Quick answer
A QR code is just data — usually a link — printed as a pattern. The code itself can't infect your device. The risk is what happens after you scan: a malicious code can send you to a phishing site, trigger an unwanted download, or connect you to a rogue WiFi network. The defense is simple: always see the decoded content before you act on it.
Why QR codes became a scam vector
A QR code is unreadable to humans. When you see a printed link like example.com, you can judge it at a glance — but a QR code hides its destination completely until it's decoded. Scammers exploit exactly that gap.
Security researchers call this quishing (QR phishing). It grew fast for a simple reason: people scan codes in trusting contexts — a restaurant table, a parking meter, a poster, a delivery slip — and most phone cameras open the link immediately, before anyone reads the URL.
Common QR code scams to know
- Sticker overlays: scammers print their own QR sticker and paste it over a legitimate one on parking meters, menus, or posters. The setting looks trustworthy, so people scan without thinking.
- Fake payment requests: a code that opens a convincing clone of a payment or banking page and asks you to log in.
- Phishing emails with QR codes: emails increasingly carry QR codes instead of links, precisely because email security filters scan links but often ignore images.
- Rogue WiFi codes: a WiFi QR code that connects you to an attacker-controlled network where your traffic can be monitored.
- Malicious downloads: codes that push an APK or app installer instead of opening a web page — a serious red flag on Android.
Red flags after you decode a QR code
Decode first, then check the result against this list before opening anything:
- Shortened or redirecting links (bit.ly, tinyurl, and similar) — the true destination is hidden behind another layer.
- Lookalike domains: paypa1.com, amaz0n-support.net, your-bank.secure-login.xyz. Read the domain right to left — the real domain is the part just before the last dot.
- Urgency in the surrounding context: "pay this fine within 24 hours," "your parcel will be returned."
- A login page you didn't expect: if a printed poster leads straight to a password prompt, stop.
- File downloads: a QR code should almost never install anything.
- HTTP instead of HTTPS: legitimate services use encrypted connections.
The safe scanning habit
The single most effective protection is choosing a scanner that shows you the decoded content instead of opening it automatically.
- Scan the code with a tool that previews the result: /image-qr-scanner
- Read the full URL. Check the domain carefully, character by character if it claims to be a bank or payment service.
- If it's shortened, don't follow it blindly — or skip it entirely if the context is sensitive.
- Only then decide to open, copy, or ignore.
ScanQR is built around this decode-first workflow: every scan runs locally in your browser (nothing is uploaded), and you always see the raw content — link, text, or WiFi credentials — before anything happens. For a deeper walkthrough, see the safety guide: /secure-qr-scanner
Physical checks before you even scan
- Look for a sticker pasted over another code — edges, bubbles, or misalignment with the printed design.
- Be extra careful with codes in public, unattended places: parking meters, lamp posts, ATM surrounds.
- Codes inside sealed official mail are safer than codes on loose flyers — but the decode-first rule still applies.
What to do if you already opened a bad link
- Close the page. Don't enter anything.
- If you entered a password, change it immediately on the real site and enable two-factor authentication.
- If you entered card details, contact your bank and watch for unauthorized charges.
- If you installed an app, uninstall it and run a reputable mobile security scan.
- If you joined a rogue WiFi network, forget the network and avoid logging into sensitive accounts until you're back on a trusted connection.
FAQ
Can a QR code hack my phone just by scanning it?
Practically, no. Modern scanning happens in a sandboxed camera or browser context; the code delivers data, not executable code. Real-world attacks rely on what you do after — visiting a phishing site, entering credentials, or approving a download.
Are QR codes on restaurant menus safe?
Usually yes, but sticker overlays have been found on menus too. A quick glance at the decoded domain (does it match the restaurant or a known menu service?) takes two seconds.
Is it safer to scan with an app or a website?
What matters is the decode-first behavior and privacy. A browser-based scanner that decodes locally, like ScanQR, never uploads your image and always shows the content before opening — with nothing to install and no app permissions to grant.
Check before you tap
Scan any QR code from an image, screenshot, or camera and preview exactly what's inside — decoded locally, nothing uploaded: /image-qr-scanner