QR Code NW

QR Code scams: how they work and how to protect yourself

Date Published

QR Codes have one characteristic that fraudsters love: you cannot see where they lead before scanning. A link in text can be inspected; a square of pixels cannot. That opacity is the basis of practically every scam involving the technology.

The good news is that the scams are few, repetitive and carry clear signals. Knowing the patterns cuts the risk considerably.

The sticker-over-the-code scam

The most common and the simplest to execute. The fraudster prints a payment QR Code with their own account details and sticks it over the legitimate code displayed on a shop counter, a parking meter, a donation poster or a car park sign.

The customer scans believing they are paying the business, and the money goes to the fraudster. The merchant only finds out when the customer shows a receipt for money that never arrived.

How to protect yourself when paying

  • Check the recipient name on the app screen before confirming. This is the single most effective protection. The name is displayed for exactly this reason. If it does not match the business, do not confirm and tell someone there.
  • Be suspicious of a sticker that looks applied on top, with bubbles, a misaligned edge or paper different from the rest of the material.
  • Check the amount before confirming. A charge differing from what was agreed is a warning sign.

How to protect yourself when receiving

  • Scan your own code periodically and confirm it still leads to you.
  • Run a hand over the code to feel for a layer stuck on top.
  • Use a laminated, framed or directly printed sign, far harder to cover discreetly than a loose sheet.
  • Put your logo in the code. Besides identifying it, this makes substitution with a generic code harder. See how to do it without breaking scanning.

Quishing: phishing by QR Code

The word combines QR with phishing. The code leads to a fake page imitating a bank, a delivery service, a tax authority or a fines payment system, asking for a login, password or card details.

The QR Code is used instead of a link because it bypasses security filters: email anti-fraud systems read links but do not decode images as easily. That is why quishing has grown in corporate email.

Typical channels:

  • An email saying your account will be blocked, with a code to "reactivate" it.
  • A physical letter with an official appearance, demanding a fee or fine.
  • A poster on a lamp post or parking meter offering quick payment.
  • A message about a parcel held at customs asking for a fee.
  • A fake job vacancy or a promotion from a well-known retailer.

The warning signs

  • Urgency. "Your account will be blocked within 24 hours." Haste is a fraudster’s main tool.
  • A strange address. After scanning, read the address before opening. Misspelled domains, lots of hyphens or unusual endings are red flags.
  • A request for a password or card details. No bank asks for that through a link you received.
  • A code received from a stranger, by unsolicited message or email.
  • An offer too good to be true. A prize, an unexpected refund, an absurd discount.
  • A loose QR Code in a public space, stuck on a post, bus stop or toilet door, with no indication of who put it there.

Habits that remove almost all the risk

  1. Always read the address before opening. iPhone and Android show the destination in a notification; read it before tapping.
  2. Never type a password into a page opened by QR Code. If you need to sign in, close it and open the official app or type the address by hand.
  3. Check the recipient name on any payment.
  4. Do not scan codes received from strangers.
  5. Keep your phone operating system updated.
  6. Enable two-factor authentication on important accounts. Even if a password leaks, access does not complete.

What a QR Code cannot do

It is worth dispelling some exaggerated fears in circulation. Scanning a QR Code, on its own, does not install a virus, does not hack your phone and does not transfer money.

It is text. The most it does is open an address, propose a network connection or fill in a field. All damage depends on an action you take afterwards: typing a password, confirming a payment, installing a file. The defence always lives in that second step — which is why it deserves two seconds of attention.

If you have been a victim, report it to the police, tell your bank immediately, and if the scam used a company brand, notify that company too.