Jeyki SecurityCybersecurity consulting
Phishing

QR Code Scams (Quishing): What They Are and How to Avoid Them

How QR code phishing scams work at parking meters, restaurants, and in email attachments, and the habits that keep a quick scan from becoming a compromised account.

← Back to guidesPublished 2026-08-20 · Updated 2026-08-20

Why QR codes are a convenient scam vector

A QR code hides its destination until you scan it, which is exactly why attackers like it. A sticker placed over a legitimate parking meter code, a fake table-top code at a restaurant, or a QR code embedded in a phishing email or PDF can all lead to a convincing fake site designed to steal a password or a credit card number. Cities including Montreal and Ottawa have publicly warned about fraudulent stickers placed over municipal parking meter QR codes.

Where 'quishing' shows up most often

The scam adapts to wherever people are used to scanning without thinking twice.

  • Parking meters and public signage, where a sticker with a fake code is placed over the real one
  • Restaurant tables advertising a digital menu, where a fake code leads to a phishing page instead
  • Email attachments, especially PDFs, using a QR code to bypass email link scanners that only check text-based links
  • Fake delivery notices or parking tickets left on vehicles with a QR code for 'payment'

How to check a QR code before trusting it

A few seconds of caution stops almost every version of this scam.

  • Look closely at the physical code for signs of a sticker placed over another sticker, a mismatched size, or crooked placement
  • After scanning, check the URL preview before tapping through; most phones show the destination link before opening it
  • Be suspicious of any QR-linked page that immediately asks for a password, credit card number, or personal information
  • For parking or municipal payments, use the official app or website directly instead of scanning a code on a pole or meter
  • For a QR code in an email, treat it with the same suspicion as a text link: verify the sender before scanning

What to do if you already scanned a malicious code

The same response as any phishing incident applies, adjusted for what the fake page asked for.

  • If you entered a password, change it immediately on the real site and anywhere else it was reused
  • If you entered payment card details, contact your card issuer to flag the card and watch for unauthorized charges
  • Report the incident to Canada's national cybercrime and fraud reporting system, especially for physical scams like tampered parking meters, so authorities can remove them

Frequently asked questions

Are QR code scanning apps safer than the phone's built-in camera?

Not inherently; the risk is in the destination the code points to, not the scanning method. What matters is checking the previewed URL before opening it and being cautious about what the resulting page asks for, regardless of which app does the scanning.

Can a QR code install malware just by scanning it?

Most quishing attacks rely on tricking you into visiting a phishing page or downloading a file after scanning, rather than an automatic infection from the scan itself. The real danger is what happens after you land on the page, which is why checking the destination before proceeding matters.

Should businesses stop using QR codes for menus and payments?

Not necessarily, but businesses using QR codes should physically secure them (behind glass or laminated in a way that prevents sticker overlays) and periodically check that the codes have not been tampered with.

Official resources