ScanTraceQR
← All guides Guide

Are QR Codes Safe to Scan? How to Spot a Malicious One

By The ScanTraceQR Team · July 25, 2026 · 8 min read


QR codes are on menus, parking meters, packaging, posters and payment terminals — and unlike a link in an email, you can’t see where one goes just by looking at it. That opacity is the whole security story. The pattern itself is harmless; what it hides is the problem.

Here’s what a QR code can and cannot do to your phone, how the real-world attacks actually work, and a short routine that removes nearly all of the risk.

What a QR code actually is

A QR code is a way of printing text so a camera can read it. That’s the entire technology. The text is most often a URL, but it can be plain text, a phone number, a Wi-Fi network name and password, a contact card, or a payment string.

It contains no executable code. There is no mechanism by which scanning a pattern of squares installs software on your phone. Anyone telling you a QR code “gave them a virus” is describing something that happened after the scan — on the page it opened, or in an app they were persuaded to install.

So the honest framing is: a QR code is exactly as safe as clicking an unknown link — with the crucial difference that you can’t read the link first. That’s a meaningful downgrade in your ability to judge, and it’s what attackers exploit.

The real risks

1. Quishing — phishing by QR code

The dominant attack. A code leads to a convincing replica of a login page, a bank form or a delivery-fee payment screen. Because the victim arrived by scanning a physical object in the real world, the page inherits a sense of legitimacy that the same link in an email would never get.

QR-based phishing also slips past defences built for text: email filters that scan for malicious URLs see only an image, and there is no hoverable link for a suspicious user to inspect.

2. Sticker overlays on public infrastructure

The most effective physical version. Someone prints a malicious code as an adhesive label and sticks it over the legitimate one — on parking meters, EV charging points, bike-hire docks, public transport signage, restaurant tables. Reports of exactly this have come from municipalities and transport operators in several countries.

The victim scans what they reasonably believe is the operator’s code and lands on a payment page that takes their card details. Because they expected to pay, nothing feels wrong.

3. Fake payment codes

In markets where QR payments are routine, a substituted merchant code sends money to the attacker instead of the shop. Both sides can be some way into the transaction before anyone notices.

4. Codes that aren’t links at all

Less common, and mostly nuisance rather than compromise:

  • Wi-Fi codes that join you to an attacker-controlled network, where unencrypted traffic can be observed.
  • Contact cards that add a plausible-looking but fraudulent entry to your address book.
  • Pre-filled SMS or call actions to premium-rate numbers. Your phone should always ask before sending — don’t wave that prompt away.

5. Legitimate codes pointing somewhere stale

Worth knowing about because it isn’t malicious. Dynamic QR codes let the owner change the destination after printing. If a business abandons the account or its short-link provider shuts down, a perfectly genuine printed code can end up pointing at a parked domain — which may later be bought by someone else. An old code on old signage deserves a little more scepticism than a fresh one.

The pattern across every one of these: the danger is the destination, never the code. Every practical defence is therefore about seeing the destination before you commit to it.

How to scan safely

Read the URL preview before you tap

Modern iPhone and Android cameras show the destination in a banner when they detect a code. That banner is your defence — read it. If your scanner app doesn’t preview URLs, replace it with one that does.

What to look for:

  • Does the domain match the organisation? A code on a bank’s poster should lead to the bank’s domain, not a lookalike.
  • Check for lookalike spellings. paypa1.com, your-bank-secure.com, rnicrosoft.com. Attackers rely on you reading the shape of a word rather than its letters.
  • Read the domain right-to-left from the final slash. In example.com.evil.ru/login, the actual host is evil.ru. Everything to the left is decoration.
  • Be extra careful with shorteners. A short link is not malicious in itself — plenty of legitimate campaigns use them, including dynamic QR codes — but it hides the final destination, so it deserves more scrutiny of the physical context.

Inspect the physical code

This catches the sticker attacks, and it takes two seconds:

  • Is it a sticker on top of something else? Look for a raised edge, a lifted corner, a mismatch in finish or a code that sits oddly within its printed frame.
  • Does the print quality match the surrounding material? A crisp laminated sign with one slightly pixelated code is a red flag.
  • On payment terminals and parking meters, does the branding around the code match the operator?
  • If something feels off, use the operator’s app or type the URL from the signage manually.

Apply the normal rules once you land

  • Never enter credentials on a page you reached by scanning. If a code sends you to a login, close it and navigate to the site yourself or use your password manager, which won’t autofill on the wrong domain — a genuinely useful signal.
  • Never install an app from a QR code. Go to the official store and search for it.
  • Be suspicious of urgency. “Your vehicle will be towed”, “payment failed, re-enter your card”. Manufactured time pressure is the constant across every variety of this fraud.
  • Watch for unexpected downloads. A scan that immediately fetches a file is not normal.
  • Keep your phone updated. Doesn’t stop phishing, but closes the browser vulnerabilities a hostile page might otherwise reach for.

If you think you’ve scanned a malicious code

  • Close the page. Don’t enter anything further.
  • If you entered a password, change it immediately — everywhere you reused it.
  • If you entered card details, contact your bank now and ask them to block the card.
  • If you installed something, remove it and run a scan with your platform’s built-in protection.
  • Report the physical code to whoever owns the location — the café, the council, the charging network. A sticker left in place keeps catching people.

If you publish QR codes

You’re also a target, because a tampered code damages your customers and your reputation:

  • Print the URL in readable text beside the code. It gives people a way to verify the destination and a fallback if the scan fails.
  • Use your own recognisable domain where you can. A destination customers recognise is one they can check.
  • Laminate or print codes directly onto the material rather than applying stickers — a stuck-on code is easy to cover with another stuck-on code.
  • Check your physical codes periodically. Someone should be looking at the ones in public places.
  • Monitor your scan analytics. A code that suddenly stops registering scans may have been covered over — one of the more practical reasons to use a trackable code at all.

The short version

QR codes don’t carry malware and can’t run anything on your phone. They hide their destination, and that hiding is what attackers use. Read the URL banner before you tap, glance at whether the code has been stuck on top of something, and never type a password or card number into a page you arrived at by scanning. That routine takes a few seconds and defeats essentially all of it.

If you’re making codes rather than scanning them, our free QR code generator creates one in your browser, and a trackable QR code lets you spot the sudden drop in scans that means a code in the wild has been covered up.

Frequently asked questions
Can a QR code give you a virus?

Not by itself. A QR code is just encoded text — usually a URL. It cannot execute anything on your phone. The risk is entirely in what the encoded link leads to: a phishing page, a fake payment form, or a prompt to install an app from outside the official store.

How can I see where a QR code goes before opening it?

Most modern phone cameras show the destination URL in a banner before you tap it. Read that URL first. If your camera doesn’t preview it, use a scanner app that does — being able to inspect the link before opening is the single most useful safety feature.

What is quishing?

Quishing is phishing delivered by QR code. Because the destination is hidden inside the pattern, a malicious code can be printed on a sticker and placed over a legitimate one — on a parking meter, an EV charger or a restaurant table — sending people to a convincing fake payment or login page.

Is it safe to scan a QR code on a restaurant table?

Usually, but check the sticker physically. If it’s a printed label stuck on top of the table’s own code or laminate, treat it with suspicion. Then check the URL preview matches the restaurant’s real domain before tapping.

Try it yourself — free

Create your first tracking link and QR code in under a minute.

Get started free
Keep reading