That QR Code on the Wall Might Not Take You Where You Think
You see a QR code.
At a restaurant:
“Scan to view menu.”
At a parking machine:
“Scan to pay.”
On a poster:
“Scan for offer.”
In an email:
“Scan to verify your account.”
You point your camera at it.
Your phone recognizes the code.
You tap the notification.
A website opens.
Everything looks normal.
But here’s the problem:
A QR code doesn’t tell you whether the destination is trustworthy.
It simply encodes information.
That information could lead to:
A legitimate website.
Or:
A phishing page.
Or:
A fraudulent payment page.
Or:
A malicious download.
Or:
A fake login portal.
And because you’re physically scanning something, your brain may automatically assume:
“It must be legitimate.”
That’s exactly what scammers can exploit.
What Is Quishing?
You’ve heard of:
Phishing
You may have heard of:
Smishing — SMS phishing.
And:
Vishing — voice phishing.
QR-code phishing is commonly called:
Quishing
It’s essentially phishing delivered through a QR code.
The QR code itself isn’t necessarily malicious.
The problem is:
Where it sends you.
A QR Code Is Just a Shortcut
Think of a QR code as a printed hyperlink.
Instead of:
https://example.com/payment
you see:
▦
Your phone reads the encoded information.
The QR code doesn’t magically verify:
Who created it.
Whether the website is legitimate.
Whether the payment recipient is trustworthy.
That’s your job.
The Simplest QR Scam
Imagine a legitimate poster contains:
“Scan to get 20% off.”
A scammer places another QR sticker over the original code.
You scan it.
Instead of the company’s website:
You reach a fake website.
Everything may look convincing.
Logo.
Colors.
Fonts.
“Special offer.”
But:
You’re on the attacker’s website.
QR Codes Are Perfect for Physical Scams
Traditional phishing requires:
An email.
SMS.
Social-media message.
QR scams can be placed physically.
For example:
- Parking meters
- Restaurant tables
- Posters
- Flyers
- Public notices
- Event tickets
- Vending machines
- Payment counters
- Store displays
That’s why QR scams blur the line between:
Cybercrime and physical-world fraud.
The Sticker-Over-the-Real-QR Trick
This is particularly simple.
A legitimate QR code is printed on something.
Someone places:
A fake QR sticker
over it.
The victim doesn’t necessarily notice.
They see:
“Pay here.”
They scan.
But the destination has changed.
Always Check the Destination
After scanning a QR code, don’t immediately tap:
Open
Look at the URL preview.
Ask:
Does this domain actually belong to the organization?
For example, a bank might use:
bank.example
A scammer may use:
bank-security-login.example
or an unrelated domain designed to look convincing.
The Domain Is More Important Than the Logo
A phishing page can copy:
- Logo
- Colors
- Fonts
- Images
- Layout
But the domain tells you where the page is actually hosted.
Don’t judge a website by:
How professional it looks.
Judge it partly by:
Who controls the domain you’re visiting.
The “Almost the Same” Domain
Scammers love domains that resemble legitimate ones.
For example:
paypal.compaypa1-example.compaypal-security-example.com
A quick glance can fool someone.
Don’t read only the first word.
Read the actual domain.
Subdomains Can Also Be Misleading
Consider:
login.example.com
The important registered domain is:
example.com
But something like:
example.com.attacker-site.com
is controlled by:
attacker-site.com
not:
example.com
This is why understanding domain structure matters.
HTTPS Does NOT Mean the Website Is Legitimate
This is one of the biggest misconceptions.
You scan a QR code.
The browser shows:
🔒
You think:
“It’s secure.”
HTTPS means the connection is encrypted.
It does not mean:
The website is honest.
A scam website can also use HTTPS.
So:
HTTPS protects the connection — not your judgment.
QR Scams Can Target Your Money
Payment QR codes are particularly dangerous.
Imagine you’re buying something.
The seller says:
“Scan this QR code to pay.”
You scan it.
The payment application opens.
You see:
₹10,000
You approve it.
Money leaves your account.
The problem isn’t necessarily that the QR code “hacked” your payment app.
You may have simply:
Authorized a payment to the wrong recipient.
This Is Why You Should Verify the Recipient
Before confirming a payment:
Check:
Recipient name
Amount
Account/UPI details where shown
If something doesn’t match:
Stop.
