🛡️ Security

Booby-trapped QR codes: the real risks, and how not to get caught

By The QRyx team · ⏱️ 7 min read ·

Fake QR codes on parking meters, stickers placed over the real ones, emails containing a square to scan: the press reports on it regularly, and suspicion is rising. But what exactly are we talking about? Can a QR code hack a phone? Here is what the risk really is, what it is not, and the few reflexes that are enough to scan with peace of mind.

In short

  • A QR code cannot, on its own, install anything on your phone: it is only an image containing text.
  • The risk comes solely from the destination: a malicious QR leads to a fake site — this is called “quishing”, a blend of QR and phishing.
  • The most widespread scam consists of sticking a label over a genuine QR code in a public place.
  • Your phone always shows the address before opening it: reading it for one second defeats the vast majority of attempts.
  • Never enter payment details or a password on a page opened from a QR code you did not ask for.

A QR code cannot infect your phone

Let us clear up the most widespread fear first. A QR code is not a program, contains no virus and does not run. It is an image, and that image contains text — usually a web address. Scanning “launches” nothing: the phone reads the text and offers you an action, which you confirm or not.

In other words, a QR code is no more dangerous than a link written on a scrap of paper. What can be dangerous is where that link leads — exactly as with a link received by email or text message.

The real risk: “quishing”

The word blends QR and phishing. The principle is identical to a fraudulent email: get you onto a page that imitates a legitimate site, so you enter a password, a card number or personal information.

The QR code gives the attacker one advantage: it hides the address. In an email, a suspicious link can be spotted by hovering over it. In a square of black-and-white modules, no human can read anything before scanning. Verification therefore comes later — when the phone displays the address.

Diagram comparing a legitimate QR code leading to the business's real site, and the same item covered by a sticker leading to a fraudulent site. The normal case The business's real site the business name in the address Address is consistent. The hijacked QR (“quishing”) sticker placed on top A site imitating the real one unknown or misspelled address The square looks identical. Only the address gives it away.
The most common method: a sticker placed over the genuine QR code, redirecting to a site that imitates the original.

The most frequent scams

The observed scenarios look very much alike, and all rely on a context where paying quickly seems normal:

  • The fake parking meter: a sticker on the machine invites you to “pay for parking online”. The page asks for a bank card, which goes straight to the fraudster.
  • The fake fine: a slip tucked under the windscreen wiper, with a QR code to immediately settle a penalty that does not exist.
  • The fake delivery notice: a card in the letterbox announces a parcel on hold and offers to pay a few euros of “customs fees” — the amount is small so as not to raise suspicion.
  • The fake menu or fake terminal: a QR code placed on a table or a charging point, leading to a counterfeit payment page.
  • The fake WiFi: a QR code displayed in a public place connects you to a network controlled by a third party, who can then observe part of the unencrypted traffic.
  • The QR code inside an email: sent as an attachment or an image to bypass anti-phishing filters, which analyse links but rarely images.

The six reflexes that are enough

None of these reflexes is technical. They take a few seconds and cover almost every attempt:

  1. Read the address your phone displays before confirming. This is the single most important gesture, and the only truly indispensable one.
  2. Check the domain name, not the rest of the address. What matters is what comes before the first “/” — the rest can contain any reassuring word.
  3. Be wary of misspelled or unusual addresses: an extra letter, one hyphen too many, an exotic extension.
  4. On a QR displayed in a public place, run your finger over it: a sticker placed on top can be felt, and can often be seen against the light.
  5. Never enter payment details or a password on a page opened from a QR code you did not ask for.
  6. Faced with a QR code asking you to settle a fine, a tax or a fee: do not use the code. Go to the official website of the organisation yourself.

How to spot a QR code stuck over another

This is the most widespread method, because it is the cheapest: no mass printing, no email campaign, just a few stickers placed in the right spot. Three clues, in order of reliability:

  • Texture. A sticker can be felt with a finger: a lifting edge, a slight extra thickness, a peeling corner.
  • Alignment. A QR added afterwards is rarely perfectly straight or perfectly centred within its printed frame.
  • Graphic consistency. The genuine QR is usually printed in the same run as the rest of the item: same shade of black, same paper, same finish. A sticker stands out.

If in doubt about a parking meter, a terminal or an official sign: do not scan. All these organisations have an official website you can reach directly, and none of them depends on a square stuck onto street furniture.

For businesses: protecting your own QR codes

If you display QR codes, you are a target too: a sticker on your window diverts your customers and damages your reputation, not the fraudster's. A few simple precautions change a great deal:

  • Print the QR into the item rather than sticking it on. A code printed in the run is far harder to cover cleanly.
  • Add your logo in the middle and readable wording around it (“Menu — La Table d'Alice”). A customer who knows the expected look spots the anomaly.
  • Laminate or varnish items exposed outdoors: a sticker adheres poorly to a glossy surface and comes off with a fingernail.
  • Visually check your items regularly, especially those freely accessible in public spaces.
  • Use a dynamic QR: if an item is compromised, you can redirect the genuine code to a warning page while you replace the printed version.

The choice of provider matters too. A serious service validates destination addresses before publication and refuses those pointing to internal resources or to sites already flagged as malicious. That does not stop a physical sticker, but it does stop your own account from serving — by mistake or after a compromise — as a relay to a fraudulent page.

What to do if you have already scanned

Having scanned is not the same as having been a victim. As long as you entered nothing and installed nothing, most likely nothing happened: simply close the page. If, however, you went further, act in this order:

  1. If you entered banking details: call your bank immediately to block the card, before anything else.
  2. If you entered a password: change it on the genuine site, and everywhere else you used the same one.
  3. If you installed an app: uninstall it, then review the permissions granted recently in your phone's settings.
  4. Report the fraudulent QR to whoever manages the location, and the address to your country's official reporting platform.

Key takeaways

  • A QR code is an image containing text: it can neither run nor install anything by itself.
  • The risk lies entirely in the destination — “quishing” is classic phishing, with the address hidden on top.
  • The most common attack is a sticker placed over a genuine QR code in a public place.
  • Reading the displayed address before confirming, and checking the domain name, defeats almost every attempt.
  • A QR code asking for a payment, a password or an app installation should be abandoned without hesitation.

Frequently asked questions

Can a QR code contain a virus? +

No. A QR code encodes text, not a program: it cannot run or install anything. The danger comes solely from the page it leads to, which may try to deceive you or get you to download a malicious app — something that always requires an action on your part.

What is quishing? +

It is a blend of “QR” and “phishing”. The principle: get you to scan a QR code that leads to a page imitating a legitimate site, in order to harvest credentials or banking details. The QR code mainly serves to hide the address before the scan.

How can I check a QR code is safe before scanning it? +

You cannot read a QR code with the naked eye: verification happens just after the scan, when the phone shows the address and waits for your confirmation. Look at the domain name — the part before the first “/” — and check it matches the organisation you expect.

Are restaurant QR codes dangerous? +

Not in themselves. The risk, small but real, is that a sticker has been placed over the genuine code. Run your finger over it: an added sticker can be felt. And a menu should never ask you to pay or to create an account.

Do I need an antivirus to scan QR codes? +

No, it is not necessary. Effective protection is behavioural: read the displayed address before confirming. Modern browsers also flag sites already known to be fraudulent.

What should I do if I scanned a fraudulent QR code? +

If you only opened the page without entering anything, close it: nothing happened. If you entered banking details, call your bank immediately. If you entered a password, change it on the genuine site and everywhere you used it.

Put it into practice

Create your dynamic QR code in a few minutes, editable without reprinting.

14-day trial, no credit card · Hosted in France · GDPR