QR Code Scams: How Criminals Use Fake QR Codes to Steal Your Data

Published: 09 March 2026 Updated: 4 May 2026 8 min read By Kumari Rajapaksha, Founder

I was paying for parking in Melbourne's CBD last year when I noticed something odd. The QR code on the meter had a slightly raised edge, it was a sticker placed on top of the original. I peeled it off and sure enough, there was a completely different QR code underneath. Someone had stuck a fake payment QR code over the legitimate one. If I'd scanned without looking, my card details would have gone straight to a scammer's fake payment page.

QR code scams, sometimes called "quishing" (QR + phishing), are one of the fastest-growing cyber threats in Australia and worldwide. Attackers paste fake QR codes over legitimate ones in public places, embed them in phishing emails, or print them on fake flyers and posters. When you scan one, it sends you to a malicious website designed to steal your credentials, install malware, or trick you into making a payment.

In this guide, I'll walk through the most common QR code scams, show you how to spot them, and give you a free tool to check any QR code safely.

Got a suspicious QR code?
Take a photo and upload it to our free QR Code Scanner. We'll decode it and check the URL against threat databases.
Scan a QR Code, Free

The 6 Most Common QR Code Scams

1. Parking Meter and Payment Scams

This is the most widespread QR code scam. Criminals place fake QR code stickers on parking meters, public transport ticket machines, and EV charging stations. When you scan to pay, you're directed to a fake payment page that captures your credit card information. These scams have been reported in major cities across the US, UK, and Australia.

⚠️ HOW TO SPOT IT
Look for QR codes that appear to be stickers placed over existing codes. If the QR code is on a sticker and the rest of the signage is printed, that's a major red flag. Use the official parking app or pay at the machine instead.

2. Restaurant Menu Scams

Since the pandemic normalised QR code menus, scammers have started replacing legitimate restaurant QR codes with their own. The fake code redirects to a convincing-looking page that asks you to "log in" or "download the menu app", capturing your credentials or installing malware in the process.

3. Package Delivery QR Codes

You find a "missed delivery" notice on your door with a QR code to "reschedule." Scanning it takes you to a fake courier website that asks for your address, phone number, and a small "redelivery fee", giving scammers both your personal information and payment details.

4. Email QR Code Phishing (Quishing)

Traditional phishing emails contain clickable links that email security filters can detect and block. To bypass these filters, attackers have started embedding QR codes in emails instead. The email might claim to be from IT support asking you to "verify your account" by scanning the code, or from HR directing you to a "benefits portal." Because the malicious URL is encoded in an image rather than a text link, many email filters miss it entirely. This is what frustrates me most about QR code security, local councils and businesses across Australia have rushed to put QR codes on everything from parking meters to restaurant tables without any plan to monitor whether those codes have been tampered with, essentially creating an open invitation for scammers to place their own stickers on top and redirect unsuspecting people to phishing pages.

5. Cryptocurrency Scams

Fake QR codes that encode cryptocurrency wallet addresses are used to redirect payments. You think you're paying a legitimate vendor or donating to a cause, but the QR code sends your crypto to a scammer's wallet. Unlike credit card fraud, cryptocurrency transactions are irreversible.

6. Wi-Fi Network Scams

QR codes in cafes, hotels, and airports that claim to connect you to free Wi-Fi can instead connect you to a rogue network controlled by attackers. Once connected, they can intercept your traffic, capture login credentials, and monitor your online activity.

How to Scan QR Codes Safely

You don't need to stop using QR codes entirely. Just be cautious.

Preview before you open. Most phone cameras show you the URL before opening it. Always read the URL carefully before tapping. Look for the same red flags you'd check in any link: misspellings, unusual domains, and suspicious paths.

Check for physical tampering. Before scanning a QR code in a public place, look for signs that a sticker has been placed over the original code. If the QR code is raised, has different printing quality, or looks out of place, don't scan it.

Use a QR code security scanner. If you're unsure about a QR code, take a photo of it and upload it to a security tool like ScanTotal's QR Code Scanner. It will decode the QR code and check the embedded URL against threat databases without you having to visit the link.

Don't scan QR codes from emails. This is almost never necessary for legitimate purposes. If an email from your company or bank asks you to scan a QR code, go directly to the website by typing the address in your browser instead.

