Quick answer
A QR code is just a link you can't read with your eyes. Attackers put malicious QR codes in emails, in documents, and on fake stickers placed over real ones (parking meters, posters), to send you to a fake login page or a malware download. Always check the web address after scanning — before you tap, log in or type anything.
WHY QR CODES ARE PERFECT FOR SCAMS
You can't see where they go.
A QR code has one big weakness for you, and one big advantage for a scammer:
- ▸ You can't read the destination with your eyes. Unlike a normal link, there's no web address to check before you scan — the square just hides it.
- ▸ They slip past email link-filters. Because the code is just an image, the security that scans links in your emails often doesn't look inside it.
- ▸ Scanning usually happens on a personal phone. And phones often have fewer protections than a locked-down work computer.
COMMON CONS
Where quishing shows up.
The same trick turns up in a few familiar disguises:
- ▸ "Scan to view" emails. You have a voicemail, a parcel or an invoice waiting — just scan this code to view it. The code leads somewhere you didn't expect.
- ▸ Stickers over the real thing. A scammer sticks their own QR code straight over the legitimate one on a parking meter or a poster, so honest people scan the fake by mistake.
- ▸ Codes inside a PDF or flyer. A document or handout carries a QR code that leads to a fake Microsoft or bank login page.
RED FLAGS
When to be suspicious.
None of these are proof on their own, but any of them is a good reason to slow down:
- ▸ A QR code where you'd normally expect a plain link. If a business could just give you a clickable link, why hide it in a square?
- ▸ An unexpected email asking you to scan something. Especially if it's urgent or about a login, payment or delivery.
- ▸ A code that opens a login page. Real services rarely need you to sign in via a scanned code.
- ▸ A sticker that looks stuck on over another. Peeling edges or a mismatched sticker on a meter or poster are a warning sign.
HOW TO SCAN SAFELY
Look before you leap.
- Preview the web address firstWhen you scan, your phone shows the link before it opens. Read it. If it doesn't match the business you expected, don't open it.
- Never log in via a scanned codeIf a code takes you to a login page, stop. Go to the official app or website directly and sign in there instead.
- Be extra wary in emails and public placesCodes in unexpected emails and codes on posters, meters and flyers are the two spots scammers love most.
- Keep your phone and apps updatedUpdates fix the security holes that malicious pages and downloads try to exploit.
A simple habit. If a QR code leads to a page asking you to log in or pay, stop. Open the real app or type the official website address yourself instead.