The square black-and-white codes now appear on restaurant tables, parking meters, and package inserts, offering a fast way to open a menu or a payment page. That same convenience is what makes them useful to criminals, because a scannable code hides its true destination behind a pattern the human eye cannot read.
Consumer protection guidance describes a tactic in which a scammer covers a legitimate QR code with a fraudulent one, or plants a fake code in a place people expect to find a real one. When a person scans it, they can be routed to a look-alike site built to capture logins, card numbers, or a payment meant for a real business.
What a QR code really is
A QR code is simply a machine-readable link. Pointing a phone camera at one usually opens a website, and because the code itself is just a pattern of dots, a person has no way to tell a safe code from a malicious one before scanning it.
That gap between what a person sees and where the code leads is the entire basis of the scam. A fraudulent code can look identical to a legitimate one while sending the scanner somewhere entirely different. The tactic is sometimes called quishing, a blend of QR and phishing, because it applies the logic of a deceptive link to a format that hides the address from view until the moment of the scan.
How the swap works in the real world
The most physical version of the scheme involves a sticker. A scammer prints a QR code that points to their own site and places it directly over a genuine code on a parking meter, a payment terminal, or a posted flyer.
Anyone who scans the tampered code may land on a page that mimics the real one, complete with a form asking for payment details. The victim believes they are paying a legitimate charge, while the information flows to the person who planted the sticker. Parking meters and municipal payment kiosks have been recurring targets, in part because drivers there are often rushed, unfamiliar with the specific vendor, and conditioned to expect a code that opens a payment screen.
Codes that arrive uninvited
QR codes also travel through email, text messages, and printed notes tucked into packages. A message might claim there is a problem with an account or a delivery and urge the recipient to scan a code to resolve it.
These unexpected codes deserve the same suspicion as an unexpected link. The pressure to act quickly, paired with the difficulty of previewing the destination, is exactly what a scammer is counting on. A message warning that a package is stuck, an account is frozen, or a small fee is overdue is engineered to provoke an immediate scan before the recipient stops to weigh whether the sender is genuine.
The signs that a code cannot be trusted
Consumer guidance highlights a few warning signs. A code that appears to be a sticker placed on top of another surface, an unexpected code that demands urgent action, or a scan that leads to a page requesting a login or payment out of context all warrant a pause.
After scanning, the address that loads offers another checkpoint. A misspelled company name, an unfamiliar domain, or a page that asks for more information than the task should require are all reasons to close it without entering anything. A legitimate menu or parking payment rarely needs a login, a Social Security number, or banking credentials, so a request for that level of detail should stop the transaction before any data is typed.
How to scan more safely
The core defense is to verify the destination before acting on it. When a phone previews the link a code contains, that preview is worth reading, and a shortened or unfamiliar address is a reason to stop.
For payments in particular, it is safer to reach a company through a known channel rather than a scanned code, by typing the address directly or using a number printed on an official statement. Inspecting a physical code before scanning is another quick check, since a sticker with a peeling edge, a code layered over another, or one that does not match the surrounding signage is a sign of tampering worth heeding. The full breakdown of the risks and precautions appears in consumer guidance on QR codes.
Why the tactic keeps working
QR codes succeed as an attack because they collapse a decision into a single scan. There is no address bar to inspect first, no obvious cue that a code has been tampered with, and a strong social habit of scanning without a second thought.
Recognizing that a code is just an unverified link, and treating one from an unexpected or physically altered source as untrusted, removes most of the danger. The safest approach is to slow down at the moment of scanning, since that instant is where the entire scheme either works or fails. Businesses can help by printing codes directly on durable surfaces rather than on easily swapped stickers, but the last line of defense remains the individual choosing whether to trust a code before acting on it.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview