Short answer
Check the setting and sender before scanning, inspect the decoded address before opening it, and assess the action requested afterwards. A QR code is simply encoded data. It commonly opens a link, supplies a payment destination or carries login information. The danger is that it conceals the destination and exploits the habit of moving directly from scan to action. An unknown source, covered sticker, urgency, login, payment or installation request should prompt you to use a known official website or app instead.
A QR code turns a link into an image
A conventional email link may display a domain, and on a computer a pointer can hover over it to reveal the target. A QR code encodes the content in a pattern that people cannot read directly. It may contain an official address, shortened link, phone number, Wi-Fi configuration or cryptocurrency address. The camera performs the decoding. Convenience comes from removing typing; risk comes from removing an opportunity to inspect.
The Australian Cyber Security Centre calls QR-based phishing “quishing”. Codes in emails, digital platforms and physical objects can direct people to imitation sites, data requests or malicious downloads. Because the link is embedded in an image, some email defences also have less ability to inspect it. Cyber.gov.au: Quishing
Scanning normally decodes and presents the content. The higher-consequence actions are opening, signing in, authorising, installing, granting access and paying. There is no need to believe that every code infects a phone the moment the camera sees it. There is equally no reason to make scanning and every later action one automatic gesture.
Ask why the code is present
A menu on a restaurant table, boarding pass in an airline app, device login that you just initiated on a computer, and payment code on a verified bill have coherent contexts. An anonymous parcel inviting you to discover the sender, an unexpected fine, an account-freeze warning or a street sticker offering an implausible reward relies on curiosity, fear or urgency.
In 2025 the FBI warned about unsolicited parcels containing QR codes that led recipients to provide personal and financial information or download malicious software. The FTC has also described codes placed over parking-payment labels and messages imitating delivery or account problems. FBI: Unsolicited Packages Containing QR Codes; FTC: Scammers hide harmful links in QR codes
Professional design is not proof. A government seal, company colour, case number and formal tone can all be copied. The stronger question is whether a second trusted channel confirms that the underlying transaction exists.
A physical code can be covered
The original code on a parking meter, charging station, table, billboard or public notice can be covered by another sticker. Inspect raised edges, inconsistent colours and a label placed over instructions. For payment, prefer an official app already installed or navigate independently to the organisation's known website and locate the parking zone, bill or order there.
An apparently original label is not conclusive. A dynamic-code service may allow the destination to be changed later, and a legitimate operator's account can be compromised. Physical integrity is one signal, not a complete trust decision.
Read the preview before opening
Most modern camera applications show a URL preview. Identify the actual registrable domain rather than relying on a familiar word at the beginning. company.example.com belongs under example.com; company-login.example.net belongs under example.net. Misspellings, substituted characters, extra hyphens and shortened links can conceal ownership.
A shortened link is not inherently malicious, but it reveals less. For an account, payment or identity transaction, avoid following it and enter through the official app or a known address. After opening, inspect the address again and respect browser warnings. HTTPS encrypts a connection; a fraudulent site can also obtain a certificate.
Evaluate what the destination asks you to do
Viewing a menu differs from entering the password to a main mailbox. Reading event details differs from confirming a bank transfer. Increase scrutiny when a page requests a password or multifactor code, links a new device, downloads an application or configuration profile, requests Contacts, Photos, Accessibility or device-management access, collects card and identity information, demands cryptocurrency, or instructs you to turn off security.
Device-linking codes require particular care. A legitimate service may show a QR code on a signed-in computer for scanning in its official mobile app. A scammer may persuade a victim to scan the attacker's linking code, connecting the attacker's device to the victim's account. Scan only a login code that you have just generated through a trusted service and whose device relationship you understand.
My assessment: QR risk comes from removing visible transitions
A QR code is not a new category of malware. It is interface compression. It collapses “read an address, enter it and confirm the destination” into “point and tap”. When someone scans an image from a work email using a personal phone, the action may also leave the organisation's filtered email and managed-browser environment.
The most effective defence is therefore not learning to interpret the pattern. It is restoring the omitted transitions: verify the transaction, preview the destination, inspect the domain, assess the requested action and use an independent route for consequential operations. The same reasoning applies to shortened links, NFC tags and text-message URLs.
If you have already scanned or submitted information
If you only scanned and previewed the content, close it. If a file was downloaded but not opened, remove it and review downloads. If an application or configuration was installed, uninstall it, review permissions and run the device's supported security checks. If a password was entered, use a trusted device and official site to replace it immediately, address every account where it was reused, enable multifactor authentication and end unknown sessions.
For card information or payment, contact the financial institution promptly. Cryptocurrency transfers are usually difficult to reverse, so report quickly to the platform and relevant scam or law-enforcement channel. Preserve the code, page, message, time and transaction details as evidence without continuing the conversation with the sender.
One-minute checklist
- Did I expect this code, and is the underlying transaction real?
- Does a physical label show covering, raised edges or inconsistent printing?
- Is the main domain in the preview exactly correct?
- Can I complete the action in an official app or by typing the known website?
- Is the page creating urgency through payment, punishment or account closure?
- Does it request a password, code, device link, installation or powerful permission?
- Does the payment confirmation show the expected recipient and amount?
- If it is a login code, did I personally initiate it moments ago?
Conclusion
QR convenience comes from concealment and compression, and scams exploit the same properties. Do not decide trust from whether the image is printed or digital, and do not rely on a polished landing page. Examine the source, real domain and final action. The closer the task comes to login, authorisation, installation or payment, the more valuable it is to leave the QR path and complete the task independently through a known official destination.
Related reading
Continue reading: All articles in How Digital Life Actually Works
Discover more from Geoffrey Chen
Subscribe to get the latest posts sent to your email.