Scanning a QR code is usually safe, because scanning only reads the text stored in the code. The risk comes from what you do next: opening a link to a fake site, paying on a copycat payment page, installing an app, or handing over personal details. If you read what a code contains before you act on it, you’ve removed most of the danger.
That said, QR code scams are real enough that the FTC and FBI have both issued warnings about them. Here’s what can go wrong and how to tell a risky code from a normal one.
What actually happens when you scan a QR code? #
Your phone’s camera reads the black and white pattern and turns it back into text. That text might be a web address, a Wi-Fi network name and password, a contact card, a phone number, an email draft, a text message or plain words.
Then your phone offers an action: open the link, join the network, add the contact, start the call. Up to that point, nothing has happened on your phone except reading. The decision point is the tap.
What are the real risks of scanning QR codes? #
| Risk | How it happens | What protects you |
|---|---|---|
| Phishing page | The code opens a copy of a bank, parking or sign-in site | Reading the domain before you open it |
| Fake payment | A sticker code sends you to a lookalike payment form | Paying in the official app or on the meter |
| Malicious download | The page pushes an app or file | Installing apps only from the App Store or Google Play |
| Unwanted actions | The code starts a call, a text or an email | Checking the number and message first |
| Rogue Wi-Fi | The code joins you to a network someone else controls | Only joining networks you expect |
| Tracking | A dynamic code logs when and where it was scanned | Knowing that marketing codes often count scans |
The first three are the ones that cost people money. The FTC describes scammers covering real codes on parking meters and sending codes by email or text with made-up urgency about packages and accounts. The FBI has warned about tampered codes that redirect payments and, more recently, unsolicited packages with QR codes inside.
Tracking is a different kind of risk. Many business QR codes are “dynamic,” meaning they route through a service that counts scans before forwarding you. That’s normal marketing practice, not a scam, but it’s worth knowing. See static vs dynamic QR codes for how that works.
Can scanning a QR code hack your phone? #
Reading a code doesn’t install anything. The realistic attacks need you to take another step: open a page, sign in, pay, or install an app.
The one edge case is an unpatched flaw in a phone’s software, which in theory could be triggered by visiting a malicious web page. That’s why the FTC’s advice includes keeping your phone’s operating system updated.
Which QR codes deserve suspicion? #
Slow down when a code:
- Is a sticker on a meter, sign or poster, especially one covering printed text or another code.
- Arrived unexpectedly by email, text or mail, or in a package you didn’t order.
- Comes with pressure: a fine, a failed delivery, a locked account, a deadline.
- Leads to a payment or login page. That’s where scammers collect.
- Uses a shortened link, so the real destination is hidden.
- Asks you to install an app from a link instead of your phone’s app store.
Our guide to what quishing is walks through the common scam formats.
Which QR codes are usually fine? #
Most codes you’ll meet are ordinary: a menu printed on the table card, a code on product packaging, a museum label, an event ticket, a boarding pass, a Wi-Fi code in a friend’s kitchen. The pattern is that they’re printed by the business itself as part of the item, and they don’t ask you for money or a password.
Even then, a quick look at the address costs a second. A restaurant menu code that leads somewhere asking for your card number before you’ve ordered is worth a second thought.
How to scan QR codes safely #
- Preview before you open. Read the link banner your camera shows, or use a scanner that shows the whole contents first.
- Find the real domain. It’s the part right before the first single
/, read from the right.pay.yourcity.govbelongs toyourcity.gov;yourcity.gov.pay-now.infobelongs topay-now.info. - Check physical codes for stickers, as the FBI recommends.
- Don’t pay or log in through a code you didn’t expect. Open the official app or type the address you know.
- Install apps from the App Store or Google Play, never from a QR link.
- Keep your phone updated and use multi-factor authentication on important accounts.
QR Handler is designed around step 1. It never opens a code on its own; you see the full link, network or contact first. For links it shows the real host, whether the connection is encrypted, and warnings for shortened links, raw IP addresses, @ tricks and look-alike characters. It only allows web, email, phone and text-message links to be opened at all. It doesn’t check sites against a blocklist, so a scam page with an ordinary name won’t be flagged. It helps you see the address clearly, and you still decide. Our step-by-step guide to checking a QR code before opening it explains what to look for.
Are QR scanner apps safe? #
The FBI’s 2022 warning advises people to avoid downloading a QR scanner app, because most phones can scan codes with the built-in camera. That’s fair advice. Some third-party scanners have been loaded with aggressive ads or ask for permissions they don’t need.
If you do use one, look at what it asks for. A scanner needs the camera, and photo access if you want to scan screenshots. It shouldn’t need your contacts just to scan, your location, or an account. QR Handler is free with ads, needs no account, and keeps your scan history on your phone. We cover the trade-offs between the camera and apps in iPhone camera vs QR code scanner app.
Frequently asked questions #
Can a QR code steal your information just by scanning it? #
No. Scanning reads text. Information is stolen when you open the link and type it into a page, or install something that collects it. Reading the address first and walking away is safe.
Is it safe to scan QR codes at restaurants? #
Usually, yes. Menu codes printed on table cards are generally legitimate. Still check that the link goes to the restaurant’s site or a known ordering service, and be wary of any code stuck on top of another.
Should I scan a QR code in an email? #
Treat it like a link from an unknown sender. If it claims a delivery problem, an account issue or a failed payment, contact the company directly with a number or address you already trust instead of scanning.
Are QR codes safer than links? #
No. They carry the same risks as any link, and they hide the destination until you scan. The advantage of a link is that you can see it; with a QR code you need your scanner to show it to you.