Scam › Module 2 › Lesson 3
QR Code Phishing
How malicious QR codes hijack logins in parking lots, restaurants, and offices—and how to scan safely
Opening
Your camera is the new click
QR codes skip the moment where you read a full URL. That makes them perfect for phishing in parking garages, restaurant tables, poster ads, and office "Wi-Fi login" sheets. Attackers stick a malicious code over a legit one—or print entire fake posters.
1. How QR Phishing Works
You scan → browser opens → page asks for Microsoft/Google/bank credentials or a payment. Because you initiated the scan, the site can feel more trustworthy than a random email link—even when it is not. Some codes install profiles on mobile or open deep links into chat apps with a scammer waiting.
2. Safe Scanning Habits
Inspect the sticker
Raised edges, different paper, or a code taped over another code = walk away.
Read the URL preview
Most phone cameras show the domain before you open it. If it is not the brand you expect, cancel.
Prefer typed official apps
Pay parking or order food in the official app from the store—not a random wall code—when you have any doubt.
Work QR codes
IT rarely needs you to scan unknown codes to "keep email working." Verify with known IT channels.
URL preview is your hover
Treat the pre-open URL on your camera screen like hovering a link on desktop. No preview match, no tap.
Knowledge Check
Why are QR codes attractive to phishers?
Multiple choice
Knowledge Check
True or False: A QR sticker placed on top of another QR code can redirect you to a malicious site.
True or False
Knowledge Check
Before opening a scanned QR link you should:
Multiple choice