How to Spot a Fake QR Code — QR Code Phishing Explained

Picture this: you pull up to a parking meter, see the QR code sticker for the payment app, and scan it without a second thought. The page that loads looks vaguely right — logo, input fields, the usual. You enter your card number and move on with your day. A week later there's a charge on your statement from a city you've never visited.

This isn't a hypothetical. QR code phishing — sometimes called quishing — has been showing up at parking meters, restaurant tables, package delivery notices, and airport charging stations across the country. The FBI and FTC have both issued warnings about it. And because QR codes are just patterns of black and white squares, there's nothing visual that distinguishes a legitimate one from a fake QR code someone printed and slapped on top.

The good news: once you know what to look for, you can sidestep almost all of it.


What QR Code Phishing Actually Is

The attack is low-tech and surprisingly effective. Someone prints a QR code that points to a site they control — a fake login page, a credential-harvesting form, or a page that silently attempts to install malware. Then they stick that code over a legitimate one in a high-traffic public location.

Parking meters are a favorite target because people are rushed and distracted. Restaurant tables work because diners expect to scan a QR code for the menu. Package delivery notices work because you're already anxious about a package. The context does half the job — you have every reason to trust the code before you even look at it.

It's not just physical stickers, either. Malicious QR codes show up in phishing emails, text messages, fake invoices, and social media posts. The delivery method varies, but the goal is the same: get you to scan without thinking, and then capture whatever you type next.


5 Signs a QR Code Might Be Fake

None of these are foolproof on their own, but if you see more than one, slow down.

1.

It's a sticker placed over an existing code.

Run your fingernail along the edge of the code. If you can feel a raised sticker — especially at a parking meter or on signage you'd expect to be printed directly — that's a red flag. Legitimate codes are usually printed on the sign itself, not stuck on top of something else.

2.

The URL preview looks off.

Most phone cameras show you the URL before you tap. Look at it. Does it match the organization you're expecting? A parking app should have the city's official domain, not a shortened link, a misspelled brand name, or a random string of characters. If the URL looks wrong, it probably is.

3.

It sends you somewhere unexpected.

A restaurant menu QR code shouldn't ask for your Apple ID password. A parking meter code shouldn't route you through three redirects before landing on a login page. If scanning a code that should show you a PDF or menu instead asks for credentials, close the browser immediately.

4.

The code is in an unusual location.

An unsolicited email with a QR code instead of a link. A handwritten note on your door with a code to “claim a prize.” A poster for something that doesn't quite make sense. QR codes in weird contexts — ones you weren't expecting, from sources you don't recognize — warrant more skepticism than the menu code at your regular lunch spot.

5.

There's urgency pressure.

“Scan now or your account will be suspended.” “Your package is on hold — scan within 24 hours.” Urgency is the oldest trick in phishing because it works. It short-circuits the part of your brain that would otherwise pause and ask “wait, why does a parking meter need me to act in the next 10 minutes?”


What to Do Before You Tap

The single most useful habit: read the URL before you open it.

When you point your camera at a QR code, your phone shows you a banner with the URL before anything loads. That two-second pause is your window. Look at the domain — not just the beginning of it, but the actual root domain right before the first slash. That's where fakes hide. A URL like cityparking-pay.io/meter/123 looks plausible until you notice that your city's parking app is at parking.yourcity.gov.

If the URL is a shortened link (bit.ly, tinyurl, t.co) and you don't know exactly what it points to, treat it as suspicious. Legitimate public infrastructure doesn't need to hide its URLs behind shorteners.

And if anything feels off — the page asks for unexpected credentials, your browser warns you about the site, or something just seems wrong — close it. Don't enter any information. You can always find the real URL directly.


Why a Dedicated Scanner Gives You an Advantage

Here's the problem with your phone's built-in camera: it's optimized for convenience, not caution. On many phones, scanning a QR code with the default camera app will immediately open the URL in Safari or Chrome — sometimes with barely a glimpse of where it's going. The URL banner appears for a second, then disappears. You have to be fast and know what to look for.

A dedicated scanner like SnapScan shows you the full decoded content of the QR code — the complete URL, text, contact info, whatever is actually in it — before you decide what to do with it. Nothing opens automatically. You see the URL, read it, and then tap to open if you want to. That's the entire difference: you stay in control of what gets opened on your phone instead of the code deciding for you.

It's also worth noting that dedicated scanners tend to be much more privacy-conscious than the built-in camera. If you haven't already read about what QR scanner apps do with your data, the short version is: many of them log your scans, sell your location data, and ask for far more permissions than they need. That's a separate problem from phishing, but it's worth thinking about at the same time. When you're thinking about what permissions your scanner actually needs, the answer is: just the camera.

If you frequent restaurants, this is especially relevant. We have a whole post on restaurant QR code safety that goes into the specifics — table codes are one of the more common targets for tampered stickers because they're easy to replace and diners are conditioned to trust them.


SnapScan: See the URL Before You Open It

SnapScan is a one-time $14.97 — no subscription, no account, no data collection. It shows you the full decoded URL (or text, or contact info, or whatever the code actually contains) before anything happens. You decide what to open. The QR code doesn't decide for you.

It's the simplest possible defense against QR code scams: just see what's in the code before you act on it. For more on the privacy side of things, the privacy post covers what SnapScan does and doesn't collect in detail.

See every QR code's content before you open it.

One-time $14.97. No subscription. No data collection.

Get SnapScan — $14.97 One-Time

FAQ

Can QR codes contain viruses?

The QR code itself can't contain a virus — it's just encoded data, usually a URL. What it can do is point you to a website that attempts to download malware, or to a phishing page that tries to steal your credentials. The code is just the delivery mechanism. The danger lives on the other end of the link, which is why reading the URL before you open it is so important.

How can I check if a QR code is safe before scanning?

The best approach is to use a scanner that shows you the full URL before opening it. Most built-in phone cameras flash the URL briefly, but a dedicated app like SnapScan holds it on screen so you can actually read it. Look at the root domain — the part right before the first single slash — and ask whether it matches the organization you're expecting. If it's a shortened URL or an unfamiliar domain, don't open it.

What should I do if I accidentally scanned a fake QR code?

Close the browser immediately and don't enter any information on the page. If you've already entered a password or payment info, change the password right away and contact your bank or card issuer if financial details were involved. Most damage from QR phishing happens at the credential entry step, not from scanning itself — so catching it before you type anything limits the exposure. If the page attempted to download something, check your downloads folder and delete anything unfamiliar.

Are QR codes at restaurants safe?

Usually, yes — but not always. Table tent codes and posted menu codes are a target for tampered stickers because they're low-effort to replace and customers are conditioned to trust them. A quick glance to check whether the code looks like a sticker vs. printed directly on the material is a good habit. And reading the URL before opening it takes two seconds. For the full breakdown on this scenario, see the restaurant QR code safety guide.


The QR code itself can't hurt you — it's just data. It's what it points to that matters. Take two seconds to read the URL before you tap, and you'll sidestep 99% of QR code scams.

SnapScan shows you the full URL before anything opens. $14.97 once, no subscription.

Get SnapScan — $14.97 One-Time

From the makers of this guide

No Ads. Just Scans.

SnapScan scans QR codes instantly — no ads, no tracking, works offline. One-time $14.97.

Get SnapScan — $14.97 (30-day guarantee)