Don’t authorize the payment just because someone is standing in front of you saying:
“It’s correct.”
QR Codes Don’t Need to “Hack” Your UPI
This distinction is important.
A scammer doesn’t necessarily need to break:
UPI
or:
Your banking application.
They may simply trick you into:
Sending money yourself.
That’s social engineering.
“Scan This QR to Receive Money” Is a Major Red Flag
A common scam pattern is:
“I’ll send you money. Scan this QR to receive it.”
Be extremely cautious.
Receiving money generally does not require you to enter your UPI PIN to “accept” a payment.
If you’re asked to:
Enter UPI PIN
to receive money:
Stop and verify what’s actually happening.
UPI PIN Is for Authorizing Transactions
Your UPI PIN is sensitive.
Treat it like:
A banking password.
Never share it with:
- Buyers
- Sellers
- Delivery agents
- Customer support callers
- Strangers
- “Bank employees”
QR Codes Can Lead to Fake Login Pages
Suppose you scan:
“Microsoft account security verification.”
A login page appears.
It looks perfect.
You enter:
Password
The attacker receives them.
Now the QR code has effectively become:
A phishing delivery mechanism.
Fake Google Login Pages
A scammer could create a page that visually resembles:
You see:
Sign in
You enter your credentials.
The attacker now has:
Your username/password.
This is why you shouldn’t trust a login page simply because:
It looks familiar.
Fake Microsoft Login Pages
The same technique can target:
- Microsoft 365
- Outlook
- OneDrive
- Teams
A fake QR code could send you to a fraudulent authentication page.
Fake Banking Login Pages
This is even more dangerous.
A QR code says:
“Bank KYC verification.”
You scan it.
A fake banking page requests:
- Customer ID
- Password
- Card details
- OTP
Now the attacker has potentially collected highly sensitive information.
QR Codes Can Be Used in Email Phishing Too
You receive:
“Your account has been suspended.”
There’s a QR code inside the email.
Why not just include a clickable link?
Because security systems and users may be more suspicious of links.
A QR code can move the interaction:
From computer → phone
where the attacker hopes the victim will trust the mobile interface more.
This Is Sometimes Called QR-to-Phone Phishing
The attacker may deliberately use a QR code to move the victim from:
A monitored desktop environment
to:
A personal smartphone.
This can be useful to criminals because people often trust their phone’s camera and apps.
QR Phishing Can Target Businesses
Imagine an employee receives an email:
“Microsoft 365 security verification required.”
Instead of clicking a suspicious link, they scan the QR code.
The phone opens a fake login page.
The employee enters:
Corporate credentials.
Now the attacker may have obtained credentials for:
A business account.
QR Codes Can Also Lead to Malicious Downloads
A QR code might say:
“Download the latest security app.”
The destination offers:
APK
or:
Another executable/download.
This is particularly dangerous when the page asks you to bypass normal platform protections.
Never Install an APK Just Because a QR Code Tells You To
Especially if the QR code came from:
- Unknown person
- Random poster
- Unverified message
- Suspicious website
- Social-media account
Android allows installation from outside official app stores under certain configurations.
That doesn’t mean:
Every APK is safe.
The Fake App Scam
A QR code leads to:
“Bank Security App”
You install it.
It requests:
- Accessibility
- SMS
- Notifications
- Screen access
- Contacts
Suddenly the attacker has far more access than a simple phishing page would provide.
Never install an application merely because a QR code tells you:
“Your account requires it.”
Verify through the organization’s official website/app.
QR Codes Can Also Be Used for Malicious Website Exploits
In rare cases, a malicious website may attempt to exploit a vulnerability in the browser or operating system.
This is considerably more sophisticated than ordinary phishing.
The important defense remains:
Keep your phone and browser updated.
You Don’t Need to Assume Every QR Code Is Dangerous
QR codes are legitimate and extremely useful.
You probably use them for:
- Menus
- Tickets
- Payments
- Wi-Fi
- Product information
- Event registration
- Authentication
The goal isn’t:
“Never scan QR codes.”
It’s:
Don’t trust the destination automatically.
QR Code Scam at a Restaurant
Imagine you’re at a restaurant.
A table has:
“Scan for menu.”
The code has been replaced.
You scan.
Instead of the restaurant’s website:
Fake page.
