Is this QR code safe to scan?
QR codes can hide a scam link as easily as a real one. Here is how QR phishing works, the warning signs and how to see where a code goes before you open it.
A QR code is just a link you can’t read. That is what makes it convenient and it is exactly what makes it useful to scammers. You would think twice about typing in parkmeter-pay.xyz, but a square of dots on a parking meter gives you no chance to.
How QR scams work
Stickers on top of real codes. The most common version. A scammer prints codes that lead to a convincing copy of a parking or charging payment page and sticks them over the real ones. You scan, pay and your card details go to someone else.
Codes in emails and letters. A message says your account needs verifying or a parcel is waiting, with a code to scan. Putting the link in a picture gets it past email filters that check links and moves you from a computer to a phone, where the address bar is small and easy to ignore.
Codes that do more than open a page. A code can also join a WiFi network, start a text message to a premium number or offer an app to download. Each needs your confirmation on a modern phone, but a hurried tap is exactly what scammers count on.
Consumer protection agencies, including the US Federal Trade Commission, now warn about these scams specifically.
What to look at before you open anything
The website name is what matters, not the look of the page. Read the part of the address just before the first single slash. For https://pay.citypark.example.com/meter, the site is citypark.example.com. Watch for:
- Text before an @ sign. In http://paypal.com@203.0.113.9/login, everything before the @ is ignored by the browser. The real destination is the number after it.
- A bare number instead of a name. Legitimate businesses almost never send customers to an IP address.
- Lookalike letters. Addresses can use characters from other alphabets that look identical to Latin ones.
- Link shorteners. bit.ly and similar services hide the real destination completely.
- http instead of https. Never enter a password or card number on an unencrypted page.
The QR code scanner shows the full address, names the site it leads to and flags each of these automatically. It works on a screenshot or photo as well as with the camera, so you can check a code from an email without opening anything.
Habits that help
Pay through the operator’s own app or website rather than a code on a sign. Feel the code on a meter or poster: a sticker on top of the printed one is a warning sign. Never scan a code in a message you weren’t expecting. And when a page asks for a password, type the site’s address yourself instead.
For codes you make yourself, a static code with your own address in it, as explained in do QR codes expire, is easier for people to trust because the destination is visible when they check it.
For a related next step see Why is my QR code blurry or not scanning?.
Common questions
Can scanning a QR code hack my phone?
Scanning alone doesn’t install anything. The danger is what the code leads you to do next: open a fake website and type in a password or card number, download an app from outside the app store or join a network run by someone else. A scanner that shows the destination first lets you stop before any of that.
What is quishing?
QR code phishing. It is ordinary phishing with the link hidden in a QR code, which gets past email filters that check links and hides the address from someone who would otherwise notice it looks wrong.
Are QR codes in restaurants safe?
A menu code printed on the table by the restaurant is usually fine. Be more careful with codes that ask for payment or login details, codes that are stickers placed on top of something and codes in messages you weren’t expecting.
What should I do if I entered details on a fake page?
Change the password straight away, starting with any account that uses the same one and contact your bank if you entered card details. Report the code to whoever owns the place it was stuck, such as the car park operator.