Think Before You Scan: How to Spot a Fake QR Code

Article summary: Fake QR codes can hide malicious links in emails, signs, and even parking meters. Spotting a fake QR code starts with a quick pause to check where it came from and preview the link before opening it. Combined with email filtering and stronger sign-ins, that simple habit reduces the risk of stolen passwords and fraudulent charges.

A flyer taped to the breakroom door promises a free lunch for completing a quick employee survey. There’s a QR code at the bottom.

Someone scans it, and their phone opens what looks like the company’s Microsoft 365 sign-in page.

There’s just one problem: nobody in HR posted the flyer.

QR codes have become so common that scanning one barely feels like clicking a link. Scammers take advantage of that familiarity to send people to fake login pages, payment sites, and other malicious destinations.

Learning to recognize a suspicious QR code is now part of everyday business security, not just something for IT to worry about.

Why QR Codes Make Such Good Bait

A QR code is essentially a link you can’t read at a glance.

With a regular link, you can inspect the web address before clicking. A QR code hides that destination inside an image, making it harder to tell where you’re going before you scan.

Attackers are taking advantage of that blind spot. Microsoft Threat Intelligence reported that QR code phishing attacks increased 146% during the first quarter of 2026, climbing from 7.6 million in January to 18.7 million in March.

Most were delivered through PDF attachments. By hiding malicious links inside QR-code images, attackers can also make them harder for text-based email scanning tools to detect.

There’s another advantage for the attacker: a QR code displayed on a work computer is usually scanned with a phone. That can move the victim away from the protections on a company-managed computer and onto a personal or unmanaged device.

The result is a phishing link that is harder for both the employee and some security tools to inspect before someone follows it.

Where Fake QR Codes Show Up

Fake QR codes work best when they appear somewhere you already expect to see one. Here are three places to be especially careful.

In Your Inbox

QR code phishing emails often disguise themselves as routine business messages. You might see a document waiting for your signature, an HR notice, or a warning that your multifactor authentication needs to be reset.

The message tells you to scan a QR code to take care of the problem. Instead, the code leads to a fake login page designed to steal your credentials.

On Parking Meters and Public Signs

Scammers can place fraudulent QR code stickers over legitimate ones on parking meters, signs, menus, and other public materials.

The FBI has warned that criminals tamper with physical and digital QR codes to redirect people to malicious websites that steal login credentials, payment information, and other sensitive data.

If a QR code looks like a sticker placed over another code, has been tampered with, or sends you somewhere unexpected, don’t continue.

In Unexpected Packages

A malicious QR code can even show up at your door.

In 2025, the FBI warned about unsolicited packages containing QR codes but little or no information about the sender. Curiosity about the mystery package can persuade recipients to scan the code.

That scan may lead to a fraudulent website designed to collect personal or financial information or potentially download malicious software onto the device.

How to Spot a Fake QR Code Before It Costs You

Before you scan, ask four questions:

  • Was I expecting this? Be suspicious of unexpected codes, especially ones that create urgency.

  • Does it look tampered with? Check public QR codes for stickers placed over the original.

  • Where does it lead? Preview the address and watch for misspellings or unfamiliar domains, just like in business impersonation scams.

  • What does it want? If an unexpected code leads to a login or payment page, stop and visit the official site or app instead.

The FTC also recommends keeping your phone updated. And skip third-party QR scanner apps. Your phone’s built-in camera can usually do the job.

What Your Business Can Do Beyond Training

Employee awareness works better when technology provides another layer of protection.

Start with email security that can inspect images and attachments for phishing threats, not just visible links.

Next, strengthen account security. Phishing-resistant authentication can help stop credentials captured by a fake login page from being used to access an account. Number matching for MFA prompts can also help protect employees from MFA fatigue attacks.

Finally, make suspicious QR codes easy to report. If someone enters a password on a fake site, IT needs to know quickly so it can secure the account and investigate. If payment information was entered, contact the card issuer promptly.

Just like suspicious email attachments, questionable QR codes should be reported instead of ignored.

Is Your Team Ready for the Next Fake QR Code?

QR codes are easy to trust because scanning them has become second nature. A quick check of the source and destination can help employees recognize when something doesn’t look right.

Pair those habits with stronger email protection and account security, and your business has more than one line of defense against QR code phishing.

BrainStomp can help strengthen your email and account security while giving your team practical guidance for recognizing phishing attempts before they cause trouble.

Contact BrainStomp or call 260-918-3548 to get started.

Article FAQs

What is quishing?

Quishing is a type of phishing attack that uses a QR code to send someone to a malicious website. The goal is often to steal login credentials, payment information, or other sensitive data.

How can I check where a QR code goes before opening it?

Use your phone’s built-in camera to scan the code, but check the web address it previews before opening the page. Watch for misspellings, unfamiliar domains, or an address that doesn’t match the organization you expected.

What should I do if I scanned a fake QR code and entered information?

Report it to IT immediately so they can secure any affected accounts. If you entered payment information, contact your card issuer promptly and follow its instructions for protecting the account.