Back to Learn Hub

QR Code Safety: How to Scan Securely and Avoid QR Phishing

Category: Digital Safety5 min readUpdated: August 2026

QR codes (Quick Response codes) have become a standard fixture of daily life. From viewing menus at restaurants and making mobile payments to registering for events and scanning brochures, these two-dimensional barcodes provide a highly convenient link between the physical and digital worlds.

However, because humans cannot read a QR code's matrix pattern with the naked eye, cybercriminals have increasingly hijacked this technology. This has led to the rise of **"Quishing" (QR Code Phishing)**. In this guide, we explain how QR codes can be manipulated and how you can scan them safely.

What is Quishing (QR Phishing)?

Phishing occurs when scammers pretend to be a trustworthy entity (like a bank, utility provider, or courier service) to steal personal credentials or financial details. In a **quishing** attack, the malicious link is hidden inside a QR code.

Cybercriminals use several common delivery channels:

  • Sticker Overlays: Scammers place physical stickers containing malicious QR codes directly over legitimate codes in public spaces, such as municipal parking meters, public transport signs, or restaurant tables.
  • Email Quishing:Phishing emails often bypass traditional text-based spam filters by hiding the link inside an attached image containing a QR code (e.g. "Scan to verify your bank security details").
  • Fake Parking Tickets: Scammers place mock citations on vehicles directing drivers to scan a QR code to pay the fine online, collecting credit card numbers on a clone of a local government payment portal.

How Scammers Exploit the QR Scan Flow

When you scan a QR code, the camera parses the square modules and translates them into a character string (often a web URL). The danger lies in what happens next:

  1. Malicious Redirection: You are directed to a phishing page designed to mimic your banking app, email sign-in, or payment gateway.
  2. Automatic Downloads: The URL triggers an automatic download of malicious software (APK files or spyware) onto your smartphone.
  3. Session Hijacking: The link logs you into a mock session to capture cookies or active authentication keys.

Best Practices for QR Safety

Protecting yourself from quishing requires a few basic habits:

  • Inspect the Code Physically: Always feel the QR code sign in public spaces. If it feels like a sticker placed on top of a plastic or metal sign, do not scan it. Report it to staff immediately.
  • Preview the URL: Do not use scanner apps that open links automatically. Standard camera apps on iOS and Android show a preview of the destination URL before you tap. Verify that the domain matches the official brand (e.g., check for typos like `pay-sars.co.za` instead of `sars.gov.za`).
  • Avoid Payment Scans via Email: Trustworthy companies rarely request payment by asking you to scan a QR code sent inside a notification email.
  • Use Multi-Factor Authentication (MFA): Ensuring MFA is active on your accounts means that even if a phishing page captures your password, they cannot gain access without your second-factor authorization code.

Create secure, custom QR codes for your own needs:

Open the QR Code Generator