All scam guides

How to spot a QR code scam

Updated October 11, 2026

A QR code is a link you cannot read until you scan it. Scammers use that: they stick their own code over a real one, or print it on a letter, an email or a package. The code opens a fake page that asks for your card details or a password, or pushes you to install an app. Police and consumer agencies in the US and Europe now warn about it regularly. It is often called "quishing", short for QR phishing.

Where scam QR codes show up

  • Parking meters and pay stations, as stickers over or next to the real code.
  • Fake delivery or collection notices in your letterbox, asking you to rebook a parcel.
  • Emails and PDF attachments: "your password expires", "sign this document", "confirm your account". A QR code in an email gets past many work email filters.
  • Packages you never ordered, with no sender and a QR code inside.
  • Fake fines, toll notices and tax refunds.
  • Posters, flyers and restaurant tables, where a sticker can sit on top of the real menu code.

Warning signs in the link

Most phone cameras show the address before opening it, and QR Snap shows it in full. Read it before you tap:

  • The site name is the part just before .com, .co.uk, .fr and so on. In paypal-secure-login.com the site is paypal-secure-login, not PayPal. In royalmail.parcel-reschedule.help the site is parcel-reschedule.help.
  • Misspellings and swapped characters: paypa1 with a one, rnicrosoft with "rn" for "m", an extra or missing letter.
  • An "@" in the address. Everything before it is ignored, so https://www.paypal.com@example.net opens example.net.
  • A short link (bit.ly, tinyurl and many QR services) hides the real destination. That is not proof of a scam, but you need to see where it ends up.
  • A payment or sign-in page on a free website builder or hosting address (weebly.com, pages.dev, github.io, web.app and similar). Banks, parking operators and carriers use their own domains.
  • Pressure: pay within the hour, your account is suspended, the fine doubles tomorrow.

What QR Snap checks before you open a link

QR Snap shows you the link first and does not open it until you tap. Before you do, it runs these checks:

  • Where it really goes. Short links and redirects are followed to the page they end on, and QR Snap shows that site ("Opens example.com, after 2 redirects").
  • Known threats. The link and its destination are checked against Google Web Risk and a public list of active phishing sites.
  • Look-alike names. A company name on a site it does not own, misspellings like paypa1 or rnicrosoft, letters from other alphabets, and an "@" that hides the real address.
  • Free website builders and file hosts. A payment or sign-in page hosted on a free site builder, a dynamic-DNS name or a storage bucket is a common scam setup.
  • Brand-new websites. Most scam sites are days or weeks old, so QR Snap shows when the site was registered.

If you already entered your details

  • Card details: call your bank on the number printed on your card, block the card and ask about a chargeback.
  • A password: change it on the real site, and anywhere else you use it. Turn on two-step verification.
  • An app you installed from the link: uninstall it and run your phone’s security check. On Android, that is Google Play Protect.
  • Report it. In the US: reportfraud.ftc.gov and ic3.gov. In the UK: Action Fraud, or forward scam texts to 7726. In the EU and Switzerland: your national police or cyber security centre.

What no checker can promise

New scam sites appear every day, and some hide behind bot checks so automated tools only see a harmless page. A clean result means none of the checks found a known threat, not that the page is guaranteed safe. If a page asks for card details or a password you did not expect to give, close it and go to the company yourself: type its address or open its official app.

Sources

More guides