QR Code and Quishing Scams: Where That Square Could Lead

Ask a Question
QR Code and Quishing Scams: Where That Square Could Lead

QR codes have become part of everyday life. You scan one to pay for parking, read a restaurant menu, check in somewhere, or open a link in a leaflet. They are quick and convenient, which is exactly why scammers have taken an interest.

Quishing, a blend of QR and phishing, is what happens when a fraudster uses a QR code to send you to a fake website. The page might ask for your card details, your banking login, or personal information that can be used to impersonate you later. Because the code itself looks harmless, it slips past the usual checks people make on links and emails.

Where dodgy QR codes turn up

Some of the most common places are the obvious ones, which is part of the problem. When a QR code appears somewhere we expect it, we tend to assume it belongs there, and that assumption is what scammers rely on.

  • Parking meters and pay-and-display machines, where a sticker has been placed over the genuine code or the council's signage.
  • Restaurant and pub tables, where a fake menu code is stuck on top of the real one.
  • Electric vehicle charging points, on or near the screen.
  • Posters and flyers in public spaces, sometimes pasted over genuine adverts.
  • Letters that look as though they come from HMRC, the DVLA, Royal Mail, your bank or a delivery company.
  • Emails, especially ones claiming a problem with a parcel, a payment, a password or a shared document.
  • Packaging and product labels, where a counterfeit code has replaced the real one.

The method behind it is straightforward. A scammer prints a code that points to a website they control, designed to mimic the real service. Once you scan and enter your details, those details go straight to them. In some cases the page will then forward you to the genuine site, so nothing seems amiss.

Why QR codes are useful to scammers

You cannot read a QR code with your eyes. A long web address printed on a page can be checked at a glance, but a square of black and white tells you nothing until your phone decodes it. That alone is a problem.

Codes printed on stickers are also cheap and easy to apply. A fraudster does not need to hack anything. They print a sheet of stickers at home and walk around town placing them on top of genuine codes. On a busy high street it can take days or weeks before anyone notices.

Email filters and security software are also better at spotting suspicious links in text than codes hidden inside an image. A QR code in an attached PDF can slip through checks that would normally flag a phishing link.

How to spot a fake

There is no foolproof sign, but a few things are worth a closer look before you scan.

  • Check whether the code is a sticker placed over something else. Run a fingernail along the edge. A genuine printed code on a parking machine should be part of the original surface, not a label added on top.
  • Look at the surrounding signage. Spelling mistakes, mismatched fonts, or a phone number that does not match the council or company are warning signs.
  • Be wary of any QR code that arrives by email or letter and pushes you to act quickly. Threats about fines, account closures, missed deliveries or tax refunds are standard phishing tactics, whether they come as a link or a code.
  • Treat unexpected codes on packaging, particularly anything asking you to register or claim a prize, with caution.
Scam Detector

Scam Detector

Got a text, call, email or offer that feels off? Paste it in below and we will tell you how scammy it looks, the warning signs to spot, and exactly what to do next.

Try our Scam Detector free, here on this site →

What to check before you tap the link

Most phones show a preview of the web address when you point the camera at a QR code, before you open anything. This preview is your main line of defence, and it is worth slowing down to read it properly.

  • Look at the start of the address. Is it the genuine domain you would expect? For a UK government service, the main part of the address should end in .gov.uk. For a bank, it should match the address you would type yourself. Legitimate sites do sometimes use subdomains, so focus on the core domain rather than every word in the link.
  • Watch for lookalike spellings, extra words, or a familiar name buried inside a longer address. Something like "hsbc.secure-login-uk.com" is not HSBC, because the real domain is "secure-login-uk.com" and HSBC has simply been placed in front of it.
  • Be careful with shortened links such as bit.ly or tinyurl. They hide the real destination. If you cannot see where a link leads, do not follow it.
  • If the page that opens asks for card details, passwords, or one-time codes, stop. Open a browser separately and go to the company's website by typing the address yourself.

For payments, you may find it safer to use the official app for your bank, your parking provider, or the retailer, rather than following a code from a sticker or email. Apps such as RingGo or PayByPhone for parking can be downloaded directly from your phone's app store.

Your situation may be slightly different. ask a question below ↓ and our editorial team will reply with our advice.

What to do if you have scanned a suspicious code

If you only scanned the code and did not enter any details, close the page and clear your browser history. The risk in that case is low, though it is sensible to keep an eye on your phone for unusual behaviour.

If you entered card details, contact your bank straight away. Rather than using a number from a letter, email or website you have just visited, find the contact details through your bank's official app or by typing the bank's website address into your browser yourself. Many UK banks have signed up to the Contingent Reimbursement Model, a voluntary code that can lead to refunds for authorised push payment fraud, but not every bank takes part and outcomes vary, so it is worth checking your bank's own policy.

If you gave away a password, change it at once on the real site, and on any other account where you use the same one. Turn on two-factor authentication if you have not already.

Reporting a fake QR code

Reporting helps stop others from being caught out, and can help authorities trace those responsible.

  • For scam emails containing QR codes, forward the message to report@phishing.gov.uk, which is run by the National Cyber Security Centre.
  • For scam texts, forward to 7726, which is free on most UK networks.
  • For fraud you have lost money to, or attempted fraud, report to Action Fraud at actionfraud.police.uk or on 0300 123 2040. In Scotland, report to Police Scotland on 101.
  • For a sticker on a parking meter, EV charger or council sign, tell the council or operator so they can remove it. Most have a contact form on their website.
  • For a fake code in a shop, pub or restaurant, point it out to staff. They often have no idea it is there.
  • If your personal data has been misused, you can also contact the Information Commissioner's Office at ico.org.uk.

For broader advice and education on scams, Friends Against Scams, an initiative from National Trading Standards, offers free online training and resources. The Financial Conduct Authority also publishes guidance on bank fraud and what to expect from your provider.

QR codes are not going away, and most of the ones you meet will be perfectly genuine. Slowing down for a couple of seconds to read the preview, and being cautious about any code that pressures you to act, removes most of the risk. If something feels off, type the address in yourself or use the official app. Citizens Advice and GOV.UK both have further guidance on scams if you want to read more.

Related warnings

See more recent scams on the Latest Scam Warnings page.

The Next Step

Scam Detector

Now that you have read through the advice above, you might want to put it into practice. Our Scam Detector lets you got a text, call, email or offer that feels off? Paste it in below and we will tell you how scammy it looks, the warning signs to spot, and exactly what to do next. Try it now →

Ask Safe from Scams a Question

Ask Safe from Scams a question

Ask our editorial team a question and we will reply with our advice. Tell us as much about your situation as you can: the more detail you give, the more useful our answer can be.

You do not need to use your real name. Please do not include your full address, phone number, email address, or the names of other people. We may edit or remove identifying details for privacy and legal reasons.

Comments are moderated before publication.

Try our free Scam Detector Check It Now