A QR code's entire function is to hide a destination until after you've already scanned it — that's what makes it convenient, and it's exactly what makes it easy to abuse. "Quishing" (QR phishing) exploits that gap: a scammer prints a sticker with a malicious code and places it over a legitimate one, or emails a QR code instead of a link specifically because email security filters are often tuned to catch suspicious text links, not images of QR codes.
Where this shows up
- Parking meters and public payment terminals. A sticker over the real code redirects payment to a fake site that captures your card details and charges you without ever paying for parking.
- Restaurant table codes for menus or payment, swapped or overlaid the same way.
- "Scan to verify" emails impersonating delivery services, banks, or IT departments, using a QR code specifically to dodge link-scanning security tools and to make the destination hard to check before scanning.
- Flyers and posters in public spaces advertising fake surveys, giveaways, or event registrations.
How to check before you commit
The takeaway
A QR code isn't inherently more dangerous than a text link — it's just harder to inspect first, which is the entire reason scammers have leaned into it. Read the URL preview before your phone opens it, and treat "scan this" requests with the same default caution you'd give "click this."