Scanning a QR code cannot, by itself, harm your phone. The pattern is inert data — the camera reads it and shows you what it says.

Everything that goes wrong happens in the seconds after: you tap a link, you land on a convincing page, and you type something you should not have. Understanding that is most of the defence, because it tells you exactly where to be careful.

The sticker trick

This is by far the most common version, and it is low-tech. Somebody prints a QR code sticker and puts it over the genuine one — on a parking meter, a restaurant table, an EV charger, a donation sign, a poster.

The code underneath is fine. The one you scan is not.

How to spot it: look at the code itself before you scan. A sticker over a printed sign has edges, corners that lift, a slightly different white, or sits at an angle to everything around it. On a menu or a laminated sign, run a thumb over it — a genuine code is part of the surface.

If a code looks added rather than printed, treat it as suspect.

Fake payment codes

Two variants worth knowing:

A swapped code at the till. A code taped to a counter, replaced with somebody else's account. The money reaches a stranger, and the shop finds out when they reconcile.

A code sent to you. Somebody sends a code and says "scan this to receive your refund". A payment code cannot send you money — scanning one only ever prepares a payment from you. Any story that involves scanning a code to receive money is false.

If you are paying a business, prefer the code the staff hand you or show on their own screen over a sticker on the furniture, and check the recipient name your banking app displays before confirming. That name is the real verification, not the code.

Codes in letters, emails and parking notices

Physical letters with QR codes have become a favourite, because a letter feels more official than an email. So have fake parking fines under a windscreen wiper and fake delivery cards through a door.

The tell is the same in all cases: the code takes you to a page asking for payment or login details, and you did not initiate the contact.

Do not scan it. Go to the organisation the normal way — type the address you already know, or use the number on the back of your card — and check whether the thing is real.

Red flags in the address

Once you scan, the banner shows the destination. Read it before you tap.

SignWhy it matters
Domain does not match the businessThe most reliable single check
A shortener hiding the real addressLegitimate for marketing, but you cannot see where it goes
Brand name in the wrong placeyourbank.example.com is not your bank
Lookalike charactersSwapped letters and digits in a familiar name
Asks for a login immediatelyReal services rarely need one to show you information
Wants an app installed from outside the storeAlmost never legitimate

What is safe and what is not

Safe: scanning. Reading what the banner says. Closing it.

Not safe: entering passwords, card numbers, one-time codes, or ID details on a page you arrived at from a code in public. Also not safe: installing anything a scanned page offers you.

The rule that covers almost every case — if a scan leads to a page asking for money or credentials, stop and reach the organisation another way. No legitimate business loses anything if you pay through their app or website instead of their sticker.

If you already scanned and entered something

Move quickly and in this order:

  1. If it was card or banking details, contact your bank now and freeze the card
  2. If it was a password, change it wherever you use it, starting with email
  3. Turn on two-factor authentication on those accounts
  4. If you installed anything, remove it and restart the phone
  5. Report it — to the business whose code was tampered with, and to the police if money moved

Then tell the business. A tampered sticker on their counter is going to catch other people until somebody points at it.

If you print codes for the public

You are a target too, and there are a few things worth doing:

  • Check your codes regularly. Physically look at them. Staff should know that a sticker appearing over a code is an incident, not a mystery.
  • Make them hard to cover. A code printed as part of a laminated sign or engraved on an acrylic stand is far more effort to tamper with than a sticker on a table.
  • Print your domain next to the code. It gives customers something to verify against, and it makes a substitution obvious.
  • Never ask for passwords or card details on a scanned landing page. Training customers that this is normal is what makes the scams work.
  • Point codes at your own domain, not a shortener. Customers can then check the address matches your name.

The honest summary

QR codes are not dangerous. They are a way of typing a link without typing. The danger is the same danger a link in an email has always had, and the same caution applies.

Read before you tap, distrust anything asking for credentials, and be suspicious of stickers.

If you are making codes rather than worrying about them, ours are static — they contain your link directly, with no redirect service in between for anybody to hijack.