A QR code can open a website, start a payment, connect to Wi-Fi or share contact information. Because the destination is hidden inside the pattern, a criminal can use a code to disguise a phishing link.
Where the fake code appears
- A sticker placed over a genuine payment or menu code
- A delivery or parking notice
- An email claiming an account needs urgent action
- A social post promising a prize
- A message asking you to receive or reverse money
Pause before opening
Use the phone’s preview to inspect the domain. Look for misspellings, unrelated domains and shortened links. If the request concerns a bank, delivery company or government service, open its official app or type the known address yourself.
Check the physical sign
Inspect whether a sticker covers another code or whether the sign looks altered. Ask staff to confirm the payment name or official process before sending money.
Do not install an app from the page
A QR destination that asks you to install an unknown app, enable restricted settings or grant accessibility access creates serious risk. Leave the page and use the official app store or provider website.
If you entered information
Change the affected password from a trusted device, sign out other sessions, contact the bank if money is involved and preserve the link, message and transaction evidence.
The bottom line
Treat a QR code as a link you cannot see until scanning. Check the destination and verify sensitive requests through another official route.