A QR code is just a link
A QR code can't infect your phone by itself. It is only a way of storing text, usually a web address. The risk is where it sends you. A malicious code can lead to a fake login page, a phishing form, a payment request or a page that tries to trick you into installing something. Scams that use QR codes are often called “quishing”.
Common QR code scams
- Sticker overlays. A fake code is stuck over a genuine one on a parking meter, restaurant table or shop counter.
- Fake payment codes. A scammer swaps a shop's payment code for their own.
- Phishing emails and letters. A message says your account is locked or a parcel is held, and gives a code instead of a link so email filters can't inspect it.
- “Scan to receive money”. Receiving a payment never requires you to scan a code and enter a PIN.
How to check a code before opening it
- Read the address your phone shows before you tap it. Look for misspellings or unfamiliar domains, such as an extra word or a swapped letter.
- Be suspicious of shortened links when you don't know who made the code.
- Check the physical code: is it a sticker placed over another one, or does it look scuffed or misaligned?
- Never enter a password, card number or one-time code on a page you reached from an unexpected code. Open the official site or app yourself instead.
- Don't install an app just because a code told you to. Use your phone's official app store.
Keep your own codes trustworthy
- Use a link on a domain you control and that people recognise.
- Add a short line of text near the code, such as the website name, so people can see where it leads.
- Check public codes regularly to make sure no one has covered or replaced them.
- Use a protected surface for codes that handle payments.
- If you use a dynamic code, only point it at destinations you trust and re-check them periodically.
Test every code with our QR checker before printing, and see static vs dynamic QR codes for how each type behaves.
What to do if you scanned something suspicious
Close the page without entering anything. If you did enter a password, change it on the genuine site straight away and enable two-step verification. If you paid money, contact your bank or payment provider immediately and report the code to the business or authority that owns the location. To report a QRinst code that points somewhere harmful, see our contact page.
More guides
- What size should a printed QR code be?
- How to make a Wi-Fi QR code guests can scan to connect
- QR code not scanning? 9 common causes and fixes
- How to make a QR code menu for your restaurant
- How to put a vCard QR code on your business card
- Static vs dynamic QR codes: which one should you use?
- How to make a WhatsApp QR code that opens a chat