FAKE QR CODES MAKE FOR EASY SCAMS – BE CAREFUL WHAT YOU SCAN OUT THERE

In case you missed it Most Read Tech

Mon 13 April 2026:  

It’s a simple thing we encounter many times every single week – often while in a hurry. You pull up at a parking spot, scan a QR code and pay within seconds. Or you sit down at a cafe, scan a code to view the menu and order your meal.

At the train station, you scan the code on the poster for timetable updates. QR codes are increasingly used in public transport systems worldwide for ticketing, payments and accessing real-time information.

Because QR codes are so widespread, scammers naturally find them appealing too. Here’s what you need to know to stay safe.

What are QR codes?

A QR (quick response) code is a type of barcode that stores information and encoded data in a square pattern of black and white pixels. They were first developed in 1994 by Japanese company Denso Wave for labelling automotive parts.

Today QR codes are widely used because they’re quick to create and easy to scan without needing a specialised scanner – a smartphone camera will do. They’re designed to remove friction: you scan, and something happens instantly.

However, a QR code doesn’t show you where it leads until after it’s scanned. Your device can perform a range of functions after scanning a QR code: open up a web page, check you in to a location, or even connect your device to a wireless network without needing to type anything.

That’s what makes it so useful, but also potentially risky. Malicious QR codes can redirect users to fake websites or prompt them to download harmful content. QR codes are so familiar and widespread, we tend to trust them without question. That’s exactly what scammers rely on.

What to look out for

Phishing – where cyber criminals “fish” for sensitive information – is the most common type of cyber crime, typically sent by email or text. When a QR code is involved, that becomes “quishing” – short for QR phishing.

Scammers now include QR codes in emails or text messages instead of clickable links. When scanned, the code directs users to fake login pages or payment sites. Because there’s no visible link, these messages can seem more trustworthy and can even bypass some email security filters.

Malicious downloads

Some QR codes don’t just take you to a website – they trigger an app or file download, which could contain malware. This can give attackers access to your device, data or accounts. Because the action happens quickly, you may not have time to question whether the download is legitimate.

Fake QR codes in public places

One of the simplest methods to trick people involves placing a sticker with a fake QR code over a legitimate one. For example, scammers have been caught sticking fraudulent QR codes on parking meters. When drivers scan the code, they are taken to a fake payment page and asked to enter their card details. Posters, flyers and other signs in public places may also contain malicious QR codes.

Redirect scams

Even when a QR code looks legitimate, it may redirect you through multiple websites before landing on a fake page. This makes it harder to detect suspicious activity. By the time you see the final page, it may look convincing enough to trust.

@whichuk There’s been a huge spike in the number of people falling victim to nasty QR code scams—also known as quishing. This scam involves fraudsters tampering with QR codes in public places—such as restaurants, pubs, shops, bus stops, stations, and car parks—to redirect people to scam websites or malicious apps. Here 5 ways to use QR codes safely 1. Check for evidence of tampering when you scan QR codes in public spaces, as someone may have placed a sticker over the real one, or it may look out of place. If in any doubt, type in the web address manually to visit the correct website. 2. Don’t use an app to scan QR codes as it increases the risk of downloading malware or being redirected to a misleading advert. Most phones have a scanner built into the camera, so use this instead. 3. Preview the web address as you start to scan it – you should be able to inspect the link by clicking on additional settings within the scanner, or you could turn off internet access for your device (put it on airplane mode) and open the link to view the address details first. If it doesn’t begin with ‘https’ or the website’s address is different to what you were expecting, then don’t visit it. 4. Don’t use QR codes to download apps as this increases the risks of installing something malicious. Use a verified app store instead (Play Store at play.google.com or App Store at apps.apple.com). 5. Avoid QR codes in emails as scammers are increasingly using QR codes to disguise malicious links, as email security tools don’t always scan images. #scam #scamalert #scamawareness #qrcode #qrcodes #quishing #fraud #learn #learnontiktok #scammers #fraudawareness #staysafe #staysafeeveryone ♬ original sound – Which?

How to stay safe

The good news is you don’t need to stop using QR codes. You just need to use them more carefully.

Treat QR codes like unknown links. If you wouldn’t click a random link, don’t scan a random QR code.

Check for signs of tampering. In public places, look closely at the code. Is it a sticker placed over another one? Does anything look out of place?

Look at the web address before proceeding. Many phones now show a preview of the hyperlink retrieved via the QR code before opening it. Don’t just hit “go”, take a moment to check it looks legitimate.

Avoid scanning codes from unsolicited messages. If you receive a QR code via email or text asking you to log in or make a payment, don’t use it. Go directly to the official website instead.

__________________________________________________________________________

https://whatsapp.com/channel/0029VaAtNxX8fewmiFmN7N22

__________________________________________________________________________

Don’t rush to enter personal details. If a site asks for sensitive information, pause. Double-check you’re on the correct website.

Keep your phone updated. Security updates may sometimes feel like a nuisance, but they do help protect your device against malicious sites and downloads.

QR codes are not dangerous by themselves. They are useful tools that make everyday tasks easier. But they remove a key safety step: the ability to see where you’re going before you get there.

The next time you scan a QR code, take a second to think. In a world where scams are getting smarter, the safest habit is simple – don’t trust the code and verify where it leads.

Author:

Meena Jha

This article is republished from The Conversation under a Creative Commons license. Read the original article.

The Conversation

__________________________________________________________________________

FOLLOW INDEPENDENT PRESS:

WhatsApp CHANNEL 
https://whatsapp.com/channel/0029VaAtNxX8fewmiFmN7N22

TWITTER (CLICK HERE) 
https://twitter.com/IpIndependent 

FACEBOOK (CLICK HERE)
https://web.facebook.com/ipindependent

YOUTUBE (CLICK HERE)

https://www.youtube.com/@ipindependent

Think your friends would be interested? Share this story! 

Leave a Reply

Your email address will not be published. Required fields are marked *