Split QR code surrounded by digital circuits and cybersecurity warning symbols

You Scan a QR Code and Your Phone Opens the Door — How QR Code Scams and Quishing Work

spyboy's avatarPosted by

That QR Code on the Wall Might Not Take You Where You Think

You see a QR code.

At a restaurant:

“Scan to view menu.”

At a parking machine:

“Scan to pay.”

On a poster:

“Scan for offer.”

In an email:

“Scan to verify your account.”

You point your camera at it.

Your phone recognizes the code.

You tap the notification.

A website opens.

Everything looks normal.

But here’s the problem:

A QR code doesn’t tell you whether the destination is trustworthy.

It simply encodes information.

That information could lead to:

A legitimate website.

Or:

A phishing page.

Or:

A fraudulent payment page.

Or:

A malicious download.

Or:

A fake login portal.

And because you’re physically scanning something, your brain may automatically assume:

“It must be legitimate.”

That’s exactly what scammers can exploit.


What Is Quishing?

You’ve heard of:

Phishing

You may have heard of:

Smishing — SMS phishing.

And:

Vishing — voice phishing.

QR-code phishing is commonly called:

Quishing

It’s essentially phishing delivered through a QR code.

The QR code itself isn’t necessarily malicious.

The problem is:

Where it sends you.


A QR Code Is Just a Shortcut

Think of a QR code as a printed hyperlink.

Instead of:

https://example.com/payment

you see:

Your phone reads the encoded information.

The QR code doesn’t magically verify:

Who created it.

Whether the website is legitimate.

Whether the payment recipient is trustworthy.

That’s your job.


The Simplest QR Scam

Imagine a legitimate poster contains:

“Scan to get 20% off.”

A scammer places another QR sticker over the original code.

You scan it.

Instead of the company’s website:

You reach a fake website.

Everything may look convincing.

Logo.

Colors.

Fonts.

“Special offer.”

But:

You’re on the attacker’s website.


QR Codes Are Perfect for Physical Scams

Traditional phishing requires:

An email.

SMS.

Social-media message.

QR scams can be placed physically.

For example:

  • Parking meters
  • Restaurant tables
  • Posters
  • Flyers
  • Public notices
  • Event tickets
  • Vending machines
  • Payment counters
  • Store displays

That’s why QR scams blur the line between:

Cybercrime and physical-world fraud.


The Sticker-Over-the-Real-QR Trick

This is particularly simple.

A legitimate QR code is printed on something.

Someone places:

A fake QR sticker

over it.

The victim doesn’t necessarily notice.

They see:

“Pay here.”

They scan.

But the destination has changed.


Always Check the Destination

After scanning a QR code, don’t immediately tap:

Open

Look at the URL preview.

Ask:

Does this domain actually belong to the organization?

For example, a bank might use:

bank.example

A scammer may use:

bank-security-login.example

or an unrelated domain designed to look convincing.


The Domain Is More Important Than the Logo

A phishing page can copy:

  • Logo
  • Colors
  • Fonts
  • Images
  • Layout

But the domain tells you where the page is actually hosted.

Don’t judge a website by:

How professional it looks.

Judge it partly by:

Who controls the domain you’re visiting.


The “Almost the Same” Domain

Scammers love domains that resemble legitimate ones.

For example:

paypal.com
paypa1-example.com
paypal-security-example.com

A quick glance can fool someone.

Don’t read only the first word.

Read the actual domain.


Subdomains Can Also Be Misleading

Consider:

login.example.com

The important registered domain is:

example.com

But something like:

example.com.attacker-site.com

is controlled by:

attacker-site.com

not:

example.com

This is why understanding domain structure matters.


HTTPS Does NOT Mean the Website Is Legitimate

This is one of the biggest misconceptions.

You scan a QR code.

The browser shows:

🔒

You think:

“It’s secure.”

HTTPS means the connection is encrypted.

It does not mean:

The website is honest.

A scam website can also use HTTPS.

So:

HTTPS protects the connection — not your judgment.


QR Scams Can Target Your Money

Payment QR codes are particularly dangerous.

Imagine you’re buying something.

The seller says:

“Scan this QR code to pay.”

You scan it.

The payment application opens.

You see:

₹10,000

You approve it.

Money leaves your account.

The problem isn’t necessarily that the QR code “hacked” your payment app.

You may have simply:

Authorized a payment to the wrong recipient.


