What are the risks of scanning a QR code?
A QR code is simply an encoded string — most often a URL — and the risk is that you cannot read it before you act on it. That single property is what makes the format attractive to fraudsters.
The core problem. A printed or displayed link shows you where it goes; a QR code shows you nothing. You are trusting whoever placed the code, and verification happens only after your camera has already resolved it.
The main attacks:
Quishing (QR phishing). A code leading to a convincing fake login page — bank, parcel delivery, parking. Because the code arrives by email or on a physical sign, it bypasses email link filtering, which is precisely why attackers moved to it.
Sticker overlays. Malicious codes printed on stickers and placed over legitimate ones. This has been widely documented on parking meters, EV chargers, restaurant table codes and public information signs, and it is effective because the surrounding context looks entirely genuine.
Payment redirection, sending money to the wrong recipient.
Non-URL payloads. Codes can encode Wi-Fi credentials (joining you to a hostile network), contact details, calendar entries, or app deep links triggering actions.
Malicious app downloads, particularly on Android where sideloading is possible.
Tracking. Legitimate codes frequently carry campaign parameters and unique identifiers, so scanning is logged.
Practical precautions:
Check the URL preview your camera shows before tapping. Modern phones display it; read it rather than tapping reflexively. Look at the actual domain, not the words around it.
Inspect physical codes for stickers applied over the original — a raised edge or a mismatched print is the tell.
Never enter credentials or payment details on a page reached from a scanned code; navigate to the site independently instead.
Be suspicious of unsolicited codes arriving by post, email or on a windscreen.
Keep the phone updated, since some risks depend on browser vulnerabilities.