A link in an email can be inspected before you click it. A QR code cannot. The pattern is unreadable to humans, so scanning one is trusting whoever printed it. That gap is now actively exploited, to the point where the practice has a name: quishing.
How the attack works
The common version needs no technical skill at all. Someone prints a sticker with their own QR code and places it over a legitimate one. Parking meters, restaurant menus, EV chargers and payment terminals have all been targeted, because people expect a code there and scan without thinking.
The code leads to a convincing copy of the real payment page. You enter card details, the page confirms, and nothing seems wrong until the charges appear.
QR codes are also used to get past email filters. A phishing link in text gets scanned and blocked, but the same link inside an image of a QR code often passes, and the victim opens it on a phone where the address bar is truncated.
What a QR code can contain
- A web address, by far the most common.
- Plain text, with no action attached.
- Wi-Fi credentials, which can make a device join a network automatically.
- Contact details as a vCard.
- A payment request, including UPI strings that open a payment app with an amount prefilled.
- An email or SMS draft addressed to a number you did not choose.
The variety is the point. A code that silently joins your phone to a network, or opens a payment app with the recipient already filled in, is doing something more consequential than opening a page.
Why a scanner should show you the result first
Many phone cameras open a scanned link with a single tap, and some apps go further and load it immediately. That removes the only moment where you could have noticed something wrong.
A scanner that decodes the code and shows the destination as text gives that moment back. You read the address, decide, and only then act. It is a small difference in interface that changes the risk considerably.
Reading the destination properly
- Check the domain, specifically the part immediately before the first single slash. In "paypal.com.secure-login.info/pay", the real domain is secure-login.info.
- Be wary of shorteners. A bit.ly link hides its destination entirely, and a printed code has no reason to need one.
- Look for lookalike characters: a digit 1 for a letter l, or "rn" imitating "m".
- On a physical code, feel for a sticker layered over another. That alone is strong evidence of tampering.
- Never enter card details or passwords on a page you reached only by scanning a code in public.
The camera permission is not the risk
Browser-based scanners ask for camera access because they cannot see the code otherwise, and the permission is limited to the tab and revocable. Our scanner decodes the video on your device; no frame is uploaded. The risk in QR codes is the destination, not the scanning.