QR Boost
Log in
Safety

QR code scams: how to spot them and stay safe

A QR code doesn't show where it leads until you scan it, and scammers take advantage of that. A few simple checks make it easy not to fall for it.

Updated on 17 September 2026

What quishing is

Quishing (from QR and phishing) is a scam in which a QR code takes you to a fake website that imitates a company or public body in order to steal your passwords, bank details or money, or to get you to install a malicious app.

Common forms include:

  • Fake stickers over the original code on parking meters, electric car chargers, restaurant tables or posters.
  • Emails containing a QR code instead of a link, to get past spam filters and make you open it on your phone, which is often less protected.
  • Fake parcel or fine notices in letters or notes asking you to pay a small amount by scanning the code.
  • Payment QR codes that lead to a fake payment page.

Why these scams work

You can read a written link before tapping it; you can't read a QR code. On top of that, codes tend to appear in places we trust (a restaurant table, the parking meter on our street, an official-looking letter), and we scan them in a hurry, on a phone, where the full address is harder to see. Scammers play on that trust and on urgency: a fine that goes up if you don't pay today, a parcel about to be returned or parking that runs out in minutes.

The good news is that the QR code itself isn't dangerous: scanning it doesn't install anything. The risk lies in what you do next, on the site you land on.

How to spot a suspicious QR code

  • Check the domain your camera shows before opening it. If it has nothing to do with who it claims to be, or looks odd, don't open it.
  • Look for stickers over the original code. If the code looks added on or is peeling off, be wary.
  • Be suspicious of urgency: “pay today or you'll be fined”, “your parcel will be returned”.
  • Never enter passwords or bank details on a site you reached through a QR code unless you're completely sure.
  • To pay, use the official app (of the car park, the council or your bank) rather than the QR code.
  • Report it to whoever runs the place and, if it's a QR Boost code, through our report form.

If you've already entered your details

  1. Change the password of the affected account and of any other account that uses the same one.
  2. Call your bank as soon as possible if you gave card details or made a payment.
  3. Report it to the police.
  4. Contact your national cybersecurity or fraud helpline, e.g. Action Fraud in the UK.

If you create QR codes for your business

  • Place them where they're hard to cover: behind glass, printed on the display itself or on materials that show signs of tampering.
  • Use a branded frame and a clear call to action, so that a code stuck on top stands out.
  • Show the short link under the code, so people can check it matches.
  • Check your codes regularly in case someone has stuck another one over them.
  • Use a provider that screens destinations.

How QR Boost protects people who scan

  • We check every destination (the main one, rule destinations, the fallback and the website on contact cards) against Google's lists of dangerous sites (Google Web Risk) when a QR code is created or edited, and we recheck all active destinations periodically.
  • We reject dangerous destinations. If a QR code's destination becomes dangerous, the code is blocked automatically and shows a “not available” page instead of redirecting.
  • Destinations that point to IP addresses, contain credentials in the link or chain through other link shorteners get extra scrutiny. IP-address and credential links are rejected.
  • Anyone can report a QR code through our report form, and we review every report.
  • Our terms of use forbid phishing and malware.
  • We never store the IP address of people who scan.

When you scan a QR Boost code, your camera shows qrboost.com/go/…, not the final destination. That's why we screen that destination ourselves. And because the redirect is direct, with no interstitial page, check the address bar of the page you land on.

Learn more in how QR Boost works.

FAQ

Is it safe to scan a QR Boost code?

We check destinations against Google's lists of dangerous sites and block the ones that are, but no check is foolproof: always look at the address of the page you land on and don't give out details if something feels off.

How do I report a QR code?

If it's a QR Boost code (its link starts with qrboost.com/go/), use the form at /en/report. If you've been scammed, report it to the police as well.

What do you do with reports?

We review every one. If the QR code breaks our terms of use, we block it and it stops redirecting.

What should I do if I've already paid or given my details?

Change your passwords, call your bank, report it to the police and contact your national cybersecurity or fraud helpline, such as Action Fraud in the UK.