Maybe it requests:
Phone number
Payment
App installation
Before entering anything:
Ask the restaurant staff for confirmation.
QR Code Scam at Parking Lots
A parking machine says:
“Scan to pay.”
You scan.
The payment page looks legitimate.
But the QR sticker has been replaced.
You pay:
₹2,000
instead of:
₹50.
Always verify:
Amount
Recipient
Domain
before authorizing payment.
QR Code Scam at Airports
You see:
“Free Wi-Fi — Scan Here.”
You scan.
A fake captive portal appears.
It asks for:
Password
Maybe:
Credit card information
Don’t enter sensitive information into a Wi-Fi portal unless you understand exactly who operates it.
QR Codes on Parking Tickets
Don’t assume:
Printed = legitimate.
Physical documents can be altered.
Check the surrounding context.
QR Codes in WhatsApp Messages
Someone sends:
“Scan this QR to verify your account.”
Ask:
Why?
WhatsApp has legitimate QR functionality, but scammers can use screenshots or deceptive instructions to manipulate users.
Never scan or approve authentication actions you didn’t initiate.
QR Codes and Account Linking
Some services use QR codes to:
Link devices.
That’s legitimate.
But this creates an important rule:
Never scan a login/linking QR code you didn’t intentionally request.
QR Authentication Can Be Abused Through Social Engineering
A scammer might say:
“Scan this to connect your account.”
You think:
“I’m just confirming.”
But you may actually be authorizing:
A new device/session.
Always understand what you’re approving.
A QR Code Can Hide the Destination
You can’t visually read:
A QR code.
You see:
Black squares.
Your phone translates it.
That’s convenient.
But unlike a visible URL:
You don’t know where it goes until your device decodes it.
So:
Preview first.
Don’t Scan QR Codes From Random Screens
Be especially cautious with:
- Random stickers
- Street posters
- Unverified emails
- Social-media posts
- Unexpected packages
- Unknown messages
Context matters.
QR Code Safety Rule #1
Never scan a QR code just because someone tells you to.
Ask:
What exactly will happen after I scan it?
QR Code Safety Rule #2
Preview the URL before opening it.
If the domain looks suspicious:
Don’t continue.
QR Code Safety Rule #3
Never enter passwords immediately after scanning.
First verify:
Where you are.
QR Code Safety Rule #4
Never enter your UPI PIN to receive money.
The PIN authorizes transactions.
QR Code Safety Rule #5
Don’t install APKs from QR codes unless you’ve independently verified the source.
QR Code Safety Rule #6
Check payment details before confirming.
Especially:
Recipient
Amount
QR Code Safety Rule #7
Don’t approve unexpected account-linking requests.
QR Code Safety Rule #8
Keep your phone updated.
QR Code Safety Rule #9
Use official apps instead of random QR destinations when possible.
For example, if your bank has an official app:
Open the app directly.
Don’t necessarily scan a QR code sent by a stranger claiming to represent the bank.
QR Codes vs Normal Links
A normal link:
lets you inspect the text.
A QR code:
▦
hides that destination until decoded.
That’s why QR phishing can be psychologically effective.
The “Looks Official” Trap
Scammers may include:
- Government logos
- Bank logos
- Police logos
- Company branding
- Blue verification-style graphics
- Official-looking language
None of that proves authenticity.
Anyone can copy a logo.
The Urgency Trap
QR scams often say:
“Scan within 10 minutes.”
“Your account expires today.”
“Payment required immediately.”
“KYC deadline today.”
Urgency is designed to reduce your thinking time.
When a QR code comes with:
Fear + urgency + payment
slow down.
The Curiosity Trap
Other scams use:
“You have won ₹50,000.”
“See your private photos.”
“Secret video.”
“Celebrity leaked video.”
Curiosity can be just as powerful as fear.
The Authority Trap
The QR code says:
Police verification
or:
Bank security
or:
Government KYC
The goal is to make you obey without questioning.
Remember:
Authority branding isn’t proof of authenticity.
What If You Scanned a Suspicious QR Code?
First:
Don’t panic.
Scanning a QR code doesn’t automatically mean you’ve been hacked.
What happens next matters.
If It Only Opened a Website
If you scanned it and immediately closed the page:
Risk may be limited.
Still:
- Don’t enter credentials.
- Don’t download anything.
