New:Experimental free plan now live for everyonev1.6.0

Ok1Second
Menu
Guide

QR code phishing: how to spot and prevent it

A QR code is a link you cannot read until you open it. That is exactly what makes it useful — and what makes it attractive to people who want you to visit somewhere unexpected.

Updated 2026-10-05 · 1 min read

How the attack works

Stickers are placed over legitimate codes, or a code is emailed and texted as if it came from IT or a delivery company. The code opens a lookalike login page and harvests credentials.

  • Stickers over a real code on a poster or menu
  • Codes in unexpected emails asking you to 'confirm' something
  • A destination that does not match the printed context

How to check before you tap

Most phone cameras show the destination URL before you open it. Read it. If a code on a restaurant table wants a login, or a parking meter wants your bank details, something is wrong.

  • Preview the URL and check the domain
  • Prefer codes you asked for over codes you were sent
  • Never enter credentials on a page reached from an unsolicited code

If you print codes

Use dynamic codes so the destination is visible in the redirect path, keep the printed asset in a place that is hard to sticker over, and check your own signage occasionally for tampering.

Frequently asked questions

What is quishing?
Phishing delivered through a QR code, usually to a lookalike login page.
Can a QR code install malware by itself?
Simply scanning is not enough — the risk is the page you land on and anything you download or enter there.
How can businesses protect their codes?
Use dynamic codes with a visible, controlled short domain, and inspect signage regularly for overlaid stickers.

Keep reading

Ready to create one?

Dynamic codes are editable forever from $4/month.

Create your first dynamic QR code

Free to start. One code, editable forever, with scan tracking from the first scan.

Privacy-first analyticsNo per-scan feesEdit links anytimeNo contract