SecurityQR code basics

Are QR Codes Safe? Quishing, Sticker Scams and How to Protect Yours

A QR code is just text — it cannot infect anything. The risk lives entirely in where it sends you, and in whether somebody has stuck a different code over yours.

The Qrelux Team6 min read

Every so often a story goes round warning people to stop scanning QR codes. The advice is usually too broad to act on, and the underlying risk gets misdescribed — which leaves both consumers and the businesses printing codes unsure what they should actually do.

The short version: the code itself is harmless. The destination might not be, and the code on the wall might not be the one you put there.

A QR code cannot contain a virus

This is the most common misconception, and clearing it up makes everything else easier to reason about. A QR code stores text. That is the entire capability of the format. It cannot execute code, install anything, or access your phone — see how QR codes work for what is physically in the pattern.

When you scan one, your phone reads a string and reacts to what it recognises. A string starting https:// gets offered as a link. One starting WIFI: gets offered as a network. Nothing happens without that offer, and nothing happens until you accept it.

So the honest framing is: a QR code is exactly as dangerous as a link somebody hands you on a piece of paper. The danger is the destination, plus the fact that you cannot read a QR code with your eyes to check it first.

What quishing is

"Quishing" is phishing delivered by QR code. The goal is the same as any phishing attempt — get you onto a convincing fake page and have you type in a password or card details — but the delivery has two advantages for the attacker.

It defeats the visual check. You cannot glance at a pattern of squares and notice the domain is wrong. All the usual advice about hovering over links to inspect them stops applying.

It moves you to a less protected device. A QR code in a phishing email pushes you from a corporate laptop, with its filtering and managed browser, onto a personal phone that has none of it. That is often the actual point of using a code rather than a link.

The scams that actually happen

A sticker over a real code

The most common physical attack, and the simplest: print a code, stick it over the legitimate one, walk away. Parking meters and EV chargers have been repeat targets because people expect to pay at them, so a payment page raises no suspicion. Restaurant tables, event posters and charity collection points get hit for the same reason.

Fake payment requests

A code that opens a payment page for a plausible amount — a parking fee, a delivery surcharge, a small fine. The amounts are deliberately small enough not to warrant a phone call to check.

Codes in unsolicited post and email

Letters claiming to be from a bank, a tax office or a delivery company, with a code to "verify your details". The physical letter lends credibility that an email would not have.

Prize draws and surveys

Codes on flyers or windscreens offering a reward for a short survey, which ends by asking for card details to "cover postage".

How to scan safely

Not "stop scanning codes" — that advice is unrealistic and does not match the actual risk. These five habits cover almost everything:

  1. Read the URL preview before opening. Both iPhone and Android show the address as a banner rather than opening it immediately. Check the domain — specifically the part just before the first single slash, which is the only part that identifies who you are talking to.
  2. Look at the physical code. A sticker with an edge you can feel, a code slightly crooked against its printed background, or one whose colour does not match the rest of the poster is worth being suspicious of.
  3. Never enter passwords or card details on a page you reached by scanning something in public. If a scan leads to a login, close it and navigate to the site yourself.
  4. Be sceptical of codes on unsolicited post. Contact the organisation using a number you looked up independently, not one printed on the letter.
  5. Keep your phone updated. The scan is safe; the browser session afterwards is ordinary web browsing, and normal patching applies.

Note what is not on that list: installing a "secure QR scanner" app. The built-in camera on both platforms already previews the URL, and third-party scanner apps are themselves a common source of unwanted advertising and data collection.

Protecting codes you print

If you are the business whose code is on the table, a sticker attack is a problem for you as much as for the customer — you lose the scan, they lose money, and your brand is attached to the experience.

  • Make the code physically hard to cover. Print it directly onto the material rather than applying a label, laminate it, or place it under the surface of a menu or table where a sticker will not sit flat.
  • Design the code into the artwork. A code sitting inside a designed frame with matched brand colours is much harder to overlay convincingly than a plain black square on white.
  • Check placements regularly. Public codes in unattended locations should be part of somebody's routine inspection — a fortnightly walk-past catches most tampering.
  • Tell staff what to look for. The people wiping the tables are the ones who will notice a sticker first, if they know it is a thing that happens.
  • Never ask for payment or login on a page reached from a public code. If your own flow trains customers to do this, you have made every sticker attack against you easier.

Why your own domain matters here

A dynamic code encodes a short link, and the domain of that link is what a cautious customer sees in the preview banner. If it is a generic shortener shared by thousands of unrelated businesses, the preview tells them nothing and gives an attacker something easy to imitate.

A branded short domain — your own name in the link — turns the preview into a genuine check. The customer sees something recognisable, and a fake code pointing somewhere else becomes visibly different rather than indistinguishable. Qrelux supports custom domains on the plans that include them; the FAQ covers how that works.

There is a second benefit specific to dynamic codes: if a destination is ever compromised or a campaign has to be pulled, you can repoint every printed code at a safe page immediately, without recalling anything.

If you think you scanned something malicious

  1. Close the page. If you did nothing but look at it, you are almost certainly fine — visiting a page is not the same as being compromised.
  2. If you entered a password, change it now, and anywhere else you reused it.
  3. If you entered card details, contact your bank, and say the details were entered on a fraudulent page.
  4. If you installed anything the page prompted you to, remove it and run a check on the device.
  5. Report the physical code. Tell the venue or operator — a sticker left in place keeps working on the next person.

QR codes are not uniquely dangerous, and treating them as such mostly stops people using a genuinely convenient thing. They are, however, unreadable to humans, and that single property is what every one of these scams exploits. Preview the URL, and most of the risk evaporates.

Dynamic codes let you repoint a compromised or outdated destination instantly, without reprinting or recalling anything.

Start a free trial

Frequently asked questions

Are QR codes safe to scan?

The code itself is safe — it stores text and cannot execute anything or install software. The risk is entirely the destination, exactly as with any link. Because you cannot read a QR code by eye, the key habit is checking the URL preview your phone shows before opening it.

Can a QR code hack your phone?

Not by itself. Scanning displays a string and offers an action; nothing runs without you accepting it. Harm requires you to then visit a malicious page and do something on it, such as entering credentials or installing an app it prompts you to install.

What is quishing?

Phishing delivered by QR code. It works because you cannot visually inspect a code the way you can hover over a link, and because a code in an email moves the victim from a filtered work laptop to an unmanaged personal phone. The end goal is the same: a convincing fake page that harvests passwords or card details.

How do I know if a QR code has been tampered with?

Look for a sticker rather than printing — raised or peeling edges, a code slightly crooked against its background, colours that do not match the surrounding artwork, or a code covering part of the original design. Parking meters, EV chargers and restaurant tables are the most frequently targeted places.

How can I protect the QR codes my business prints?

Print codes directly onto the material rather than applying labels, laminate or recess them so a sticker will not sit flat, design them into branded artwork that is hard to imitate, inspect public placements regularly, and use your own branded short domain so customers can recognise a legitimate link in the preview.

Stop guessing what your printed marketing does

Dynamic QR codes let you change the destination after printing and show you every scan—when, where, and on what device.

Start a 14-day free trial

No credit card required

Keep reading