QR code safety
How to tell if a QR code is safe
Before you tap, check three things: where the code is, the web address your phone previews, and what the page asks you for. If a code on a parking machine, in an email or in a letter wants card details or a password, close it and go to the official app or website yourself. Most QR codes are harmless. The UK’s National Cyber Security Centre (NCSC) says codes in pubs and restaurants are probably safe to scan. Codes in open spaces such as car parks and stations, and codes that arrive by email, call for more caution.
Last reviewed: October 2026.
What is quishing?
“Quishing” is phishing that uses a QR code. The code takes you to a fake website built to steal personal or financial information, according to Action Fraud. The NCSC says it works in email because a code hides the link, some security tools don’t scan images, and people scan with personal phones that may lack work-device protections.
The numbers need context:
- Microsoft’s 2026 Digital Defense Report says Microsoft Defender for Office 365 detected more than 145 million QR code phishing attacks between July 2025 and June 2026. That figure comes from Microsoft’s own customer telemetry. It is not a global total.
- In the UK, Action Fraud received 784 reports of quishing between April 2024 and April 2025, with almost £3.5 million lost.
- The NCSC describes QR-enabled fraud as relatively small compared with other cyber fraud.
So there’s no need to fear QR codes. Check them the way you would check any link.
Where scam QR codes turn up
Parking machines and signs. Action Fraud says quishing happens most often in car parks, where criminals put stickers over the QR codes on parking machines. In late September 2026, Perth and Kinross Council removed fake QR stickers from ticket machines in several Perth car parks. It reminded drivers that RingGo does not use QR codes for parking payments and asked them to pay by coins, card or the official RingGo app from the App Store or Google Play. Which? reports that Southend-on-Sea and Aberdeen councils say they don’t use QR codes on their machines.
Emails, attachments and letters. The NCSC says it is seeing more QR codes in phishing emails. Action Fraud has had reports of codes in messages impersonating HMRC and other government schemes, and of online sellers emailed codes to “verify” their account or receive payment. Microsoft found PDF attachments were the main delivery method, reaching 79% of the QR phishing attacks it saw by April 2026. Your bank will never ask you to send personal information by email (NCSC).
Unexpected parcels. The US Federal Trade Commission has warned about parcels from unknown senders with a note asking you to scan a code to see who sent them.
At work. From mid to late October 2026, Microsoft Teams will blur QR code images from external users by default; you can reveal them if you trust the sender. Microsoft says the blur doesn’t mean the code is malicious.
Posters and table stickers. Codes in pubs and restaurants are usually safe, but any printed code can be covered. The Canadian Centre for Cyber Security advises asking staff before scanning a label that could be covering another code, and caution with codes in public places such as stations and street adverts.
Check before you scan: a quick checklist
- Look at the code itself. A sticker over something else, peeling edges or a code that looks added later? Don’t scan it.
- Use your phone’s built-in camera. The NCSC recommends your phone’s own scanner over a downloaded QR app.
- Read the preview before you tap. Phone cameras usually show the web address first. Check it matches the organisation you expect, with no misspellings or swapped letters. A link shortener’s name tells you which service made the link, not who placed the code.
- Notice what the page asks for. Be wary of urgency (“pay now to avoid a fine”) or requests for more information than the task needs.
- Avoid paying through a scanned link. Use the official app from your app store, card or cash, or find the official website yourself.
- Treat emailed codes like links. If a message asks you to scan to sign in or pay, contact the organisation using details from its official website.
- If in doubt, ask. Staff can confirm whether a code is theirs.
Scanned one already? What to do
- You didn’t enter anything: close the page. Report a fake-looking site to the NCSC’s scam website service.
- You entered a password: change it, and any other account using the same one, then check for activity you don’t recognise.
- You entered card or bank details, or paid: call your bank now on the number on the back of your card (or 159, which connects to most UK banks), then report it to Report Fraud (the service that replaced Action Fraud in December 2025) at reportfraud.police.uk or on 0300 123 2040. In Scotland, call Police Scotland on 101.
- Report the code too: tell the operator, council or business. Forward scam emails to report@phishing.gov.uk and scam texts to 7726.
For businesses: make your codes easy to trust
- Print the address next to the code. A line such as “Scan or visit example.co.uk/menu” lets people compare the preview with something you printed.
- Use a domain people can recognise. Free URL codes made on qrcode.house encode a qrcode.house short link, so the preview shows qrcode.house/… rather than a random string. qrcode.house doesn’t offer custom or branded short domains, so every one of these links starts qrcode.house/. That shows which service made the link, not that the code is yours, so print your name and address alongside it.
- Place codes where they are hard to tamper with. The British Parking Association (BPA) advises against putting payment instructions in vulnerable locations, recommends areas staff can monitor, and says codes with a company logo are harder to copy. A code printed into the sign, rather than stuck on, makes an overlay easier to spot.
- Check your codes regularly. Look for overlays and scan each one to confirm its destination. The BPA recommends regular inspections and patrols.
- Offer another way. Card, cash or a typed web address means nobody has to scan to pay.
- Act quickly if you find a fake. Remove it, warn customers and report it. A sticker placed over your code is someone else’s code, so changing or switching off your own code won’t stop it; the sticker has to come off. If your own qrcode.house code needs pausing while you sort things out, you can turn it off from your dashboard once you’ve claimed it and signed in, and an unlocked code ($9.99/year) can have its destination changed without reprinting.
