A QR code is just a link wearing a costume. Your phone reads the black-and-white squares, finds a web address inside, and offers to open it — that’s the whole trick. Useful, fast, and exactly why it’s become a favorite tool for scams. Here’s how to scan without getting caught.
Short answer: Scanning a QR code is safe; the link inside is the risk. Preview the URL before you open it, distrust codes stuck in public places, and never enter a password or payment on a page you reached by scanning a code you didn’t expect.
Why QR codes are a scammer’s dream
A normal phishing link shows its address — you can hover, squint, and spot paypa1-secure.com before you click. A QR code shows you nothing but squares. That opacity, plus the fact that most scans happen on a phone where the address bar is tiny, strips away the defenses people have built up against dodgy links.
The scam even has a name: quishing (QR + phishing). The playbook is simple — put a code somewhere trusted, point it at a fake page, and wait.
Where the fake codes show up
- Texts you didn’t expect. A “package couldn’t be delivered” or “unpaid toll” message with a link or code — the most common form today, and the one to distrust most.
- Stickers over real codes. Parking meters, EV chargers, and restaurant tables are prime targets: a scammer covers the genuine code with their own.
- Unsolicited mail and flyers. The same “missed delivery” or “unpaid fee” hook, printed and mailed to look official.
- Emails and PDFs. A code in an attachment dodges the link-scanning that protects your inbox.
- Too-good posters. Free Wi-Fi, a prize, a discount — scan here.
The five-second safety check
Before you act on any code:
- Preview the URL. Your phone’s camera shows the address first — read it. A legit brand uses its real domain, not a random link shortener.
- Look for tampering. On a physical code, is there a sticker on top? Does it look added-on?
- Distrust urgency. “Pay now or your car is towed” is pressure, and pressure is the scammer’s oldest tool.
- Never enter credentials from a cold scan. No passwords, no card numbers on a page you reached by scanning something unexpected.
- When unsure, type it. Go to the company’s real site directly instead of trusting the code.
If you do end up entering a password anywhere it shouldn’t have gone, change it immediately — and if you reuse that password, this is your sign to generate a unique one with a Password Generator.
Making codes other people can trust
If you’re the one creating QR codes — for a menu, a poster, a business card — you’re asking strangers to trust a link they can’t read. Return the favor:
- Point to a real, recognizable domain, not an anonymous shortener that looks exactly like a scam.
- Generate the code somewhere private. The QR Code Generator builds your code entirely in your browser, so the destination — which might be a private form or a payment link — is never uploaded to a third-party server.
- For genuinely sensitive text, don’t put the secret in the code at all. Encrypt it first with Encrypt Text and share the passphrase separately, so a code that gets photographed off a wall reveals nothing.
The one habit that covers most of it
QR codes aren’t dangerous; blind trust is. Treat every code like a link from a stranger — because that’s precisely what it is — and the same instinct that makes you hesitate over a weird email link will keep you safe here too. Want the mechanics of building and testing your own? Read how to create a QR code.