QR code safety: spot quishing and scan safely
Updated: July 2026
A QR code is convenient but opaque: you cannot tell where it leads just by looking. Scammers exploit exactly that. Quishing - a blend of QR code and phishing - has become one of the most visible scams recently. The good news: a few simple rules keep your scanning safe, and you can design your own codes so that others trust them.
A QR code itself is harmless
A QR code stores only characters - usually a web address, sometimes text, WiFi access, or contact details. It cannot run any malware by itself. The danger is never the pattern but the destination behind it: a fake website, a harmful download, or a pre-filled payment. Once you understand that, you make the right decision in the right place - namely before you enter anything on the destination page.
What is quishing?
In quishing, scammers put a QR code into circulation that leads to a fake page. There you are meant to enter login, bank, or card details, or trigger a payment. Because a code only reveals its destination after scanning, the deception is often noticed late.
Where fake QR codes appear
Consumer-protection bodies see fake codes mainly where people pay or log in quickly:
- on parking meters and EV chargers, often as a sticker over the real code
- in fake letters that look like mail from your bank
- on posters and in emails claiming prizes or parcel notices
- as stickers over genuine codes in restaurants or shops
How to scan safely
- On fixed codes, check whether a sticker has been placed over another code.
- Read the address your phone shows before opening. Watch for unusual spellings or foreign endings.
- Be suspicious if a code unexpectedly asks for a password, payment, or personal data.
- When in doubt, do not enter sensitive data via the code; open the official website yourself instead.
- Do not use a scanner app that opens links instantly and without asking.
How to make your own QR codes trustworthy
If you use QR codes for your business, your customers should be able to trust them. Three things help:
- Say what happens. A labelled frame such as "View the menu" removes the uncertainty, because people know in advance where the code leads.
- Point at your own address. A code that visibly leads to your own domain rather than a cryptic short link looks more credible. A static FairQR code even stores the destination directly in the pattern.
- Avoid provider-dependent redirects. If your code runs through a service that can switch it off later, that is not only a subscription risk but also a trust problem. With the free subscription-trap check you can see, before printing, where a code really leads.
FairQR cannot stop strangers from sticking fake codes somewhere - no generator can. But FairQR helps you create your own codes that honestly show where they lead, and that nobody can switch off as leverage against you.
Frequently asked questions
- Can a QR code contain a virus?
- No. A QR code is just a machine-readable pattern for text or an address and cannot run a program by itself. The danger is not the code but the destination: a fraudulent website, a harmful download, or a pre-filled payment. So always check where a code leads before entering anything there.
- How do I recognise a fake QR code?
- Watch for stickers placed over another code, and for unexpected prompts (payment, login, prize). Check the address your phone shows before opening for unusual spellings. When in doubt, open the website yourself via its official address instead of via the code.
- Is scanning QR codes dangerous?
- Simply scanning is harmless as long as you check the address shown and do not immediately enter sensitive data. It only becomes a problem if you enter passwords, bank or card details on a fake destination page. Reputable organisations do not ask for that via a randomly placed QR code.