QR safety · answers “qr code scams / quishing”
QR Code Scams in 2026: How Quishing Works and How to Spot It
A QR code scam, or "quishing," hides a malicious link inside those black-and-white squares so you can't read the destination until you've already scanned. U.S. authorities including the FBI and FTC have warned about fake stickers on parking meters, bogus menus, unexpected packages, and QR codes buried in phishing emails. The fix is simple: treat a QR code like any unknown link, and see where it goes before you open it.
What quishing is
“Quishing” is phishing with a QR code. Instead of a suspicious link you can read in an email, the scammer hides the link inside a QR image. You scan, you land on a page that looks legitimate, and it asks for a login, a payment, or permission to install something. The FBI describes attackers embedding malicious web addresses in QR codes to move you off a computer and onto your phone, where a bad link is harder to inspect. The squares are the disguise. Everything else about the scam is old — it’s the same fake-page trick, wearing a new coat.
Fake stickers on parking meters and signs
One of the most reported patterns is also the lowest-tech. Scammers print QR stickers and paste them over the real code on parking meters, signs, and payment kiosks. The FBI’s IC3 has warned that criminals tamper with both physical and digital QR codes, swapping legitimate ones for malicious codes. Security researchers have documented sticker-over-meter incidents in cities including Austin, Houston, and Fort Lauderdale. You think you’re paying for parking; you’re handing your card to a stranger’s page. The tell is physical: a sticker sitting on top of the printed surface, often slightly crooked or newer than everything around it.
QR codes on fake menus and flyers
Contactless menus made table-side QR codes normal, and scammers noticed. A malicious sticker over a restaurant’s menu code, or a bogus flyer taped up in a public spot, quietly routes people to a copycat page. Before you scan a menu code, check that it’s printed on the menu itself rather than a sticker stuck on top. If a café or restaurant has a code on a sticker that looks added after the fact, ask a staff member instead of scanning.
Unexpected packages with a QR code
A newer twist rides on “brushing” scams. In 2025 the FBI’s IC3 warned about unsolicited packages that arrive with a QR code, sent to push the recipient into handing over personal and financial details or installing malicious software. The box looks harmless, the code promises to reveal who sent it, and the page it opens is the trap. The FTC has issued the same warning about QR codes on packages you never ordered. If a package shows up unexpectedly and the only way to “identify the sender” is a QR code, don’t scan it.
QR codes inside phishing emails
Most quishing still arrives by email. A message impersonates a big-name provider, your bank, or your own IT department and includes a QR code “to verify your account” or “review a document.” Putting the link inside an image helps it slip past filters that would flag a bad web address — and it pushes you onto your phone, away from your work computer’s protections. A real IT team doesn’t ask you to scan a code from your desk to keep your access. When an email’s main call to action is a QR code, be skeptical.
Why QR codes appeal to scammers
It comes down to one thing: the link is hidden until you scan. With a normal link you can read the address, hover, and judge before you click. A QR code shows you nothing until you’ve already pointed your camera at it. That opacity is the entire appeal. It also travels cheaply — a sticker costs pennies, works on any wall or counter, and carries no obvious sender to trace back.
Red flags at a glance
- A code that’s a sticker sitting on top of other artwork or signage.
- Any code that arrives unsolicited — in the mail, a package, an email, or a text.
- A destination that asks for a password, card number, or app install right after scanning.
- Urgent wording: “act today,” “scan to avoid a fine,” “your access expires.”
- A domain that’s misspelled or padded with extra words (secure-paypal-login, ups-reschedule, and the like).
How to protect yourself
The habits are simple, and they’re the same ones in our QR code safety guide:
- Preview the link before you open it. Your iPhone shows the domain and waits for a tap — read it first.
- Don’t scan codes from unexpected packages, emails, or texts. If a company seems to be asking, reach it through a number or site you already trust.
- For payments, type the address yourself instead of scanning a code.
- Don’t install apps straight from a QR code; use the App Store.
- If a page asks for a login or payment right after a scan, stop.
Where Inkcode fits — honestly
Inkcode won’t tell you a link is “safe” — no honest app can, and it isn’t a security scanner. What it gives you is a clear look before you leap. Scan with Inkcode and the decoded link appears on a result card first; nothing opens until you choose it. Because the app is ad-free, there’s no fake “virus detected” pop-up muddying the moment — the scareware ads common in free scanners are their own small scam. Seeing the real destination on a quiet screen is exactly what helps you catch a quishing attempt before it catches you.
Common questions
What is quishing?
Quishing is phishing that uses a QR code. The scammer hides a malicious link inside the code, so you can't read the destination until you scan. It usually leads to a fake login or payment page.
Can a QR code itself contain a virus?
Not really. A QR code is just a link in visual form. The danger isn't the code — it's the site it opens and what that site asks you to type, download, or approve.
What should I do if I scanned a scam QR code?
If you only decoded it and closed the page, you're almost certainly fine. If you entered a password, change it everywhere you used it. If you shared card details, call your bank. The FBI takes reports at ic3.gov.
Does Inkcode protect me from QR code scams?
Not as a security scanner — it doesn't scan links for malware, and no honest app does. It helps by showing the decoded link on a card before anything opens, and by being ad-free, so no fake 'virus detected' pop-up rushes your decision.
Sources
- FBI IC3 — Unsolicited Packages Containing QR Codes Used to Initiate Fraud Schemes (PSA, Jul 2025)
- FBI IC3 — Cybercriminals Tampering with QR Codes to Steal Victim Funds (PSA, Jan 2022)
- Security.org — Quishing: How to Spot QR Code Phishing Scams
- FTC Consumer Advice — Scam alert: QR code on an unexpected package