the danger lies in what the code opens.
Can QR code scams affect iPhone and Android users?
Yes. Both iPhone and Android users can be targeted, so neither platform is immune. The useful checks are the same on both: look at where the code leads, whether the context makes sense, and whether the web address matches the service you expect.
How can I tell if a QR code is safe?
Only scan it if you trust the source and the situation makes sense, such as a code on a service you are already using. If your phone shows the destination first, inspect the web address for odd spellings, unfamiliar domains or login and payment prompts. If anything looks off, stop and open the official website or app yourself.
What should I do if I entered my details after scanning a QR code?
If you entered card or bank details, contact your bank and check for unusual transactions. If you entered a password, change it and turn on extra account protection where it is available. It also makes sense to review the device for anything you did not mean to download, because some malicious QR codes can lead to malware.
Are QR codes on posters and menus always safe?
No. Posters, menus, parking signs and package labels are common places for fake stickers or replaced codes, so you should not assume they are genuine. Scan only when the location and source are clearly trustworthy, and if in doubt, use the venue’s official website or app instead.
