📷 Consumer Security

QR Code Phishing Is Surging — How to Check If a QR Code Is Safe Before You Scan It

KandiCare · May 22, 2026 · 7 min read

QR codes are everywhere — restaurant menus, parking meters, package notices, email attachments. Attackers know this. They've replaced the link in phishing emails with a QR code image, because your security software can't read what's inside a picture.

What Is QR Code Phishing?

A QR code is just a machine-readable image that encodes a URL. When you point your phone camera at one, the camera decodes the URL and opens it — usually with a single tap and no preview. That last part is the problem.

With a normal link in an email, you can hover over it and read the destination before clicking. Your email security software can scan it. You can spot "amaz0n.com" instead of "amazon.com." With a QR code, the URL is invisible to both you and your security tools. The only thing you see is a grid of black-and-white squares.

Attackers figured this out. QR code phishing — nicknamed "quishing" — has become one of the fastest-growing social engineering attacks. Microsoft's Digital Crimes Unit reported a 587% spike in QR phishing campaigns in a single year. The FBI issued a public warning after a wave of fake parking meter QR code stickers appeared across major US cities.

587% Increase in QR phishing campaigns (Microsoft, 2023)
22% Of phishing emails now use QR codes instead of links
$50M+ Lost to parking meter QR scams in the US

Why QR Codes Are So Dangerous Right Now

Three things have converged to make quishing effective:

1. Your security software is blind to it. Corporate email gateways, Microsoft Defender, and consumer antivirus tools analyze URLs in email bodies. They don't extract and analyze URLs encoded inside image files. A phishing email that replaces its malicious link with a QR code image sails through many filters untouched.

2. You're trained to scan them. The pandemic normalized QR codes for menus, check-ins, and payments. The friction of "is this QR code legitimate?" has been socially eroded. We scan without thinking.

3. Physical placement is easy to fake. A piece of paper or a sticker placed over a legitimate QR code is all an attacker needs. You're in a parking lot, you're in a hurry, you scan what's in front of you. The legitimate code is hidden underneath.

⚠️ Critical detail: Most phone camera apps open a QR code URL with a single tap — they show a tiny preview but most people tap immediately. The window between seeing the URL and opening it is often under one second. By the time your browser loads, you're already on the attacker's page.

Where Malicious QR Codes Appear

🅿️
Parking Meters & Kiosks
Stickers placed over the official QR code direct payments to attacker-controlled accounts. FBI reported this across dozens of US cities.
📧
Phishing Emails
"Verify your account" or "unusual sign-in detected" emails replace the link with a QR code to bypass email security filters.
📦
Fake Package Notices
Printed slips left on your door or in your mailbox claim a package couldn't be delivered. "Scan to reschedule" leads to credential theft.
🍽️
Restaurant & Retail
Table cards and window posters can be swapped. Rare but documented — especially in tourist areas where footfall is high.
📄
PDF Attachments
A PDF "invoice" or "benefits statement" contains a QR code. The attachment itself is harmless — it's the QR code that carries the payload.
🎟️
Fake Giveaways & Surveys
Flyers claiming you've won a prize, or social media posts directing you to "claim your reward" via QR code.

What Happens When You Scan a Bad QR Code

The destination is almost always one of three things:

A fake login page. It looks exactly like your bank, Microsoft, Google, PayPal, or a government agency. You enter your credentials. The page either throws an error or forwards you to the real site while the attacker now has your username and password — often in real time, so they can log in before you notice.

A malware download. The page automatically downloads an app or a file disguised as a receipt, invoice, or security update. On mobile, it might request permissions to your contacts, messages, or camera.

A payment redirect. Especially at parking meters and events — the page looks like the real payment portal but sends your card details or bank transfer to an attacker-controlled account.

