QR & Barcode StudioQR Studio

QR Code Safety: Avoid Phishing and Fake Codes

QR code phishing, often called quishing or qshing, hides a malicious link behind a code so you cannot read it before scanning. The defence is simple: check where the link goes before opening it, and never enter payment or login details on a page reached from an unverified code.

Common QR scams

  • Stickers on parking meters, EV chargers and bike rentals that send you to a fake payment page.
  • Notes on cars claiming an unpaid fine or parking ticket with a QR code to pay it.
  • Emails or letters with a QR code asking you to re-verify a bank, delivery or work account.
  • Codes that download an app file directly instead of opening an official app store.
  • Fake Wi-Fi codes in public places that connect you to a network run by someone else.

What to check before you open a link

Read the domain carefully. Look for misspellings, extra words such as secure-parking-pay, unusual endings, very long subdomains or a raw IP address instead of a name. Be wary of link shorteners that hide the real destination, and of letters from other alphabets that imitate familiar names. Official payment for parking or fines is usually made through a known app or the authority’s own website, which you can type in yourself.

How this scanner helps

The scanner shows the full link and the readable domain before anything opens, and rates it as safe, check before opening or potentially dangerous. The analysis runs offline on your device, looking at signals such as plain http, IP addresses, punycode and mixed scripts, shorteners, unusual ports, risky file downloads and lures that imitate official notices. A warning is a prompt to pause; a clean result is not a guarantee, so the domain check is still worth doing.

If you already entered details on a suspicious page, contact your bank or service provider through its official channel and change the password.

How to make it

  1. Open Scan and point the camera at the code, or scan a screenshot or image.
  2. Read the displayed domain and the safety rating before tapping Open.
  3. If anything looks unusual, do not open it; go to the official website or app yourself.
  4. Report fake stickers to the venue, operator or local authority.

Frequently asked questions

Can scanning a QR code alone hack my phone?

Scanning just reads text. The risk comes from what you do next: opening a malicious page, installing a file or entering credentials. Checking the link first avoids most of it.

Is it safe to pay for parking with a QR code on the meter?

Be careful. Fake stickers on meters are a known scam. Check that the sticker is not stuck over another code, and prefer the official parking app or website.

Are QR codes in emails safe?

Treat them like links in emails. If a message urges you to scan to fix an account problem, go to the service directly instead of scanning.