This Is Why You Should Verify the Recipient

Before confirming a payment:

Check:

Recipient name

Amount

Account/UPI details where shown

If something doesn’t match:

Stop.

Don’t authorize the payment just because someone is standing in front of you saying:

“It’s correct.”


QR Codes Don’t Need to “Hack” Your UPI

This distinction is important.

A scammer doesn’t necessarily need to break:

UPI

or:

Your banking application.

They may simply trick you into:

Sending money yourself.

That’s social engineering.


“Scan This QR to Receive Money” Is a Major Red Flag

A common scam pattern is:

“I’ll send you money. Scan this QR to receive it.”

Be extremely cautious.

Receiving money generally does not require you to enter your UPI PIN to “accept” a payment.

If you’re asked to:

Enter UPI PIN

to receive money:

Stop and verify what’s actually happening.


UPI PIN Is for Authorizing Transactions

Your UPI PIN is sensitive.

Treat it like:

A banking password.

Never share it with:

  • Buyers
  • Sellers
  • Delivery agents
  • Customer support callers
  • Strangers
  • “Bank employees”

QR Codes Can Lead to Fake Login Pages

Suppose you scan:

“Microsoft account security verification.”

A login page appears.

It looks perfect.

You enter:

Email

Password

The attacker receives them.

Now the QR code has effectively become:

A phishing delivery mechanism.


Fake Google Login Pages

A scammer could create a page that visually resembles:

Google

You see:

Sign in

You enter your credentials.

The attacker now has:

Your username/password.

This is why you shouldn’t trust a login page simply because:

It looks familiar.


Fake Microsoft Login Pages

The same technique can target:

  • Microsoft 365
  • Outlook
  • OneDrive
  • Teams

A fake QR code could send you to a fraudulent authentication page.


Fake Banking Login Pages

This is even more dangerous.

A QR code says:

“Bank KYC verification.”

You scan it.

A fake banking page requests:

  • Customer ID
  • Password
  • Card details
  • OTP

Now the attacker has potentially collected highly sensitive information.


QR Codes Can Be Used in Email Phishing Too

You receive:

“Your account has been suspended.”

There’s a QR code inside the email.

Why not just include a clickable link?

Because security systems and users may be more suspicious of links.

A QR code can move the interaction:

From computer → phone

where the attacker hopes the victim will trust the mobile interface more.


This Is Sometimes Called QR-to-Phone Phishing

The attacker may deliberately use a QR code to move the victim from:

A monitored desktop environment

to:

A personal smartphone.

This can be useful to criminals because people often trust their phone’s camera and apps.


QR Phishing Can Target Businesses

Imagine an employee receives an email:

“Microsoft 365 security verification required.”

Instead of clicking a suspicious link, they scan the QR code.

The phone opens a fake login page.

The employee enters:

Corporate credentials.

Now the attacker may have obtained credentials for:

A business account.


QR Codes Can Also Lead to Malicious Downloads

A QR code might say:

“Download the latest security app.”

The destination offers:

APK

or:

Another executable/download.

This is particularly dangerous when the page asks you to bypass normal platform protections.


Never Install an APK Just Because a QR Code Tells You To

Especially if the QR code came from:

  • Unknown person
  • Random poster
  • Unverified message
  • Suspicious website
  • Social-media account

Android allows installation from outside official app stores under certain configurations.

That doesn’t mean:

Every APK is safe.


The Fake App Scam

A QR code leads to:

“Bank Security App”

You install it.

It requests:

  • Accessibility
  • SMS
  • Notifications
  • Screen access
  • Contacts

Suddenly the attacker has far more access than a simple phishing page would provide.

Never install an application merely because a QR code tells you:

“Your account requires it.”

Verify through the organization’s official website/app.


QR Codes Can Also Be Used for Malicious Website Exploits

In rare cases, a malicious website may attempt to exploit a vulnerability in the browser or operating system.

This is considerably more sophisticated than ordinary phishing.

The important defense remains:

Keep your phone and browser updated.


You Don’t Need to Assume Every QR Code Is Dangerous

QR codes are legitimate and extremely useful.

You probably use them for:

  • Menus
  • Tickets
  • Payments
  • Wi-Fi
  • Product information
  • Event registration
  • Authentication

The goal isn’t:

“Never scan QR codes.”

It’s:

Don’t trust the destination automatically.


QR Code Scam at a Restaurant

Imagine you’re at a restaurant.

A table has:

“Scan for menu.”

