What Is QR Code Phishing?
A QR code is just a machine-readable image that encodes a URL. When you point your phone camera at one, the camera decodes the URL and opens it — usually with a single tap and no preview. That last part is the problem.
With a normal link in an email, you can hover over it and read the destination before clicking. Your email security software can scan it. You can spot "amaz0n.com" instead of "amazon.com." With a QR code, the URL is invisible to both you and your security tools. The only thing you see is a grid of black-and-white squares.
Attackers figured this out. QR code phishing — nicknamed "quishing" — has become one of the fastest-growing social engineering attacks. Microsoft's Digital Crimes Unit reported a 587% spike in QR phishing campaigns in a single year. The FBI issued a public warning after a wave of fake parking meter QR code stickers appeared across major US cities.
Why QR Codes Are So Dangerous Right Now
Three things have converged to make quishing effective:
1. Your security software is blind to it. Corporate email gateways, Microsoft Defender, and consumer antivirus tools analyze URLs in email bodies. They don't extract and analyze URLs encoded inside image files. A phishing email that replaces its malicious link with a QR code image sails through many filters untouched.
2. You're trained to scan them. The pandemic normalized QR codes for menus, check-ins, and payments. The friction of "is this QR code legitimate?" has been socially eroded. We scan without thinking.
3. Physical placement is easy to fake. A piece of paper or a sticker placed over a legitimate QR code is all an attacker needs. You're in a parking lot, you're in a hurry, you scan what's in front of you. The legitimate code is hidden underneath.
⚠️ Critical detail: Most phone camera apps open a QR code URL with a single tap — they show a tiny preview but most people tap immediately. The window between seeing the URL and opening it is often under one second. By the time your browser loads, you're already on the attacker's page.
Where Malicious QR Codes Appear
What Happens When You Scan a Bad QR Code
The destination is almost always one of three things:
A fake login page. It looks exactly like your bank, Microsoft, Google, PayPal, or a government agency. You enter your credentials. The page either throws an error or forwards you to the real site while the attacker now has your username and password — often in real time, so they can log in before you notice.
A malware download. The page automatically downloads an app or a file disguised as a receipt, invoice, or security update. On mobile, it might request permissions to your contacts, messages, or camera.
A payment redirect. Especially at parking meters and events — the page looks like the real payment portal but sends your card details or bank transfer to an attacker-controlled account.
How to Check a QR Code Before You Open It
The only reliable way to check a QR code is to decode it and inspect the URL before your browser opens it. Here's how:
Good habit: Before scanning any QR code in the wild, ask — "Did I seek this out, or was it placed in front of me?" QR codes you actively look up (a restaurant's official website, a known app's page) are far lower risk than ones that appear on stickers, flyers, emails, or attachments you weren't expecting.
Signs a QR Code Is Likely Malicious
- It arrived in an unsolicited email — especially one claiming to be from a bank, government, delivery service, or major tech company
- The domain in the decoded URL doesn't match the supposed sender
- It redirects through multiple domains before landing on the final page
- The destination domain was registered recently (days or weeks old) — a strong indicator of a throwaway phishing domain
- It asks for login credentials — especially for accounts you didn't initiate a login for
- It's a sticker placed over something else — physically inspect it
- It came in a PDF, image, or document instead of a direct link
What to Do If You Scanned a Malicious QR Code
If you suspect you've scanned a bad QR code, act immediately:
- Do not enter any credentials on the page that opened — close it immediately
- If you entered a password, change it immediately from a different device on a trusted network. Enable two-factor authentication if it isn't already on
- If you authorized a payment, contact your bank or card provider immediately to dispute the transaction and lock your card
- If your phone downloaded a file, do not open it. Check your downloads folder and delete it. Consider running a mobile security scan
- Report the QR code — to the business it was placed at, to the FBI's IC3 (ic3.gov) for financial crimes, and to Google's Safe Browsing reporting tool
The Free Tool That Checks Before You Tap
KandiCare's QR Code Safety Scanner is a free browser tool — no account, no app, no install. It works on mobile and desktop.
You point your camera at a QR code (or upload a screenshot of one), and before your browser opens anything, the scanner:
- Decodes the hidden URL from the image
- Checks it against Google's Safe Browsing threat database (10,000+ known phishing and malware domains)
- Follows the full redirect chain to show you the real final destination
- Checks the domain's age (newly registered domains are a major red flag)
- Gives you a plain-English risk score and verdict
It takes about five seconds and costs nothing. In a world where a single tap on a bad QR code can hand an attacker your banking password, five seconds is a reasonable trade.
Check Any QR Code Before You Tap
Free, instant, no account required. Powered by Google Safe Browsing.
Open QR Safety Scanner →Works on mobile and desktop · No install required
Common Questions
What is QR code phishing (quishing)?
QR code phishing — also called quishing — is an attack where a criminal encodes a malicious URL inside a QR code image. When you scan it, your phone opens the URL before you can read it. The destination is usually a fake login page, a malware download, or a payment redirect. It's effective because QR codes hide the URL inside an image, bypassing most email security tools and your own ability to spot a suspicious link.
How can you tell if a QR code is safe?
The safest approach is to decode the QR code and check the URL before your browser opens it. KandiCare's free QR Code Safety Scanner does this automatically — it reveals the hidden URL, checks it against Google's threat database, follows redirects, and checks domain age. You can also manually inspect a decoded URL by looking at the domain name carefully for misspellings or mismatches with the company it claims to be from.
Are QR codes in restaurants and stores safe?
Usually yes — but physical QR codes at businesses can be tampered with. Attackers have placed stickers over legitimate codes at parking meters, restaurants, and kiosks. Before scanning a physical QR code, look for stickers placed over the original, and use a scanner that reveals the URL before opening it. If the decoded URL doesn't match the business, don't proceed.
Why are QR codes used in phishing emails?
Because your email security software scans URLs in text but typically cannot extract and analyze URLs encoded inside image files. A phishing email that replaces its malicious link with a QR code image bypasses most corporate email gateways and antivirus tools. Attackers also know that people are conditioned to scan QR codes without thinking about what's inside them.
Is KandiCare's QR Safety Scanner really free?
Yes, entirely free. No account, no app, no sign-up required. It works in your browser on both mobile and desktop. The URL checking is powered by Google's Safe Browsing API. KandiCare offers it as a free consumer protection tool — the same way we offer the Domain Security Scan and other tools at kandicare.com/tools/.