QR code phishing: how to spot and prevent it
A QR code is a link you cannot read until you open it. That is exactly what makes it useful — and what makes it attractive to people who want you to visit somewhere unexpected.
Updated 2026-10-05 · 1 min read
How the attack works
Stickers are placed over legitimate codes, or a code is emailed and texted as if it came from IT or a delivery company. The code opens a lookalike login page and harvests credentials.
- Stickers over a real code on a poster or menu
- Codes in unexpected emails asking you to 'confirm' something
- A destination that does not match the printed context
How to check before you tap
Most phone cameras show the destination URL before you open it. Read it. If a code on a restaurant table wants a login, or a parking meter wants your bank details, something is wrong.
- Preview the URL and check the domain
- Prefer codes you asked for over codes you were sent
- Never enter credentials on a page reached from an unsolicited code
If you print codes
Use dynamic codes so the destination is visible in the redirect path, keep the printed asset in a place that is hard to sticker over, and check your own signage occasionally for tampering.
Frequently asked questions
What is quishing?
Can a QR code install malware by itself?
How can businesses protect their codes?
Keep reading
Ready to create one?
Dynamic codes are editable forever from $4/month.
Create your first dynamic QR code
Free to start. One code, editable forever, with scan tracking from the first scan.