The square black-and-white codes now stuck to parking meters, restaurant tables, and flyers have become an everyday shortcut, and scammers have noticed. In a tactic sometimes called quishing, criminals plant or replace QR codes so that scanning them sends a person to a fraudulent website built to steal logins, payment details, or other sensitive information. Because a QR code is unreadable to the human eye, a malicious one looks identical to a legitimate one until it is too late.
How a poisoned QR code works
A QR code is simply a machine-readable link. When a phone camera scans it, the device decodes the embedded web address and offers to open it, often in a single tap. That convenience is the vulnerability. A person cannot tell by looking whether a code points to a real payment page or to a counterfeit site designed to harvest whatever is entered.
Scammers exploit that blindness in two main ways. They print their own codes on stickers and place them over genuine ones, or they distribute fake codes on notices and mailers that appear official. In each case the victim believes they are scanning a trusted code when they are actually being routed to an attacker’s page, and the switch happens entirely out of sight because nothing about the code’s appearance changes. A forged sticker can be produced with ordinary printing equipment and applied in the time it takes to walk past a meter, which keeps the effort low and the potential payoff large.
Why public codes are easy to hijack
Consumer-protection authorities have flagged the rise of malicious QR codes as a growing scam, and the settings where they thrive share a common weakness. A parking meter, a restaurant table, or a public poster is accessible to anyone, so covering a real code with a fraudulent sticker takes only a moment and no special access. The FTC’s consumer alerts describe how criminals use QR codes to steer people to sites that capture personal and financial data.
The everyday contexts make the ruse more believable. Paying for parking, viewing a menu, or settling a bill by scanning a code has become normal, so a prompt to enter card details or log in after scanning does not immediately raise suspicion the way an unsolicited email link might. Familiarity is doing the work that would otherwise trigger caution. A person who scans a code at a familiar business rarely pauses to ask who printed it.
What the fake destination is after
Once a victim lands on a fraudulent page, the goal is to collect something valuable. A fake payment screen can capture card numbers, while a counterfeit login page mimics a familiar service to steal a username and password. Some malicious codes attempt to prompt a download that installs harmful software on the phone.
Stolen credentials are especially damaging because people reuse them across accounts, so a single captured login can open doors well beyond the site that was imitated. That leverage is what makes login theft an appealing prize for the people behind these schemes, and it is why a counterfeit sign-in page is a common payload. Reused passwords compound the harm, because one stolen combination can be tried automatically against dozens of other services until it opens something.
Why a QR code invites less scrutiny than a link
Part of what makes quishing effective is that a QR code hides its destination in a way a written link does not. A suspicious web address in an email can be read and second-guessed before anyone clicks; a QR code presents nothing to read, only a pattern to scan. That opacity moves the moment of decision to after the scan, when a page is already loading.
The physical setting adds to the effect. A code printed on official-looking signage or affixed to a public fixture carries an air of legitimacy that an unsolicited message lacks, and people tend to extend the trust they place in the location to the code stuck on it. Stripping away both the readable link and the sender’s identity leaves fewer of the usual cues that something is wrong. The result is a scam that borrows both the authority of a location and the opacity of a machine-readable link, a combination that leaves a target with little to go on.
The checks that catch a fake
The strongest habit is to preview the web address before acting on it. Most phones display the decoded link after a scan, and pausing to read it can reveal a misspelled brand name, an odd domain, or an address that has nothing to do with the business the code claims to represent. Treating that preview as a checkpoint rather than a formality defeats many of these scams.
Physical inspection helps too. A sticker placed over an existing code, a QR code that looks added on as an afterthought, or one peeling at the edges can indicate tampering. When in doubt, typing a known web address directly or using a business’s official app avoids the code entirely.
Habits that limit the damage
Guidance from consumer authorities emphasizes skepticism toward any code that leads to a request for login credentials or payment, particularly one encountered in an unexpected place or received unsolicited. Entering sensitive information should follow verifying that the destination is genuine, not the other way around.
The broader shift the warnings describe is that a QR code deserves the same caution as a link in a message from an unknown sender. The format feels frictionless by design, and that frictionlessness is precisely what makes a fake one dangerous. Slowing down for even a moment before entering credentials restores the scrutiny the format is built to skip, and that pause is often all it takes to notice a destination that does not belong.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview