How QR-Code Phishing Works and How to Avoid It

A QR code can hide a link until you scan it. Check the destination, avoid urgent payment requests and open the organisation's official app or website independently.

Status: Verified Sources: 3 Last reviewed: 17 August 2026 Report a correction
Nigerian cafe customer checking a QR code destination before opening it
Scanning reveals a destination. It does not prove that the destination is safe or authorised.

A QR code can open a website, start a payment, connect to Wi-Fi or share contact information. Because the destination is hidden inside the pattern, a criminal can use a code to disguise a phishing link.

Where the fake code appears

  • A sticker placed over a genuine payment or menu code
  • A delivery or parking notice
  • An email claiming an account needs urgent action
  • A social post promising a prize
  • A message asking you to receive or reverse money

Pause before opening

Use the phone’s preview to inspect the domain. Look for misspellings, unrelated domains and shortened links. If the request concerns a bank, delivery company or government service, open its official app or type the known address yourself.

Check the physical sign

Inspect whether a sticker covers another code or whether the sign looks altered. Ask staff to confirm the payment name or official process before sending money.

Do not install an app from the page

A QR destination that asks you to install an unknown app, enable restricted settings or grant accessibility access creates serious risk. Leave the page and use the official app store or provider website.

If you entered information

Change the affected password from a trusted device, sign out other sessions, contact the bank if money is involved and preserve the link, message and transaction evidence.

The bottom line

Treat a QR code as a link you cannot see until scanning. Check the destination and verify sensitive requests through another official route.

The Tech Embed lens

What this means here

For Nigeria

QR codes used for menus, payments, tickets and promotions can be replaced or covered with malicious stickers, so physical placement does not prove authenticity.

Across Africa

The same checks apply across markets: inspect the destination and verify payment instructions through a separate official channel.

Sources and further reading

  1. www.cisa.gov
  2. www.cisa.gov
  3. www.cisa.gov
Written by

John

Tech Embed’s editorial team verifies important claims, explains technical language and adds Nigerian and African context before publication.

Leave a Reply

Your email address will not be published. Required fields are marked *