Years of phishing awareness training taught people to hover over links before clicking. QR codes quietly sidestep that entire habit — there's nothing to hover over. You point a camera, the phone resolves the code, and a browser opens before anyone has had a chance to read a URL.

Why it works

A QR code is just a container for a string, almost always a URL. The code itself gives no visual indication of where it leads — a code pointing to a legitimate banking site and one pointing to a lookalike phishing domain are visually identical. That single property breaks most of the intuitions people rely on to spot phishing: no suspicious sender, no misspelled link text, no obviously wrong domain sitting in plain view before a click.

Why it bypasses existing defenses

Email security tools are built to scan text and links inside a message body. A QR code is an image. Many scanning tools don't decode the embedded URL from an image attachment the way they would a plain-text link, so a phishing QR code can sail through filters tuned for years of text-based threats.

Where it shows up

  • Parking meters and public payment points — a sticker with a fraudulent QR code placed over the real one, routing "pay for parking" to a fake payment page.
  • Restaurant menus — the same overlay trick, exploiting the post-pandemic habit of scanning to see a menu.
  • Fake delivery notices — "your package couldn't be delivered, scan to reschedule," leading to a credential-harvesting page styled like a courier's site.
  • Internal-looking corporate emails — "scan to verify your account" QR codes embedded in otherwise convincing phishing emails, aimed specifically at bypassing link-scanning security tools.
A QR code isn't a link you can inspect. It's a link you're asked to trust before you can see it.

How to check before you scan

  • Most phone cameras show a preview of the destination URL before opening it — read that preview fully, including the domain, before tapping through.
  • Be suspicious of QR codes that are stickers layered on top of another surface, especially in public places like parking meters, posters, or table tents.
  • Treat "scan to verify," "scan to claim," and "scan to reschedule" QR codes in email with the same skepticism as a text link making the same request — go to the organization's site directly instead.
  • Avoid entering credentials or payment details on a page you reached via QR code unless you independently recognize and trust the domain shown.

QR codes aren't inherently dangerous — the format is neutral. The risk comes from the gap between how convenient they are to scan and how little verification most people do before trusting where they lead.