How Malicious QR Codes Work

Every security instinct people have built up about links depends on being able to read them. Hover over a link, look at the address, notice that it says something other than what it claims. That entire defence rests on the address being legible.

A QR code is a link you cannot read. Your phone can, and acts on it, and you find out where you went afterwards.

That gap — machine-readable, human-opaque — is not a bug in the format. It is the format working exactly as designed, and it is the whole of the attack surface.

The attack, in its most effective form

Print a sticker. Put it over an existing QR code.

That is it. There is no clever cryptography to defeat, because there is none: a QR code carries no signature, no origin, nothing that identifies who made it. A code on a parking meter, a restaurant table, a charity poster or an invoice looks exactly as authoritative as a code printed over it an hour ago.

The victim’s reasoning is sound at every step. The sticker is on the official meter. The page it opens looks like the official payment page. They were expecting to pay. Nothing in the sequence feels wrong, because the only part that was substituted is the part nobody can inspect.

The industry has settled on quishing for the QR-code variant of phishing, and it is growing quickly for a reason that has nothing to do with technical sophistication: it moves the victim from a monitored desktop to a personal phone, where the corporate mail filter, the URL scanner and the managed browser all stop applying.

Why email filters miss it

A phishing link in an email is text. Security tooling reads it, checks it against reputation data, rewrites it, blocks it.

A QR code in an email is an image. To most filters it is a picture, and the destination inside it is not text at all — it is a pattern of squares. The link never appears in a form the filter examines.

Then the user photographs it with a phone that is very likely not managed, opens it in a browser that is very likely not the corporate one, and the entire chain of protections is bypassed by the act of pointing a camera.

What the destination does

Once you are on the page, this is ordinary phishing, and the phone helps the attacker.

Mobile browsers show a truncated address bar. A long hostile URL displays its harmless-looking beginning and hides the rest. Link shorteners and open redirectors on legitimate domains conceal the final destination entirely. On a small screen, a convincing replica of a familiar login page is easier to build than on a desktop, because there is less of it to get right.

The common outcomes are the ordinary ones: credential capture, a payment form, or a prompt to install something.

Checking a code before you act on it

The defence is to close the gap — read the code as text before your phone acts on it.

Scan for text, not for action. Most phone cameras, on recognising a URL, offer to open it. Some show the address first; some show a truncated version. A plain QR reader that displays the decoded string and does nothing else gives you the whole payload, and reading it takes a second.

Read the whole hostname. The part that matters is immediately before the first single slash. Everything after it can say anything at all — secure-payments.example.com proves nothing about example.com.

Treat shorteners as unknown. A shortened link in a QR code is two layers of opacity stacked. Expand it before following it, or do not follow it.

Look at the physical code. A sticker over a printed code is usually visible if you look: a raised edge, a slight misalignment, different paper, a colour that does not match the surrounding print. Feel the surface with a fingernail.

Be most careful where you expect to pay. Parking, charging points, restaurant tables, invoices, donation appeals. These are targeted precisely because the victim is already reaching for a card.

Never install anything a scanned code leads you to. No legitimate parking meter needs you to sideload software.

For anyone printing codes

If you put QR codes in front of the public, you inherit part of this problem.

  • Print the destination in readable text beside the code. This single measure removes most of the advantage — a substituted sticker no longer matches the printed address, and any customer can check.
  • Use your own domain, never a shortener. A recognisable hostname is the only origin signal the medium allows you.
  • Make substitution hard. Laminate, print onto the surface, or place codes behind a counter. A code taped to a window is the easiest target there is.
  • Inspect them. If you rely on public-facing codes, check them physically on a schedule. Nobody else will.
  • Never encode credentials or account identifiers. Everything in a QR code is plain text to anyone who photographs it — a point worth understanding fully if you print Wi-Fi codes.

The honest summary

QR codes are not dangerous. They are unreadable, and unreadable is a different property that happens to defeat the specific defence most people rely on.

Restore the readability and the risk drops to that of any other link: read the payload before you act on it, and check that the hostname is what you expected. That habit takes a second and is very nearly the whole answer.

If you run an organisation

The corporate exposure is different from the personal one, because the attack deliberately routes around the controls you have paid for.

Your mail filter is not covering this. Assume it is not, and say so in training rather than letting people assume protection they do not have. A QR code in an email is an image, and the destination inside it is not text your tooling can inspect.

The device is usually unmanaged. Even in organisations with mobile device management, the reflex is to scan with whatever phone is nearest. Controls that apply to laptops frequently do not apply to the handset in someone’s pocket.

Give people a reporting route that works from a phone. If reporting a suspicious message requires a desktop mail client and a plugin, nobody will report the thing they scanned on their phone at a parking meter. A monitored address they can forward to, or a number they can message, removes the friction.

Say plainly that you will never send a QR code asking for credentials. A rule stated in advance is worth more than any amount of after-the-fact detection, because it gives people a simple test that does not require them to evaluate a URL.

Treat physical codes as an asset to inspect. If your organisation puts QR codes in public — on invoices, posters, equipment, reception signage — someone should be checking them on a schedule. Nobody else will, and a substituted sticker can sit in place for weeks.

The one habit that covers most of it

If you take a single thing from this: decode before you act.

Use a reader that shows you the text and does nothing else, read the hostname, and decide. It takes about a second, it requires no security knowledge beyond recognising a domain name, and it restores exactly the defence the format removed.

Everything else in this article is elaboration on that one habit.


Generate QR codes for links, Wi-Fi, contact cards, email, phone and SMS in your browser with our QR generator. Nothing is uploaded.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top