Skip to content

Practical guide

Quick Response Code safety

Scanning is safe. Trusting is the decision. The gap between those two sentences is where every Quick Response Code scam lives.


The short answer: decoding a Quick Response Code cannot harm your phone. The symbol contains data, not software; your camera reads it and shows you text. Every documented Quick Response Code attack works one step later — at the page you open, the app you are urged to install, the login you type, or the payment you approve.

This matters because it tells you exactly where to be careful. Not at the camera. At the tap.

Why Quick Response Codes are attractive to attackers

A hyperlink shows you its destination. A Quick Response Code does not. That single property — opacity to the human eye — is the whole of its abuse potential. An attacker does not need to breach anything; they need a printer and a plausible surface. The technique has a name, quishing, and it has been observed on parking meters, restaurant tables, electric-vehicle chargers, invoices, package inserts, and posters in transit stations.

The four patterns worth recognising

Quick Response Code abuse patterns
PatternHow it worksWhat gives it away
Overlay stickerA genuine printed code is covered with a sticker carrying the attacker's codeA raised edge, a peelable corner, print quality that differs from the surface beneath
Lookalike domainThe code resolves to a domain one character off the real oneRead the domain in the banner before tapping; check it against the organisation's known address
Payment redirectionA code on an invoice or terminal directs payment to the attacker's accountUnexpected urgency; a payee name that does not match the supplier
Abandoned destinationA legitimate code's domain lapsed and was re-registered by somebody elseAn old printed code leading somewhere unrelated to the original publisher

The one-second check

  1. Look at the object. Is the code part of the printed material, or stuck on top of it? Run a fingernail along the edge.
  2. Read the destination in the banner. Your phone shows it before it opens. Does the domain belong to the organisation you think you are dealing with?
  3. Notice what the page asks for. An immediate demand for a password, a card number, or an app install is the moment to stop.
  4. Prefer the known route for anything financial. For payments, open the organisation's own app or type its address yourself. A code should never be the only path to a transaction.

Notice what is not on that list: avoiding scanning. Refusing to scan is not a security posture, it is an inconvenience that buys almost nothing. Reading the destination buys almost everything.

What the standard protects, and what it does not

ISO/IEC 18004 specifies how a Quick Response Code is structured, encoded, and error-corrected. Its Reed–Solomon error correction is genuinely robust — a symbol tolerates roughly 7% loss at level L and about 30% at level H — and that resilience is why a scuffed label still reads.

But error correction protects integrity of decoding, not authenticity of origin. The standard has no opinion about who printed the symbol or whether the destination is honest. It never claimed to. That layer simply does not exist in the base symbology, and pretending otherwise is the root of most public confusion about QR safety.

Closing the gap: from "looks legitimate" to "is verifiable"

Every check above is a judgement call made by a human being holding a phone in poor light. That is a thin defence for a symbol now used on identity documents, medication packaging, machinery nameplates, and payment instructions.

A Registered QR Code replaces the judgement call with a lookup. It is the same Quick Response Code — same free standard, same camera, no app — that has additionally been carried through the governance chain and bound to a public identity record. Anyone scanning it can resolve that record and see who issued the code and whether it is currently valid. The trust does not come from the sticker. It comes from the registry.

That is the shift this reference exists to document: the ordinary Quick Response Code is a brilliant way to carry data and a poor way to carry trust. The Registered QR Code is what the same symbol looks like once the trust question has been answered.

What a Registered QR Code is →
QR Secure: security, integrity, and the trust model →
How verification works →

Frequently asked

Is it safe to scan a Quick Response Code?
Scanning is safe. The act of decoding a symbol cannot install anything or run code on your phone; it produces text. The risk lives entirely in what you do next — the page you open, the app you install, the credentials you type, or the payment you approve.
What is quishing?
Quishing is phishing delivered by Quick Response Code. Because a code hides its destination from the human eye, an attacker can put a convincing sticker in a plausible place — a parking meter, a restaurant table, an invoice — and route the scan to a page that imitates a legitimate site.
Can a Quick Response Code contain a virus?
Not directly. A code contains data, not executable software. A malicious code works by sending you to somewhere that then asks you to install something or hand over information. The phone is not compromised by the scan itself.
How can I tell if a Quick Response Code has been tampered with?
Look at the physical object first. A sticker applied over printed material, a fresh label on weathered signage, mismatched print quality, or a code that does not match the surrounding branding are all warning signs. Then check the destination domain before opening it.
Should I scan a Quick Response Code that arrived by email or post?
Treat it exactly as you would an unexpected link. A code in an unsolicited message deserves the same scepticism as a link in an unsolicited message — more, because you cannot read where it goes.
How does a Registered QR Code make scanning safer?
A Registered QR Code resolves to a public identity record naming the issuer and stating the code's current status. That converts the question from 'does this look legitimate' into 'what does the record say', which is a question anyone can answer without trusting whoever printed the label.

Related reading