How to Check a QR Code Before You Open It

The only reliable way to check a QR code is to decode it and inspect the URL before your browser opens it. Here's how:

1
Use KandiCare's QR Code Safety Scanner Go to kandicare.com/tools/qr-safety-scanner/ — scan with your camera or upload an image of the QR code. The tool decodes it, reveals the hidden URL, checks it against Google's threat database, follows any redirects, and shows you where it actually goes before you tap.
2
Read the decoded URL carefully Look at the domain name. Does it match the company it claims to be? "paypa1.com" is not PayPal. "amazon-delivery-portal.net" is not Amazon. A legitimate company will always use their primary domain — not a hyphenated or misspelled variation.
3
Watch for URL shorteners Legitimate QR codes in emails from real companies rarely use bit.ly, tinyurl, or other shorteners. Shorteners hide the real destination — a red flag in a QR code context.
4
Check for urgency language after scanning "Your account will be locked in 10 minutes." "Claim your prize within 2 hours." "Verify now or lose access." Urgency is the attacker's tool — it prevents you from pausing to think. Legitimate notifications don't threaten you.
5
In public: inspect the QR code physically At a parking meter or kiosk, look for stickers placed over the original code. Official QR codes are usually printed directly into the material or embedded in a sealed protective surface. A slightly raised sticker, an edge that doesn't perfectly align, or a different surface finish are warning signs.

Good habit: Before scanning any QR code in the wild, ask — "Did I seek this out, or was it placed in front of me?" QR codes you actively look up (a restaurant's official website, a known app's page) are far lower risk than ones that appear on stickers, flyers, emails, or attachments you weren't expecting.

Signs a QR Code Is Likely Malicious

What to Do If You Scanned a Malicious QR Code

If you suspect you've scanned a bad QR code, act immediately:

  1. Do not enter any credentials on the page that opened — close it immediately
  2. If you entered a password, change it immediately from a different device on a trusted network. Enable two-factor authentication if it isn't already on
  3. If you authorized a payment, contact your bank or card provider immediately to dispute the transaction and lock your card
  4. If your phone downloaded a file, do not open it. Check your downloads folder and delete it. Consider running a mobile security scan
  5. Report the QR code — to the business it was placed at, to the FBI's IC3 (ic3.gov) for financial crimes, and to Google's Safe Browsing reporting tool

The Free Tool That Checks Before You Tap

KandiCare's QR Code Safety Scanner is a free browser tool — no account, no app, no install. It works on mobile and desktop.

You point your camera at a QR code (or upload a screenshot of one), and before your browser opens anything, the scanner:

It takes about five seconds and costs nothing. In a world where a single tap on a bad QR code can hand an attacker your banking password, five seconds is a reasonable trade.

📷

Check Any QR Code Before You Tap

Free, instant, no account required. Powered by Google Safe Browsing.

Open QR Safety Scanner →

Works on mobile and desktop · No install required

Common Questions

What is QR code phishing (quishing)?

QR code phishing — also called quishing — is an attack where a criminal encodes a malicious URL inside a QR code image. When you scan it, your phone opens the URL before you can read it. The destination is usually a fake login page, a malware download, or a payment redirect. It's effective because QR codes hide the URL inside an image, bypassing most email security tools and your own ability to spot a suspicious link.

How can you tell if a QR code is safe?

The safest approach is to decode the QR code and check the URL before your browser opens it. KandiCare's free QR Code Safety Scanner does this automatically — it reveals the hidden URL, checks it against Google's threat database, follows redirects, and checks domain age. You can also manually inspect a decoded URL by looking at the domain name carefully for misspellings or mismatches with the company it claims to be from.

Are QR codes in restaurants and stores safe?

Usually yes — but physical QR codes at businesses can be tampered with. Attackers have placed stickers over legitimate codes at parking meters, restaurants, and kiosks. Before scanning a physical QR code, look for stickers placed over the original, and use a scanner that reveals the URL before opening it. If the decoded URL doesn't match the business, don't proceed.

Why are QR codes used in phishing emails?

Because your email security software scans URLs in text but typically cannot extract and analyze URLs encoded inside image files. A phishing email that replaces its malicious link with a QR code image bypasses most corporate email gateways and antivirus tools. Attackers also know that people are conditioned to scan QR codes without thinking about what's inside them.

Is KandiCare's QR Safety Scanner really free?

Yes, entirely free. No account, no app, no sign-up required. It works in your browser on both mobile and desktop. The URL checking is powered by Google's Safe Browsing API. KandiCare offers it as a free consumer protection tool — the same way we offer the Domain Security Scan and other tools at kandicare.com/tools/.