

Malicious codes can direct users towards phishing pages, fraudulent payment requests and potentially harmful downloads.
Checking the source, URL, website domain and payment details can help users identify suspicious QR codes.
Users who accidentally share credentials or financial information should immediately secure accounts and contact their bank.
QR codes have become so ordinary that people scan them without a second thought. They appear on restaurant tables, parking meters, delivery messages, and counters. Scammers are exploiting that convenience.
The scam is known as quishing and involves the insertion of a harmful URL into the software. Unlike an ordinary URL, which gives away the destination, this one remains concealed until it is decoded by the phone. The user might eventually be directed to a fraudulent online banking, payments, or government site.
The basic trick is not new, but delivery is becoming convincing. The Federal Trade Commission issued warnings regarding QR codes in unusual envelopes and texts. An alert in 2026 also talked about QR codes in fake traffic violation texts seeking prompt payments.
It may be more of a psychological threat than anything else. A QR code in what looks like an authentic notification will lend credence to the phishing attack. CERT-In issued a warning about fraudsters replacing legitimate QR codes in notifications.
For India, the threat is all the more relevant owing to the extensive use of QR codes for digital payments.
Also Read: SpaceX, NVIDIA Target 2027 Launch for Orbital AI Computing Network
Scanning a QR code does not necessarily hand over all the data on a phone. The bigger risk usually begins after the scan, when a user opens the destination, enters sensitive information, downloads an application or approves a payment.
A malicious QR code can lead to a spoofed website. It may ask for a password, card number, OTP, or details. The destination can also push malicious software onto the device.
Treat the scan as the beginning of verification.
First, start with the origin of the QR code. Any suspicious code that comes in an email, SMS, social media message, or even through a package requires further analysis. CERT-In cautions users to avoid scanning QR codes from unknown sources and to see whether the QR code in a public poster is pasted under some suspicious stickers.
Once the QR code has been scanned, analyze the URL carefully before providing any data. Be alert to misspellings, unusual domain names, link shorteners, or a URL that has nothing to do with the company behind the message.
Payment requests require additional care. According to CERT-In, users should always confirm the bank name before making a payment using QR codes. A UPI PIN or OTP is not necessary to receive payments.
For banking, government services, and account recovery, manually open the official app or website instead of relying on a QR code received unexpectedly. This removes one layer of uncertainty and makes it easier to confirm that the service is genuine.
Keep the operating system and apps updated and avoid installing applications from unknown sources. CERT-In specifically recommends downloading apps through official app stores and keeping security software current.
Do not panic if you scanned a suspicious code but did not provide information, install an application, or approve a transaction. Close the page and avoid interacting with it further.
If you entered a password, change it immediately anywhere it was reused. If banking or payment information was exposed, contact the bank, monitor transactions and secure the account.
The larger lesson is that the QR pattern itself is not a security signal. It is a way of carrying information. The question is where that information takes you and what it asks you to do. As QR-based services become more common, verification can outweigh the convenience of an instant scan.
Also Read: AI Agent Loops Explained: How Autonomous AI Systems Think
QR code scams, known as quishing, use malicious codes to redirect victims towards fraudulent websites designed to steal credentials, financial information or personal data.
Scanning alone does not necessarily compromise a phone. Risk increases when users open malicious websites, download applications, enter credentials or authorize fraudulent transactions.
Check where the code originated, look for tampering, preview its destination URL and verify the website domain before entering information or completing payments.
QR payments can be safe when using trusted sources. Verify the recipient's name, payment amount and transaction details before authorizing any payment or entering your PIN.
Close the website immediately and avoid entering information or downloading files. If credentials or financial details were shared, change passwords and contact your bank.