Back to BlogTemp Mail Lab Journal

The QR Code Scam: What Happens After You Scan?

TempMailLab TeamJuly 28, 20269 min read
Phone scanning a parking QR code that leads to a suspicious website

A QR code is not automatically dangerous, but its hidden link can lead to fake logins, payment scams, or unwanted downloads. Learn what to check and do next.

A QR code is not automatically dangerous. It is a compact way to store a link or another instruction that a phone can read. The trouble is that the code does not show its destination in plain text before you scan it. A scammer can use that gap to send you to a fake sign-in page, a payment page they control, or a download you did not expect.

If you scan a code and only see a web address, pause before opening it. If you opened a page but did not enter information, approve permissions, download anything, or send money, close the page and use the company's official app or a URL you type yourself. The risk rises when the page persuades you to expose an account, a payment method, or the phone itself.

Why a QR code can hide the real destination

A QR code is useful because it saves typing. It can open a menu, a parking payment page, an event ticket, or a sign-in flow. That convenience also makes the destination hard to inspect while the code is still on a poster, receipt, or phone screen. The FTC warns that scammers use QR codes to hide harmful links, including links that lead to sites designed to look real. The code is not the threat. The site, request, or payment destination behind it may be.

The term quishing means QR code phishing. It describes the same trick as phishing by email or text: someone wants you to trust a destination that only looks connected to a familiar business, government office, bank, delivery company, or employer. A code can be sent in a message, printed on a sign, or placed over a real code with a sticker.

The FBI has documented cases where criminals replaced physical and digital QR codes to redirect people to malicious sites, steal login or financial information, or divert payments. That is why a code in a familiar place still deserves a quick check.

What can happen after you scan

A scan can lead to an ordinary webpage. It can also open a page that imitates a service you use. The page may ask you to sign in, update billing details, confirm a delivery, or pay a small balance. It may try to create urgency with a warning about a missed package, an overdue bill, suspicious account activity, or a parking deadline.

The intended result depends on the scam. A fake sign-in page can collect the username and password you type. A fake bill or parking page can collect card details or direct a payment to the wrong recipient. A page may ask you to install an app, download a file, or allow permissions that do not make sense for the task. The FBI also warns that QR codes can be used to redirect payments, so treat payment pages reached through an unexpected code with extra care.

This is different from saying that every QR scan compromises a phone. It does not. A scan becomes more serious when you act on a deceptive prompt. Keeping that distinction in mind helps you respond calmly instead of assuming the worst or ignoring a real warning.

QR code branching to a login, payment, download, or safe menu destination

Common QR code scam scenarios

Parking meters and pay stations

A parking meter may display a QR code for payment, and that is a normal use of the technology. The scam appears when someone places a new sticker over the legitimate code. You scan it, see a page that resembles a parking service, and enter card details or make a payment that does not go to the operator. Before scanning, look for a loose edge, mismatched printing, or a sticker that seems to sit on top of another label. If anything looks off, use the parking app you already know, the meter's payment method, or the operator's official website.

Restaurant menus

Restaurant QR menus are common, which makes them easy to imitate. A menu code should take you to the restaurant's menu or ordering page. Be cautious if it immediately asks for a card number, a full account sign-in, or an app download just to show a menu. You can ask staff for a printed menu or confirm the restaurant's official website before opening a payment page.

Package delivery messages and unexpected parcels

A delivery text can claim that a driver could not complete a drop-off and ask you to scan a code to reschedule. An unexpected package can include a QR code that supposedly identifies the sender or explains a return. Both stories rely on curiosity or urgency. The FTC and FBI warn that these codes can lead to phishing pages, requests for financial information, or unwanted downloads. Check tracking in the carrier's official app or type its known website into your browser instead.

Sign-in prompts

A QR code can be part of a legitimate sign-in process, especially when you are linking devices. The safer pattern starts from a service you already opened yourself, such as its official app or website. Be suspicious when an email, poster, or message sends you to a code that asks for a password or a verification code. A real company can have a QR login feature, but a random QR code cannot prove that the page behind it belongs to that company.

