A QR code itself cannot harm you — it is just encoded data. The risk lives entirely in where it sends you and whether you trust it. As codes have become ubiquitous, attackers have started exploiting that trust with fake codes and “quishing” scams. The defences are simple once you understand where the danger actually is.
Where the risk really is
Scanning a code is safe; acting on its destination without thinking is where people get caught. A malicious code can send you to a convincing fake login page, a fraudulent payment request, or a site that tries to trick you into installing something. The code is just the delivery mechanism — the scam is the destination.
This means the core defence is the same skepticism you apply to links in emails: look before you trust.
Quishing: QR phishing
“Quishing” is phishing via QR codes — for example a fake parking-meter or invoice code that leads to a lookalike payment page. Because a code hides its destination until scanned, people scan things they would never click. Attackers also paste fake stickers over legitimate codes in public places, hijacking trusted locations.
Tips for users
Before acting, check the URL your phone previews after scanning — does the domain match who you expect? Be wary of codes in unsolicited emails, on stickers that look added-on, or anywhere asking for payment or login. Never enter credentials or pay through a page you reached by scanning something unexpected. When in doubt, navigate to the site yourself instead.
Treat a scanned link exactly as cautiously as a link from a stranger.
Tips for businesses
Protect your customers by making your codes verifiable: lead to your own clearly-branded domain, add a printed prompt naming the destination, and use tamper-evident placement so a pasted-over code is obvious. Inspect public-facing codes regularly for stickers or swaps.
Owning the destination domain is the strongest protection — customers can see your real brand in the link, and lookalikes become easier to spot.
Designing for trust
Trust is part of the design. A code that visibly leads to your real domain, with a clear explanation of what it does, reassures cautious users and stands out from anonymous malicious codes. As scanning habits mature, the businesses that signal legitimacy clearly will keep their scan rates while shady codes lose theirs.
Where this is heading
As quishing grows, expect phones and security tools to get better at flagging suspicious scanned links, and expect customers to become more discerning about which codes they trust. That shift rewards legitimate businesses that signal authenticity and punishes anonymous, sketchy codes.
The takeaway for both sides is steady: scanning is fine, but the destination must earn trust. Build that habit now and the rising tide of caution works in your favour.
Building safe habits on both sides
Security with QR codes comes down to habits, because the technology itself is neutral — a code is just encoded data, and all the risk lives in the destination and whether it is trusted. For users, the core habit is simple: after scanning, glance at the URL your phone previews and ask whether the domain matches who you expect. Be wary of codes in unsolicited emails, on stickers that look stuck on over something else, or anywhere unexpectedly asking you to log in or pay, and never enter credentials or money through a page you reached by scanning a surprise. When in doubt, navigate to the site yourself.
For businesses, the job is to make your codes easy to trust and hard to fake. Lead to your own clearly branded domain so customers see your real name in the link, add a printed prompt naming the destination, use tamper-evident placement, and inspect public-facing codes regularly for the pasted-over fakes that hijack trusted locations like parking meters and invoices. Owning the destination domain is the single strongest protection, because lookalikes become obvious.
The wider trend rewards exactly these habits. As QR phishing — ‘quishing’ — grows, phones and security tools are getting better at flagging suspicious links, and customers are becoming more discerning about which codes they trust. That shift quietly punishes anonymous, sketchy codes and rewards legitimate businesses that signal authenticity clearly. Build trustworthy habits now and the rising caution works in your favour rather than against you.
- The code is safe; the risk is the untrusted destination.
- “Quishing” uses fake codes for phishing and fake payments.
- Users: check the previewed URL; never pay or log in via surprise codes.
- Businesses: lead to your own branded domain and inspect codes for tampering.
- Signal legitimacy clearly — trust is part of good code design.
Ready to put this into practice?
Create a free, branded QR code in seconds — no sign-up, no watermark.
Open the generator Try Animated QR