Skip to content
TToolnest

Generators · Guide

Are QR Codes Safe? How to Spot a Malicious One

A QR code is just a link in disguise — which is exactly why scammers love them. How "quishing" works, the red flags to check before you scan, and how to make codes people can trust.

Updated 2026-07-13

Use the toolQR Code GeneratorOpen

A QR code is just a link wearing a costume. Your phone reads the black-and-white squares, finds a web address inside, and offers to open it — that’s the whole trick. Useful, fast, and exactly why it’s become a favorite tool for scams. Here’s how to scan without getting caught.

Short answer: Scanning a QR code is safe; the link inside is the risk. Preview the URL before you open it, distrust codes stuck in public places, and never enter a password or payment on a page you reached by scanning a code you didn’t expect.

Why QR codes are a scammer’s dream

A normal phishing link shows its address — you can hover, squint, and spot paypa1-secure.com before you click. A QR code shows you nothing but squares. That opacity, plus the fact that most scans happen on a phone where the address bar is tiny, strips away the defenses people have built up against dodgy links.

The scam even has a name: quishing (QR + phishing). The playbook is simple — put a code somewhere trusted, point it at a fake page, and wait.

Where the fake codes show up

  • Texts you didn’t expect. A “package couldn’t be delivered” or “unpaid toll” message with a link or code — the most common form today, and the one to distrust most.
  • Stickers over real codes. Parking meters, EV chargers, and restaurant tables are prime targets: a scammer covers the genuine code with their own.
  • Unsolicited mail and flyers. The same “missed delivery” or “unpaid fee” hook, printed and mailed to look official.
  • Emails and PDFs. A code in an attachment dodges the link-scanning that protects your inbox.
  • Too-good posters. Free Wi-Fi, a prize, a discount — scan here.

The five-second safety check

Before you act on any code:

  1. Preview the URL. Your phone’s camera shows the address first — read it. A legit brand uses its real domain, not a random link shortener.
  2. Look for tampering. On a physical code, is there a sticker on top? Does it look added-on?
  3. Distrust urgency. “Pay now or your car is towed” is pressure, and pressure is the scammer’s oldest tool.
  4. Never enter credentials from a cold scan. No passwords, no card numbers on a page you reached by scanning something unexpected.
  5. When unsure, type it. Go to the company’s real site directly instead of trusting the code.

If you do end up entering a password anywhere it shouldn’t have gone, change it immediately — and if you reuse that password, this is your sign to generate a unique one with a Password Generator.

Making codes other people can trust

If you’re the one creating QR codes — for a menu, a poster, a business card — you’re asking strangers to trust a link they can’t read. Return the favor:

  • Point to a real, recognizable domain, not an anonymous shortener that looks exactly like a scam.
  • Generate the code somewhere private. The QR Code Generator builds your code entirely in your browser, so the destination — which might be a private form or a payment link — is never uploaded to a third-party server.
  • For genuinely sensitive text, don’t put the secret in the code at all. Encrypt it first with Encrypt Text and share the passphrase separately, so a code that gets photographed off a wall reveals nothing.

The one habit that covers most of it

QR codes aren’t dangerous; blind trust is. Treat every code like a link from a stranger — because that’s precisely what it is — and the same instinct that makes you hesitate over a weird email link will keep you safe here too. Want the mechanics of building and testing your own? Read how to create a QR code.

Frequently asked questions

Can scanning a QR code hack my phone?+

Not by itself. A QR code only stores data — almost always a web address — so scanning it can't install anything on its own. The danger is what the link leads to: a fake login page, a payment scam, or a prompt to download a malicious app. The scan is safe; the destination is where you have to be careful.

What is "quishing"?+

Quishing is phishing that uses a QR code instead of a clickable link. Because a code hides its destination and often gets scanned on a phone — where the full address is harder to inspect — it slips past the instincts people have learned for suspicious email links. Fake parking-meter stickers and bogus restaurant menus are common real-world examples.

How can I check a QR code before opening the link?+

Use your phone's built-in camera, which previews the URL before opening it, and actually read that preview. Look for a legitimate domain, not a random shortener or a look-alike misspelling. On a physical code, check that no sticker has been placed over the original. When in doubt, type the address yourself instead of tapping.

Ad

Tools in this guide

Related guides