Use official apps for payments. Rather than scanning a QR code on a parking meter or vending machine, use the official payment app. Download it directly from the App Store or Google Play, not from a QR code.

Can You Get Hacked Just by Scanning a QR Code?

Scanning a QR code itself just decodes data, it doesn't execute code or install anything. The danger comes from what you do next. If the QR code contains a URL and you open it, you could land on a phishing site or trigger a download. If it contains a Wi-Fi network configuration, you could connect to a malicious network. If it contains payment information, you could send money to a scammer.

The key is to always review what the QR code contains before taking action. Your phone's camera shows you the decoded content, use that preview as your first line of defence.

Check Any QR Code for Free
Upload a photo or screenshot of a QR code. We'll decode it and check the URL for threats instantly.
Open QR Code Scanner

Why quishing beats old-school phishing defences

A traditional phishing email arrives with a visible URL, either as an inline link or hidden behind a button. Every major email provider scans those URLs, compares them against reputation lists, inspects their structure, and flags or quarantines suspicious ones. The defences are mature and effective.

A QR code short-circuits all of that. The URL is encoded into pixels. Email scanners either skip the image entirely or need specialised OCR-plus-QR-decoding pipelines to read it. Most current enterprise filters don't do this by default. So an attacker sending a phishing email whose call-to-action is a QR image sails through filters that would block the same URL posted as text.

Once the image reaches your inbox, the attack relies on two things:

That combination, bypassed filters plus trusted-but-opaque delivery, is why quishing works.

Three dominant quishing patterns in 2026 Three side-by-side scenarios showing how QR-code phishing reaches victims: a corporate email with an embedded QR code, a sticker placed over a real restaurant table QR code, and a fake QR overlay on a public parking meter. Each scenario explains the trick and the moment defences fail. PATTERN 1 QR-in-email DocuSign Required Please review and sign the attached document. The trick Email filter sees an image, not a URL. Slips past every link-scanning defence. Victim opens with phone, lands on fake login page. PATTERN 2 Sticker swap Table 7 Scan to see menu ⬅ over real one The trick Attacker prints a sticker, walks into the venue, sticks it over the real QR. Done. You're handing card details to a fake "pay-at-table" form. PATTERN 3 Public surface Parking Meter 04A Scan to pay by app The trick Parking meters, EV chargers, posters, ATM screens, any public QR can be replaced. No website to inspect, just a sticker no one will notice.
All three patterns exploit the same gap: a QR code is opaque to your eyes and (usually) to your email filter, but trusted enough that you scan it anyway.

The three dominant patterns in 2026

Pattern 1: QR-in-email (the corporate attack)

Pattern 1

The "scan to review" email

Lure: "Your Microsoft 365 security settings need to be reviewed. Scan the code below from your phone to continue." Or: "Your HR document is ready. Scan the code to view."

Why it works: Corporate email filters don't OCR and decode the QR, so the malicious URL never gets checked. The user pulls out their personal phone, often not covered by the corporate security stack, and scans.

Where it lands: A lookalike Microsoft login, Okta login, or payroll portal. Credentials are captured and replayed.

This is the corporate-crime-of-choice pattern and has been documented repeatedly by CISA and by enterprise incident response firms. It often arrives from a spoofed internal address and references a real process (quarterly review, document approval, multi-factor reset) to increase believability.

Pattern 2: Sticker overlays on physical infrastructure

Pattern 2

The parking meter, EV charger, or restaurant sticker

Lure: A real parking meter, electric vehicle charger, restaurant table, or parcel-locker has a QR code you're expected to scan to pay or view a menu. An attacker prints a lookalike sticker and places it directly over the legitimate one.

Why it works: The context, you're at the actual meter, overrides any scepticism you'd apply to an email QR.

Where it lands: A fake payment page that harvests card details and often charges a real card for a plausible amount so the victim doesn't immediately notice.

Parking-meter quishing has been reported across Australia, the UK, the US, and much of Europe. In Brisbane and the Gold Coast, local councils have had to publish warnings after multiple reports of stickered meters in 2024 and 2025, and similar reports have come from FBI field offices in Texas and Florida. Charging-station quishing targets EV drivers paying through apps, the fake page captures both card details and sometimes the driver's charging-app credentials.

Quick check at a meter or charger: Does the QR sticker look flat and uniform, or is it raised, slightly misaligned, or covering other printed text? Is the URL preview after decoding a domain you'd expect the operator to use, or something generic? If anything feels off, pay inside the app or at the terminal.

