You Scanned a QR Code. Here's What May Have Just Happened — and the One Step That Prevents It.

# You Scanned a QR Code. Here's What May Have Just Happened — and the One Step That Prevents It.

You'd never click a link from a stranger. You scan their QR codes without thinking.

QR codes went mainstream during COVID-era restaurant menus. So did a specific attack that exploits them. A scammer who gets access to a public location — a parking meter, a restaurant table, a community bulletin board — can place a sticker over a legitimate code in three seconds. Every scan after that goes to them.

The attack has a name: quishing. QR code phishing. It works because scanning reflexively, without checking where a code goes, has become completely normal.


Why QR codes are vulnerable in a way links aren't

When you tap a text link, most phones show you the URL first. You can see the domain. You can decide not to go.

When you scan a QR code, your camera reads a URL, the browser opens, and the page loads in one motion. No preview. The shortcut that makes QR codes fast is the same shortcut that skips the one moment where you might have caught it.

By the time you're looking at the screen, you're already there.


Where QR code tampering happens

Not every code is a target. Some surfaces are significantly higher risk.

Parking meters and payment kiosks

Cities moved to QR-code payment systems for street parking. Scammers place overlapping stickers that redirect to fake payment pages built to look identical to the real ones. The payment appears to process. Your card number is gone before you get back to your car.

Restaurant table tents and menus

High-turnover surfaces that dozens of strangers touch every day. A replacement sticker takes three seconds to apply. The fake menu page may ask for an email address or payment information before showing anything useful.

Package delivery slips

Printed notes left on doors sometimes include QR codes to "track your package." Fake delivery pages ask for shipping account credentials or a card number for "re-delivery fees" — a charge that doesn't exist.

Public flyers and bulletin boards

A code posted for a local event, discount, or community resource can be covered by a replacement in seconds. You enter whatever the page asks, and it goes to the person who put the sticker there.


What happens after a bad scan

The destination usually looks familiar. That's deliberate.

In one version of the attack, you land on a login screen for a real service — Netflix, your bank, Amazon. You enter your username and password. They go to the attacker. You get redirected to the real page, already logged in. Nothing looks wrong. The theft was silent.

In another, the form looks like a real payment portal. The transaction appears to process. Your card number was captured. Charges show up days or weeks later, spread across multiple vendors to stay under alert thresholds.

In a third, the page requests an app install or asks you to enable accessibility features. Any of those, if allowed, can give someone persistent access to your device.


The check before every scan

One habit prevents all of it.

Look at the physical code before your camera touches it. Is there a sticker placed over part of the original surface? Does it look layered or slightly misaligned with the design around it? A replacement sticker rarely sits flush with the original. A few seconds of looking catches most of them.

Then check the URL before the page loads. Most phones show a preview before opening the browser. That one second is when you can see the domain. A city parking meter should go to a .gov or a known vendor's domain — not a .info or a freshly registered .com with a name that's almost right.

If you don't recognize the domain, close the tab before the page finishes loading. A page that never fully loads cannot harvest credentials. Closing it is the entire defense.


If you've already scanned and entered something

If you entered a password: change it now on the real service, from a different device if possible. Turn on two-factor authentication if it isn't already on. Check recent login activity.

If you entered card details: call your issuer and report the card as compromised. Ask for a new number. Review recent transactions. Calling proactively speeds up the dispute process.

If you installed something or granted permissions: treat the device as compromised. Factory reset is the cleanest fix. Document what you installed and when before you do — your bank or the FTC may ask.

Report the tampered code to whoever owns the location. A sticker on a parking meter affects everyone who parks there after you.


The rule

A QR code is a link you can't read before you follow it.

One look at the physical code. One glance at the URL preview. That's the whole thing. The attack that takes three seconds to set up takes one second to defeat.


Scamanot's QR Code Scam Investigator investigates suspicious URLs and scan destinations for phishing indicators, fake payment pages, and known fraud patterns. No account required. Nothing you submit is stored.

Not sure if something is a scam? Run it through Scamanot — free investigations available, no account required.

Investigate Something Now