The code has been replaced.

You scan.

Instead of the restaurant’s website:

Fake page.

Maybe it requests:

Phone number

Email

Payment

App installation

Before entering anything:

Ask the restaurant staff for confirmation.


QR Code Scam at Parking Lots

A parking machine says:

“Scan to pay.”

You scan.

The payment page looks legitimate.

But the QR sticker has been replaced.

You pay:

₹2,000

instead of:

₹50.

Always verify:

Amount

Recipient

Domain

before authorizing payment.


QR Code Scam at Airports

You see:

“Free Wi-Fi — Scan Here.”

You scan.

A fake captive portal appears.

It asks for:

Email

Password

Maybe:

Credit card information

Don’t enter sensitive information into a Wi-Fi portal unless you understand exactly who operates it.


QR Codes on Parking Tickets

Don’t assume:

Printed = legitimate.

Physical documents can be altered.

Check the surrounding context.


QR Codes in WhatsApp Messages

Someone sends:

“Scan this QR to verify your account.”

Ask:

Why?

WhatsApp has legitimate QR functionality, but scammers can use screenshots or deceptive instructions to manipulate users.

Never scan or approve authentication actions you didn’t initiate.


QR Codes and Account Linking

Some services use QR codes to:

Link devices.

That’s legitimate.

But this creates an important rule:

Never scan a login/linking QR code you didn’t intentionally request.


QR Authentication Can Be Abused Through Social Engineering

A scammer might say:

“Scan this to connect your account.”

You think:

“I’m just confirming.”

But you may actually be authorizing:

A new device/session.

Always understand what you’re approving.


A QR Code Can Hide the Destination

You can’t visually read:

A QR code.

You see:

Black squares.

Your phone translates it.

That’s convenient.

But unlike a visible URL:

You don’t know where it goes until your device decodes it.

So:

Preview first.


Don’t Scan QR Codes From Random Screens

Be especially cautious with:

  • Random stickers
  • Street posters
  • Unverified emails
  • Social-media posts
  • Unexpected packages
  • Unknown messages

Context matters.


QR Code Safety Rule #1

Never scan a QR code just because someone tells you to.

Ask:

What exactly will happen after I scan it?


QR Code Safety Rule #2

Preview the URL before opening it.

If the domain looks suspicious:

Don’t continue.


QR Code Safety Rule #3

Never enter passwords immediately after scanning.

First verify:

Where you are.


QR Code Safety Rule #4

Never enter your UPI PIN to receive money.

The PIN authorizes transactions.


QR Code Safety Rule #5

Don’t install APKs from QR codes unless you’ve independently verified the source.


QR Code Safety Rule #6

Check payment details before confirming.

Especially:

Recipient

Amount


QR Code Safety Rule #7

Don’t approve unexpected account-linking requests.


QR Code Safety Rule #8

Keep your phone updated.


QR Code Safety Rule #9

Use official apps instead of random QR destinations when possible.

For example, if your bank has an official app:

Open the app directly.

Don’t necessarily scan a QR code sent by a stranger claiming to represent the bank.


QR Codes vs Normal Links

A normal link:

lets you inspect the text.

A QR code:

hides that destination until decoded.

That’s why QR phishing can be psychologically effective.


The “Looks Official” Trap

Scammers may include:

  • Government logos
  • Bank logos
  • Police logos
  • Company branding
  • Blue verification-style graphics
  • Official-looking language

None of that proves authenticity.

Anyone can copy a logo.


The Urgency Trap

QR scams often say:

“Scan within 10 minutes.”

“Your account expires today.”

“Payment required immediately.”

“KYC deadline today.”

Urgency is designed to reduce your thinking time.

When a QR code comes with:

Fear + urgency + payment

slow down.


The Curiosity Trap

Other scams use:

“You have won ₹50,000.”

“See your private photos.”

“Secret video.”

“Celebrity leaked video.”

Curiosity can be just as powerful as fear.


The Authority Trap

The QR code says:

Police verification

or:

Bank security

or:

Government KYC

The goal is to make you obey without questioning.

Remember:

Authority branding isn’t proof of authenticity.


What If You Scanned a Suspicious QR Code?

First:

Don’t panic.

Scanning a QR code doesn’t automatically mean you’ve been hacked.

What happens next matters.


If It Only Opened a Website

If you scanned it and immediately closed the page:

Risk may be limited.