Pattern 3: Payment-redirect QRs

Pattern 3

The "scan-to-pay" scam

Lure: An invoice, a charity appeal, or a messaging-app chat where someone sends a QR code "to make payment easier." In India, the UPI ecosystem has variants where a scammer sends a "collect request" QR disguised as a payment-received QR.

Why it works: Payment QRs are legitimate and common. Scanning one to pay a bill is normal behaviour.

Where it lands: The QR either encodes a payment from you (not to you), or routes through a fake payment page that captures details.

For more on the UPI variant specifically, see UPI Payment Scams in India. The general principle, read the payment preview carefully before authorising, applies to any payment-QR scenario globally.

What happens after you scan

Scanning a QR code doesn't do anything dangerous by itself. The QR is just a string, almost always a URL. The risk comes from what's at the other end, and the attacker's ideal outcome is one of:

The point of the QR is to get you to the page without the usual link-safety cues. Everything after that is standard phishing or malware distribution.

How to Safely Scan on iPhone

iPhones have had a built-in QR scanner in the Camera app since iOS 11. Open your camera, point it at the QR code, and a notification banner appears at the top showing you the URL. This is the crucial moment, read the URL before you tap the banner.

If the URL looks legitimate (the correct domain, HTTPS, no strange characters), tap to open it. If anything looks off, unusual domain extension, misspelt company name, unfamiliar domain entirely, don't tap. Our guide on checking if a link is safe covers URL red flags in detail. Instead, take a screenshot of the QR code and upload it to a QR code scanner that checks the destination for threats.

You can also access the QR scanner from Control Centre. Swipe down from the top-right corner, tap the QR code icon, and scan. Same process, always read the URL preview first.

How to Safely Scan on Android

On Android 13 and later, open the Camera app and point it at the QR code. A link preview should appear on screen. On older Android versions, you might need to enable "Google Lens suggestions" in your camera settings, or use Google Lens directly from the search bar widget.

Just like on iPhone, the key step is reading the URL preview before you tap. Android shows you where the link goes, take that half-second to actually look at it. If the parking meter QR code shows a URL like "park-pay-melbourne.example" instead of the council's official domain, don't open it.

Samsung phones have a built-in QR scanner in the camera app as well as through Bixby Vision. Either works fine, just preview the URL.

How to Spot a Tampered QR Code

Physical QR code scams rely on placing fake stickers over real ones. Before you scan any QR code in a public place, check for these signs:

What to Do if You Scanned a Dodgy QR Code

If you scanned a QR code and the website looks suspicious, close it immediately. If you entered any login details or payment information, change those passwords straight away and contact your bank to flag the transaction. Run a security scan on your phone and keep an eye on your accounts for unusual activity over the following weeks.

If you haven't entered any information, you're most likely fine. Simply closing the page is usually enough. Modern phones are quite resistant to drive-by malware installations, especially if you keep your operating system updated.

For organisations: four quick controls

If you run IT or security for an organisation where users are getting quishing emails, four controls cover most of the attack surface:

  1. Enable QR extraction in your email security. Major providers (Microsoft 365, Proofpoint, Mimecast) now offer QR-aware scanning. Turn it on.
  2. Warn users about scan-from-phone prompts. Any email asking the user to scan a QR to complete a corporate action should be treated as suspicious by policy.
  3. Run a test campaign. A QR-phishing simulation shows which users click through and informs training.
  4. Harden mobile device access. If personal phones can reach corporate SSO, quishing becomes a one-step attack. Conditional access and device compliance narrow that path.

What I Do Now Before Scanning Anything

Since that parking meter incident in Melbourne, I check every single QR code before I scan it. I look for raised edges, sticker residue, different printing quality, anything that suggests the code's been tampered with. If I do scan one, I read the URL preview on my phone before I tap it, and if anything looks off, I take a photo and run it through our QR scanner instead. It takes five seconds. The scammers who slapped that fake sticker on the meter were counting on people being in a rush and not looking closely. Don't give them that advantage.

QR Code Scams Quishing QR Code Safety Phishing Online Safety

Found a suspicious QR code? Upload a photo and we'll check it.

We decode the QR code and scan the URL for threats, free and instant.

Scan a QR Code Now

Sources & Further Reading