Free qrcode.house files carry the qrcode.house house mark in the centre. Unlocking a code ($9.99/year) lets you replace it with your own logo, which helps people recognise a code as yours.
Create a free QR code or read how qrcode.house codes work. Developers: see the FAQ and For agents.
Frequently asked questions
- How can I tell if a QR code is safe?
- Check where it is, the web address your camera previews, and what the page asks for. Be cautious if it is a sticker over something else, the address doesn't match the organisation you expect, or the page unexpectedly asks for card details or a password.
- Is it safe to scan QR codes in pubs and restaurants?
- Usually, yes. The NCSC and Action Fraud say codes in pubs and restaurants are usually safe to scan. If a code looks like a label stuck over another one, ask a member of staff before you scan it.
- Should I pay for parking with a QR code?
- Only if you are sure it is genuine. Card, cash or the operator's official app from your phone's app store is safer. Perth and Kinross Council has told drivers not to scan QR codes on its parking machines, and Southend-on-Sea and Aberdeen councils have said they do not use QR codes on their machines.
- Why are QR codes in emails a risk?
- A code hides its link, some email security tools do not scan images, and you usually scan with a personal phone that may have fewer protections. Contact the organisation through its official website instead.
- What should I do if I scanned a scam QR code?
- If you entered nothing, close the page. If you entered a password, change it everywhere you use it. If you entered card or bank details, call your bank on the number on your card, then report it to Report Fraud on 0300 123 2040 (in Scotland, Police Scotland on 101).
- Where do I report a QR code scam in the UK?
- If you lost money or shared financial details, report it to Report Fraud (which replaced Action Fraud) at reportfraud.police.uk or on 0300 123 2040 (in Scotland, Police Scotland on 101). Forward scam emails to report@phishing.gov.uk and scam texts to 7726.
Sources
- Microsoft, *2026 Microsoft Digital Defense Report*, p. 66 ("QR code phishing"), reporting period July 2025 to June 2026. https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/2026-Microsoft-Digital-Defense-Report.pdf (summary: https://www.microsoft.com/en-us/security/security-insider/threat-landscape/2026-digital-defense-report; secondary coverage: https://www.rota42.com/en/artigos/microsoft-145-million-qr-code-phishing-attacks-one-year)
- Microsoft 365 Message Center, MC1470410 "Microsoft Teams: QR code protection for messages from external users" (updated 6 October 2026), as reproduced at https://mwpro.co.uk/blog/2026/10/06/mc1470410-microsoft-teams-adds-qr-code-protection-for-messages-from-external-users-2/ and https://mc.merill.net/message/MC1470410
- The National, "Perth and Kinross car parks hit by QR code scammers" (Local Democracy Reporting). https://www.thenational.scot/news/26610790.perth-kinross-car-parks-hit-qr-code-scammers/
- NCSC, "QR Codes – what's the real risk?" (8 February 2024). https://www.ncsc.gov.uk/blog-post/qr-codes-whats-real-risk
- NCSC, "Phishing scams: how to spot and report them" (spot scams, report a scam text, report a scam website). https://www.ncsc.gov.uk/collection/phishing-scams/spot-scams ; https://www.ncsc.gov.uk/collection/phishing-scams/report-scam-text-message ; https://www.ncsc.gov.uk/collection/phishing-scams/report-scam-website
- NCSC, "Data breaches: guidance for individuals and families" (password and account steps). https://www.ncsc.gov.uk/guidance/data-breaches
- Action Fraud, "New quishing alert: £3.5 million lost last year to fraudulent QR codes" (20 June 2025), via WiredGov. https://www.wired-gov.net/wg/news.nsf/articles/New+quishing+alert+3.5+million+lost+last+year+to+fraudulent+QR+codes+20062025170500?open= (original: https://www.actionfraud.police.uk/news/qr-codes)
- GOV.UK (Serious Fraud Office), "Report Fraud: New service from City of London Police" (4 December 2025). https://www.gov.uk/government/news/report-fraud-new-service-from-city-of-london-police ; Report Fraud FAQs: https://www.reportfraud.police.uk/faqs/
- Which?, "Quishing scams warning: how to spot and avoid dodgy QR codes" (25 June 2025). https://www.which.co.uk/news/article/quishing-scams-warning-how-to-spot-and-avoid-dodgy-qr-codes-asYsH0h6jjP1
- Stop Scams UK, "159". https://stopscamsuk.org.uk/159
- British Parking Association, *Preventing Parking Payment Fraud* (2024, updated 2025). https://www.britishparking.co.uk/CoreCode/Modules/Content/ResourceLibrary/AjaxHandlers/ResourceLibraryFileHandler.ashx/e94c8ff1-ad84-409c-9310-908bc8ea6d23
- Canadian Centre for Cyber Security, "Security considerations for QR codes (ITSAP.00.141)". https://www.cyber.gc.ca/en/guidance/security-considerations-qr-codes-itsap00141
- US Federal Trade Commission, "Scam alert: QR code on an unexpected package" (23 January 2025). https://consumer.ftc.gov/consumer-alerts/2025/01/scam-alert-qr-code-unexpected-package ; "See a QR code parked somewhere? Don't scan it…yet!" (3 September 2026). https://consumer.ftc.gov/consumer-alerts/2026/09/see-qr-code-parked-somewhere-dont-scan-ityet