QR Code Scams: How Fake QR Codes Trick People
QR codes are convenient. Scan a code, open a link, pay a bill, read a menu, check in to an event, or fill out a form. That convenience is exactly why scammers abuse them.
A QR code hides the destination until the user scans it. Most people do not inspect the URL carefully before opening it. That creates an opportunity for fake QR codes, phishing pages, and payment scams.
What is a QR code scam?
A QR code scam happens when a QR code sends someone to a destination they did not expect. The destination may look legitimate, but it may be controlled by a scammer.
The user thinks they are opening a trusted page. Instead, they may be opening a fake payment page, fake login form, malware page, or phishing site.
Common QR code scam examples
- Fake parking payment QR codes
- QR stickers placed over real QR codes
- Fake restaurant menu links
- Fake package delivery forms
- Fake event check-in pages
- Fake donation pages
- Fake Wi-Fi login QR codes
- Fake invoice payment links
- Fake bank or wallet login pages
Why QR scams are hard to notice
QR codes do not visibly show the destination. A printed QR code can look official even when it points to a suspicious website.
The scam gets worse when the QR code uses a short link. In that case, the visible destination may be hidden behind a short URL, making it even harder for a normal user to know where the code really goes.
The sticker hijacking problem
One of the simplest QR scams is physical sticker hijacking. A scammer prints a fake QR code sticker and places it over the real QR code on a sign, meter, table, flyer, or payment station.
The sign may still look legitimate. The branding may still look official. But the QR code now points somewhere else.
Warning signs of a suspicious QR code
- The QR code is a sticker placed over another sticker.
- The URL does not match the business or organization.
- The page asks for payment too quickly.
- The page asks for personal information that seems unnecessary.
- The domain looks like a misspelled version of a real brand.
- The QR code redirects through multiple unknown domains.
- The sign has no alternative official website or phone number.
How users can protect themselves
- Preview the URL before opening it.
- Check whether the domain matches the business.
- Avoid entering payment details if the destination looks unusual.
- Use the official app or website when possible.
- Be extra careful with parking, payment, and login QR codes.
- Report suspicious QR codes to the business or property owner.
How businesses can protect customers
Businesses should not treat QR codes as one-time printed objects. Public QR codes should be managed and monitored.
- Use branded or checked short links.
- Show a destination preview before redirecting.
- Monitor destination changes.
- Audit public QR signs regularly.
- Use tamper-resistant labels where appropriate.
- Give customers a way to report suspicious QR codes.
- Keep a record of official QR locations.
Where chked.link fits
chked.link is being built for safety-first short links and QR codes. The goal is to help businesses publish links that are easier to inspect, verify, track, and monitor.
Instead of sending users through a blind redirect, a checked link can show destination information, status, and a report option.
QR Guard concept
A QR Guard scanner can help users scan a QR code, inspect the destination, check risk signals, and decide whether to continue.
The point is not to promise that every link is safe. The point is to reduce blind trust and make the destination more transparent.
Bottom line
QR codes are useful, but they should not require blind trust. If a QR code asks a user to pay, log in, donate, or submit personal information, the destination should be clear and verifiable.
QR codes should be checked before people trust them.