Still:

  • Don’t enter credentials.
  • Don’t download anything.
  • Don’t approve permissions.
  • Don’t make payments.

If You Entered Your Password

Immediately:

Change the password

from a trusted device.

Then:

Sign out other sessions.

Then:

Enable strong MFA/passkey.

If you reused that password elsewhere:

Change it there too.


If You Entered Banking Information

Contact your bank immediately through an official channel.

Tell them:

You may have exposed financial credentials to a fraudulent website.

Monitor your account closely.


If You Entered a UPI PIN

Treat it seriously.

If you believe you were manipulated into authorizing an unauthorized transaction or exposed your credentials:

Contact your bank immediately.

If money has actually been lost in India, report financial cyber fraud through the official cybercrime reporting channels as quickly as possible.


If You Installed an APK

Stop.

Don’t continue using the suspicious app.

If you entered credentials through it:

Change them from a known-clean device.

If you gave the app powerful permissions:

Review and revoke them.

If compromise is suspected:

Consider professional incident-response assistance or a device reset after preserving necessary evidence.


If Money Was Sent

Time matters.

Contact:

Your bank/payment provider

immediately.

In India, you can also report cyber financial fraud through:

1930

and the official cybercrime reporting portal.

Don’t wait until tomorrow.


Save the QR Code Evidence

If you encounter a scam:

Take screenshots of:

  • QR code
  • Poster/sticker
  • URL
  • Website
  • Payment screen
  • Messages
  • Phone numbers
  • Account details
  • Transaction receipt

This evidence may help when reporting.


Report the Physical QR Scam

If someone replaced a QR code at:

Restaurant

Parking machine

Store

ATM area

tell the business/property operator immediately.

They may need to:

Remove the fraudulent sticker.

Warn customers.

Preserve CCTV footage.

Notify authorities.


Don’t Peel Off the Sticker Immediately If It May Be Evidence

If you discover a malicious QR sticker on a public payment point, photograph it first.

Preserve:

Location

Time

QR code

Surrounding signage

Then notify the responsible organization/security team.


QR Code Security Checklist

Before scanning

  • Do I know who placed it?
  • Is the QR code physically attached to the expected location?
  • Does it appear tampered with?
  • Is there a sticker covering another QR code?

After scanning

  • Check the URL
  • Verify the domain
  • Don’t enter credentials blindly
  • Don’t install unknown apps
  • Don’t approve unexpected permissions

Before paying

  • Verify recipient
  • Verify amount
  • Confirm the payment request makes sense

The 30-Second QR Safety Test

Before you scan:

STOP

Who gave you the QR?

LOOK

Does it appear altered?

SCAN

Let your phone preview the destination.

READ

Check the domain.

VERIFY

Does it actually belong to the organization?

THEN ACT

Only continue if everything makes sense.


The Biggest QR Code Myths

❌ “QR codes are secure because they’re encrypted.”

A QR code is an encoding format, not a security guarantee.

❌ “If my camera recognizes it, it’s safe.”

No.

❌ “HTTPS means the QR website is legitimate.”

No.

❌ “Scanning alone means my phone is hacked.”

Usually not.

❌ “QR payments automatically protect me from fraud.”

No. You still need to verify the payment.

❌ “A QR code printed by a business must be genuine.”

Physical QR codes can be replaced or tampered with.

❌ “QR codes can’t contain malicious links.”

They can encode arbitrary URLs or other data.


Final Thoughts

QR codes have made everyday life incredibly convenient.

You can:

Open a menu.

Pay a bill.

Join Wi-Fi.

Buy a ticket.

Open an app.

Link a device.

with a single scan.

But that convenience removes one important step:

You don’t immediately see the destination.

That’s what makes QR codes attractive to scammers.

The QR code itself isn’t necessarily the weapon.

The destination is.

A fake QR code can send you to:

A phishing page.

A fake banking site.

A fraudulent payment request.

A malicious download.

A fake KYC form.

A fake account-login page.

And the most dangerous QR scams don’t look like hacking.

They look like:

A normal payment.

A normal login.

A normal verification.

A normal poster.

That’s why your best defense isn’t fear.

It’s one simple habit:

Don’t scan and trust.

Scan, inspect, verify, then act.

Because when you point your camera at a QR code, you’re not just scanning a picture.

You’re potentially opening a door.

Make sure you know where that door leads.


Discover more from Spyboy blog

Subscribe to get the latest posts sent to your email.

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.