A QR code cannot infect your phone
Let us clear up the most widespread fear first. A QR code is not a program, contains no virus and does not run. It is an image, and that image contains text — usually a web address. Scanning “launches” nothing: the phone reads the text and offers you an action, which you confirm or not.
In other words, a QR code is no more dangerous than a link written on a scrap of paper. What can be dangerous is where that link leads — exactly as with a link received by email or text message.
The real risk: “quishing”
The word blends QR and phishing. The principle is identical to a fraudulent email: get you onto a page that imitates a legitimate site, so you enter a password, a card number or personal information.
The QR code gives the attacker one advantage: it hides the address. In an email, a suspicious link can be spotted by hovering over it. In a square of black-and-white modules, no human can read anything before scanning. Verification therefore comes later — when the phone displays the address.
The most frequent scams
The observed scenarios look very much alike, and all rely on a context where paying quickly seems normal:
- The fake parking meter: a sticker on the machine invites you to “pay for parking online”. The page asks for a bank card, which goes straight to the fraudster.
- The fake fine: a slip tucked under the windscreen wiper, with a QR code to immediately settle a penalty that does not exist.
- The fake delivery notice: a card in the letterbox announces a parcel on hold and offers to pay a few euros of “customs fees” — the amount is small so as not to raise suspicion.
- The fake menu or fake terminal: a QR code placed on a table or a charging point, leading to a counterfeit payment page.
- The fake WiFi: a QR code displayed in a public place connects you to a network controlled by a third party, who can then observe part of the unencrypted traffic.
- The QR code inside an email: sent as an attachment or an image to bypass anti-phishing filters, which analyse links but rarely images.
The six reflexes that are enough
None of these reflexes is technical. They take a few seconds and cover almost every attempt:
- Read the address your phone displays before confirming. This is the single most important gesture, and the only truly indispensable one.
- Check the domain name, not the rest of the address. What matters is what comes before the first “/” — the rest can contain any reassuring word.
- Be wary of misspelled or unusual addresses: an extra letter, one hyphen too many, an exotic extension.
- On a QR displayed in a public place, run your finger over it: a sticker placed on top can be felt, and can often be seen against the light.
- Never enter payment details or a password on a page opened from a QR code you did not ask for.
- Faced with a QR code asking you to settle a fine, a tax or a fee: do not use the code. Go to the official website of the organisation yourself.
How to spot a QR code stuck over another
This is the most widespread method, because it is the cheapest: no mass printing, no email campaign, just a few stickers placed in the right spot. Three clues, in order of reliability:
- Texture. A sticker can be felt with a finger: a lifting edge, a slight extra thickness, a peeling corner.
- Alignment. A QR added afterwards is rarely perfectly straight or perfectly centred within its printed frame.
- Graphic consistency. The genuine QR is usually printed in the same run as the rest of the item: same shade of black, same paper, same finish. A sticker stands out.
If in doubt about a parking meter, a terminal or an official sign: do not scan. All these organisations have an official website you can reach directly, and none of them depends on a square stuck onto street furniture.
For businesses: protecting your own QR codes
If you display QR codes, you are a target too: a sticker on your window diverts your customers and damages your reputation, not the fraudster's. A few simple precautions change a great deal:
- Print the QR into the item rather than sticking it on. A code printed in the run is far harder to cover cleanly.
- Add your logo in the middle and readable wording around it (“Menu — La Table d'Alice”). A customer who knows the expected look spots the anomaly.
- Laminate or varnish items exposed outdoors: a sticker adheres poorly to a glossy surface and comes off with a fingernail.
- Visually check your items regularly, especially those freely accessible in public spaces.
- Use a dynamic QR: if an item is compromised, you can redirect the genuine code to a warning page while you replace the printed version.
The choice of provider matters too. A serious service validates destination addresses before publication and refuses those pointing to internal resources or to sites already flagged as malicious. That does not stop a physical sticker, but it does stop your own account from serving — by mistake or after a compromise — as a relay to a fraudulent page.
What to do if you have already scanned
Having scanned is not the same as having been a victim. As long as you entered nothing and installed nothing, most likely nothing happened: simply close the page. If, however, you went further, act in this order:
- If you entered banking details: call your bank immediately to block the card, before anything else.
- If you entered a password: change it on the genuine site, and everywhere else you used the same one.
- If you installed an app: uninstall it, then review the permissions granted recently in your phone's settings.
- Report the fraudulent QR to whoever manages the location, and the address to your country's official reporting platform.
QRyx