QR Code Scams (Quishing): Why You Can’t Verify Them

Published: August 9, 2026
📖 7 min read

A QR code cannot be checked before you scan it, unlike a text link you can hover over to preview where it actually leads. That single fact is why QR-code phishing, often called quishing, works even on people who are otherwise careful about clicking links: the destination stays hidden until your phone has already opened it. The safest response is to treat any QR code you didn't go looking for the same way you'd treat an unsolicited link, and to type the address yourself instead whenever a code is asking you to pay or log in.

We introduced quishing briefly as one of four scam channels in our guide on phishing vs smishing vs vishing; this page goes deeper into the two situations where a QR code specifically asks you to pay or hand over information: parking meters and table stickers, and unsolicited mail.

Why a QR code can't be checked before you scan it

A web link, even a suspicious one, shows you its destination in the address bar or when you hover over it. A QR code is a block of encoded pixels; the only way to know where it leads is to scan it and let your phone's camera or a QR-reader app decode and open it. This is the entire mechanism behind quishing: it removes the one habit (checking a link before clicking) that stops most other phishing attempts. The practical fix follows directly from the mechanism: if you didn't seek out a QR code yourself, don't scan it. If you need to reach a site or make a payment, type the address into your browser instead.

The parking-meter and restaurant-table version: a sticker over a sticker

One of the more common real-world versions of this scam involves a physical, printed QR code sticker placed directly over a legitimate one on a parking meter, a restaurant table tent, or an event poster. Because both stickers look equally official at a glance, there's no visual way to tell a genuine payment code from one an attacker has pasted over it. This pattern is well-documented enough that some cities have responded directly: the Miami Parking Authority removed QR codes as a payment option at its meters after reports that scanning a tampered code redirected users to a fake payment site that signed them up for unauthorized recurring charges instead of a single hour of parking. If you're about to pay for parking or a bill using a QR code, check whether the sticker looks layered, peeling, or slightly misaligned with the surface underneath it, and when in doubt, use the official parking app or pay a human directly instead.

The unsolicited-package version: the FBI's warning on QR codes in the mail

The FBI's Internet Crime Complaint Center (IC3) issued a public service announcement warning that criminals were tampering with QR codes to redirect victims to malicious sites designed to steal login credentials and financial information, a warning first raised in January 2022 and echoed in more recent reporting on unsolicited packages that arrive with a QR code insert, prompting the recipient to "confirm delivery details" or "claim a gift." If a QR code arrives in an unexpected package or letter you didn't order, treat it exactly like an unsolicited link: don't scan it, and if you're concerned about a real delivery, go directly to the shipping carrier's official site or app instead.

What happens after you scan: fake payment pages, not always malware

It's worth being specific about what a quishing scam usually does once scanned, because the answer is often less dramatic than "installs a virus" and more mundane, which makes it easier to underestimate. Most quishing attempts lead to a convincing fake payment or login page designed to capture a card number or a password directly, similar to a standard phishing site, just reached through a QR code instead of a clicked link. Some also attempt to install a malicious app or profile, particularly on less-secured devices. Either outcome depends entirely on what you enter after the page loads, which is why closing the page immediately, without entering any payment or login details, stops most of the damage even after a bad scan.

The one habit that defeats nearly all of it: type the address yourself instead

If a QR code is asking you to pay, log in, or "verify" anything, the single most reliable response is to skip the code entirely and go to the organization's site or app the way you normally would: type the address you already know, or open the app you already have installed. This works regardless of whether the code in front of you happens to be genuine or tampered with, because it sidesteps the unverifiable step altogether.

When a QR code is fine to scan

This isn't a case for avoiding QR codes altogether, since most of the time they're a genuine convenience. A code you scan to open a menu you can see is printed clearly, a code on your own utility bill or boarding pass, or a code displayed on a screen you already trust (like at checkout inside a store you're standing in) carries far less risk than one on an unattended surface asking you to pay or provide credentials. The distinction that matters is whether the code is asking for money, a login, or personal details, versus simply pointing you to a menu or a webpage you can evaluate once it loads.

A note on how to use this

This page describes reported patterns in QR-code scams and does not assign risk to any specific business or QR-code provider named for illustration. Please also read our full Disclaimer. If a QR-code scam led to a financial loss, our guide on what to do if you gave a scammer your bank details covers the immediate steps.

Frequently asked questions

What is quishing?
Quishing is phishing carried out through a QR code instead of a clickable link. Because a QR code hides its destination until after you scan it, it removes the "preview before you click" habit that catches many other phishing attempts.

Is it safe to scan a QR code at a parking meter?
Be cautious. Attackers have placed fake QR-code stickers directly over real ones on parking meters and similar surfaces. Check whether the sticker looks layered or peeling, and consider using the location's official app or paying a person directly if you're unsure.

Why did I get a QR code in the mail I didn't order?
This matches a pattern the FBI's Internet Crime Complaint Center has specifically warned about: unsolicited packages or letters containing a QR code designed to steal your information if scanned. Don't scan it; if you're expecting a real delivery, check directly through the carrier's official site or app.

What actually happens if I scan a malicious QR code?
Most commonly, it opens a fake payment or login page designed to capture your card details or password, similar to a standard phishing site. Some attempt to install a malicious app. Closing the page without entering any information stops most of the risk even after a bad scan.

Are all QR codes risky?
No. A QR code on a menu you can see printed clearly, on your own bill, or on a checkout screen inside a store you're standing in carries much less risk. The concern is specifically codes on unattended surfaces asking for payment, a login, or personal details.

Aron Benjamin

Leave a Comment

Scroll to Top