Bills, fines, and payment requests

Scammers often make payment requests feel urgent. A QR code may be presented as the fastest way to settle a utility bill, a traffic fine, or an account balance. Do not rely on the code or the contact details printed beside it. Open the provider's official app, use a bookmarked address, or look up its number independently. This also avoids sending a payment to the wrong recipient through a site that merely resembles the real one.

A sticker covering a real code

This is the physical version of a spoofed link. The location may be legitimate while the code has been altered. The FBI specifically advises people to check physical codes for tampering, including a sticker placed over the original. A quick visual inspection cannot prove that a code is safe, but it can reveal an obvious replacement before you scan.

Suspicious sticker placed over a legitimate QR code with a magnifying glass

How to check a QR code before you act

First, ask where the code came from and whether you expected it. A code in an unsolicited text, email, package, or flyer deserves more skepticism than one you reached through a company's own app. Urgency is another warning sign. Claims that you must scan now to avoid a fee, restore an account, or receive a delivery are designed to shorten your decision time.

Next, inspect the web address your phone shows before you continue. Look for the correct domain name, not just a familiar logo or a few recognizable words. Misspellings, extra words, unusual endings, and unrelated domains are reasons to stop. A short URL can hide the final destination, so it is not proof that the page is legitimate.

For a payment, sign-in, or account recovery task, take the safer route: open the company's official app or manually type a known address. Do not install a QR scanner app just for this purpose. Most phones can scan codes through the built-in camera, and the FBI advises using the app store rather than a QR code if you need to download an app.

Phone URL preview checked before opening a QR-code link

What to do if you already scanned it

If you scanned a code but did not open the link, do not continue. If you opened the page and did nothing else, close it. Then use an official channel if you still need to pay, track a package, view a menu, or sign in.

If you entered a password on a page reached through a suspicious code, change that password from a trusted device or official app. If you reused it elsewhere, change those accounts too. Turn on multi-factor authentication where it is available, and review recent account activity. A fake CAPTCHA can turn a web scam into a malware incident when it asks you to run commands or download something. If that happened, stop using the device for sensitive tasks and follow the guidance in our fake CAPTCHA and ClickFix malware guide.

If you entered card or bank details, contact the card issuer or bank using the number on the card or its official website. Explain what information you entered and follow its fraud process. If you made a payment, contact the payment provider promptly and keep any screenshots, transaction details, messages, and the QR code if you can do so safely. Do not return to the suspicious page to collect more information.

If you installed an app or granted unusual permissions, remove the app if you can identify it, review its permissions, and run your phone's trusted security checks. Update the phone's operating system. If you are unsure whether the device is safe, use a different trusted device for password changes and financial accounts.

When a QR code is probably legitimate

No visual cue can guarantee that a QR code is safe. Still, a code is less concerning when it appears inside an official app or on a page you reached by typing a trusted address, when the destination shows the correct domain, and when the request matches the task. A restaurant menu should not need your bank password. A parking session should not demand a software download. The request should make sense for the context.

Frequently asked questions

Can a QR code hack my phone just by scanning it?

A scan alone does not automatically mean your phone was hacked. The concern is what the code opens and what you do next. Close an unexpected page and avoid entering information, downloading files, or approving permissions.

Should I pay a bill through a QR code?

Only use a QR payment flow when you can independently confirm the business and the destination. For an unexpected bill, fine, or payment warning, open the provider's official app or website instead of using the code.

What should I do if a QR code leads to a fake login page?

Do not enter anything. Close the page and go to the service through its official app or a known web address. If you already entered a password, change it through the official service and review the account for unusual activity.

A QR code saves a few seconds of typing, but it should not decide where you sign in or send money. When the task involves an account, a payment, a delivery, or an unexpected warning, stop long enough to verify the destination through a channel you already trust.

CybersecurityOnline Privacy
Donate