Skip to content
Tech News
← Back to articles

QR Code Scams Explained: How to Check a Code Before You Scan It

get Popsockets PopGrip Phone Grip → more articles
In Short

Quishing works because a QR code gives you nothing to judge before you commit. Here is what the scams look like in practice and the habits that defuse them.

Quishing is phishing delivered by QR code, and it has become common for a dull structural reason: the format is unreadable to humans. You cannot skim a QR code for a misspelled domain the way you can skim a link in an email. You either scan it or you do not.

The versions that actually show up are unglamorous. Someone prints a sheet of stickers and puts them over the payment codes on parking meters or EV chargers. A table tent in a cafe gets swapped for one that leads to a lookalike ordering page. A letter arrives about an unpaid toll, a missed delivery or a tax rebate, with a code instead of a link, because a code survives the print-and-mail process and still lands the victim on a live web page. In offices, a poster about a benefits enrolment deadline is enough, because the target is a login form, not a payment.

What these share is that the code is only the delivery mechanism. The harm happens on the page afterwards: a card form, a login that mirrors your bank or workplace, or a prompt to install something. Scanning a code does not, by itself, hand anything over. Typing into the page that opens does.

That is useful, because it means the defence is not paranoia about scanning. It is a short pause between the scan and the typing.

Modern phone cameras help more than they used to. Both iOS and Android preview the URL as a banner before opening it, and that preview is the first thing worth reading. Look at the domain, specifically the part immediately before the first single slash. Scammers rely on people scanning the beginning of a long string and stopping once they see a familiar brand name, so a domain like yourbank.com.secure-login.example is designed to be read too quickly.

The second habit is to distrust the printed context. The text next to a code is not a promise. Anyone can print 'Official City Parking' above a sticker. If a code is on a surface where a sticker could have been added, run a finger over it: layered stickers are often detectable by touch, with a raised edge or a bubble.

The third is to prefer a route you already trust when money or credentials are involved. If a letter says you owe a toll, go to the tolling authority's site yourself. If a restaurant's code is for payment rather than a menu, paying at the counter costs you nothing. The scam depends on the code being the most convenient path.

When you want an actual check rather than a judgment call, a QR scanner with a security layer will decode the link and inspect the destination before you visit it, including where the redirects lead, whether the domain was registered last week, and whether any threat databases already know about it. We built susQR for this, and it is free and needs no account, but the principle holds with any tool that inspects the destination rather than just opening it.

One last thing worth internalising: none of this is about the code being 'infected'. A QR code cannot carry malware any more than a printed URL can. It carries a destination, and the entire scam is that you cannot see the destination until you are standing on it.

Key Takeaways
Worth a Look

Popsockets PopGrip Phone Grip — While the real defense against quishing is checking URLs before typing anything, having a stable phone grip helps when you're carefully inspecting a QR code preview or zooming in on a suspicious link before deciding to proceed. It's a small, practical accessory for anyone scrutinizing their phone screen more closely these days.

See Popsockets PopGrip Phone Grip on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.