- Don’t approve permissions.
- Don’t make payments.
If You Entered Your Password
Immediately:
Change the password
from a trusted device.
Then:
Sign out other sessions.
Then:
Enable strong MFA/passkey.
If you reused that password elsewhere:
Change it there too.
If You Entered Banking Information
Contact your bank immediately through an official channel.
Tell them:
You may have exposed financial credentials to a fraudulent website.
Monitor your account closely.
If You Entered a UPI PIN
Treat it seriously.
If you believe you were manipulated into authorizing an unauthorized transaction or exposed your credentials:
Contact your bank immediately.
If money has actually been lost in India, report financial cyber fraud through the official cybercrime reporting channels as quickly as possible.
If You Installed an APK
Stop.
Don’t continue using the suspicious app.
If you entered credentials through it:
Change them from a known-clean device.
If you gave the app powerful permissions:
Review and revoke them.
If compromise is suspected:
Consider professional incident-response assistance or a device reset after preserving necessary evidence.
If Money Was Sent
Time matters.
Contact:
Your bank/payment provider
immediately.
In India, you can also report cyber financial fraud through:
1930
and the official cybercrime reporting portal.
Don’t wait until tomorrow.
Save the QR Code Evidence
If you encounter a scam:
Take screenshots of:
- QR code
- Poster/sticker
- URL
- Website
- Payment screen
- Messages
- Phone numbers
- Account details
- Transaction receipt
This evidence may help when reporting.
Report the Physical QR Scam
If someone replaced a QR code at:
Restaurant
Parking machine
Store
ATM area
tell the business/property operator immediately.
They may need to:
Remove the fraudulent sticker.
Warn customers.
Preserve CCTV footage.
Notify authorities.
Don’t Peel Off the Sticker Immediately If It May Be Evidence
If you discover a malicious QR sticker on a public payment point, photograph it first.
Preserve:
Location
Time
QR code
Surrounding signage
Then notify the responsible organization/security team.
QR Code Security Checklist
Before scanning
- Do I know who placed it?
- Is the QR code physically attached to the expected location?
- Does it appear tampered with?
- Is there a sticker covering another QR code?
After scanning
- Check the URL
- Verify the domain
- Don’t enter credentials blindly
- Don’t install unknown apps
- Don’t approve unexpected permissions
Before paying
- Verify recipient
- Verify amount
- Confirm the payment request makes sense
The 30-Second QR Safety Test
Before you scan:
STOP
Who gave you the QR?
LOOK
Does it appear altered?
SCAN
Let your phone preview the destination.
READ
Check the domain.
VERIFY
Does it actually belong to the organization?
THEN ACT
Only continue if everything makes sense.
The Biggest QR Code Myths
❌ “QR codes are secure because they’re encrypted.”
A QR code is an encoding format, not a security guarantee.
❌ “If my camera recognizes it, it’s safe.”
No.
❌ “HTTPS means the QR website is legitimate.”
No.
❌ “Scanning alone means my phone is hacked.”
Usually not.
❌ “QR payments automatically protect me from fraud.”
No. You still need to verify the payment.
❌ “A QR code printed by a business must be genuine.”
Physical QR codes can be replaced or tampered with.
❌ “QR codes can’t contain malicious links.”
They can encode arbitrary URLs or other data.
Final Thoughts
QR codes have made everyday life incredibly convenient.
You can:
Open a menu.
Pay a bill.
Join Wi-Fi.
Buy a ticket.
Open an app.
Link a device.
with a single scan.
But that convenience removes one important step:
You don’t immediately see the destination.
That’s what makes QR codes attractive to scammers.
The QR code itself isn’t necessarily the weapon.
The destination is.
A fake QR code can send you to:
A phishing page.
A fake banking site.
A fraudulent payment request.
A malicious download.
A fake KYC form.
A fake account-login page.
And the most dangerous QR scams don’t look like hacking.
They look like:
A normal payment.
A normal login.
A normal verification.
A normal poster.
That’s why your best defense isn’t fear.
It’s one simple habit:
Don’t scan and trust.
Scan, inspect, verify, then act.
Because when you point your camera at a QR code, you’re not just scanning a picture.
You’re potentially opening a door.
Make sure you know where that door leads.
Discover more from Spyboy blog
Subscribe to get the latest posts sent to your email.
