If you scanned a malicious QR code but only looked at the page, close it; you’re very likely fine. What matters is what you did after the scan. If you entered a card number, call your card issuer now. If you typed a password, change it and turn on two-factor authentication. If you installed something, delete it. If you gave out personal details like your Social Security number, go to IdentityTheft.gov. Then report the scam.
Work through the sections below in order. Only the ones that match what you did apply.
First, figure out how far it went #
| What you did | Risk level | First step |
|---|---|---|
| Scanned and looked at the preview | Very low | Nothing, just don’t open it |
| Opened the page, typed nothing | Low | Close the tab, clear it from history |
| Entered a card number or paid | High | Call your card issuer |
| Typed a password or one-time code | High | Change the password, sign out other sessions |
| Installed an app or profile | High | Uninstall it, check settings |
| Shared your SSN, ID or date of birth | High | IdentityTheft.gov, freeze your credit |
| Joined a Wi-Fi network or sent a text | Medium | Forget the network, check your phone bill |
If you only scanned it or opened the page #
Scanning a QR code just reads the text inside it. Opening the page shows you a website. Neither step hands over your information by itself.
- Close the browser tab.
- Don’t tap anything on the page, including “close” or “cancel” buttons inside it.
- Clear the page from your browser history so you don’t reopen it by accident.
- Make sure your phone’s software is up to date. The FTC’s advice on QR scams includes keeping your operating system updated, which closes the security holes that malicious pages try to use.
If you entered a card number or paid #
This is the most common QR code scam outcome, especially with fake parking meter codes.
- Call your card issuer using the number on the back of your card. Tell them you paid a fraudulent site, ask them to block the card and send a new one, and dispute the charge. The FTC’s guidance for scam victims is to report it to the card issuer immediately and ask for a refund.
- If you used a payment app like PayPal, Venmo or Cash App, report the payment in the app right away and ask them to reverse it.
- Watch your statements for the next few months. Scammers sometimes test a stolen card with a small charge before a big one.
- If it was a parking payment, you probably still owe the real parking fee. Pay it through the official app or meter, and keep your records in case you get a ticket.
If you typed a password or login #
- Change the password on the real site, typing the address yourself or using the official app.
- Change it anywhere else you used the same password. Attackers try stolen passwords on other sites.
- Turn on two-factor authentication if it wasn’t already on.
- Sign out of other sessions. Most big services have a “sign out everywhere” or device list in their security settings.
- Check for changes to your recovery email, recovery phone, forwarding rules and linked devices. Attackers change these to lock you out.
- If it was a work account, tell your IT or security team now. They can reset sessions and look for misuse, and they’d much rather hear early.
If you also entered a one-time code from a text or authenticator app, assume the attacker got into the account and follow every step above.
If you installed an app or profile #
On Android: uninstall the app from Settings > Apps. Open the Play Store and run a scan with Google Play Protect. If the app requested accessibility or device admin access, remove that permission first, then uninstall.
On iPhone: delete the app. Then look in Settings > General for a VPN & Device Management section and remove any profile you don’t recognize. A configuration profile installed from a website can change how your phone behaves.
Then change the passwords for any accounts you used while the app was installed.
If you shared personal information #
If you entered your Social Security number, driver’s license, date of birth or similar:
- Go to IdentityTheft.gov, the FTC’s recovery site, which builds a step-by-step plan based on what was exposed.
- Consider a credit freeze with Equifax, Experian and TransUnion. It’s free and stops new accounts from being opened in your name.
- Get your free credit reports and check them for accounts you don’t recognize. The FBI’s 2025 warning about QR codes in unsolicited packages gives the same advice.
If the code joined a Wi-Fi network or sent a text #
QR codes can hold Wi-Fi logins and pre-written text messages, not just links.
- Wi-Fi: go to your Wi-Fi settings and choose “Forget this network.” Change passwords for anything you signed into while connected.
- Text or call: check your sent messages and your next phone bill for charges to premium numbers, and report anything odd to your carrier.
Where to report a QR code scam #
Reporting helps investigators connect cases and helps get fake codes taken down.
- FTC: ReportFraud.ftc.gov
- FBI: ic3.gov, especially if you lost money. Seniors can also call the Justice Department’s Elder Justice Hotline at 1-833-FRAUD-11, which the FBI lists in its 2025 warning.
- Texts: forward scam texts to 7726 (SPAM).
- Emails: forward phishing emails to [email protected], as the FTC’s phishing guidance suggests.
- The physical location: if the code was on a parking meter, sign or shop window, tell the city, the parking operator or the business so they can remove it.
How to avoid it next time #
The fix is to read a code’s contents before anything opens. QR Handler never opens a code by itself. It shows you the full link first, names the real site behind it, and warns about shortened links, unencrypted http, raw IP addresses, addresses that hide the real site behind an @, and look-alike characters. It can’t recognize a scam domain that’s spelled normally, so if a code leads to a payment or login page, go to the company’s official app instead. Our guide to checking a QR code before opening it covers the habit in detail, and what quishing is explains how these scams are set up.
Frequently asked questions #
Can a QR code hack my phone just by scanning it? #
Scanning only reads text, so it can’t install anything. Harm comes from opening the page and then typing information, approving a download or installing an app. Keeping your phone updated covers the rare case of a malicious page targeting an unpatched bug.
Do I need to factory reset my phone? #
Usually not. If you only opened a page, closing it is enough. If you installed an app, uninstalling it and checking for leftover profiles or permissions is normally enough. A reset makes sense if strange behavior continues after that.
Will my bank refund a QR code scam payment? #
Card payments generally have the strongest protections, and your issuer can dispute the charge. Payment apps, wire transfers and gift cards are harder to recover. Report it as fast as possible in every case.
How do I know if my phone has malware? #
Warning signs include apps you don’t remember installing, new profiles or device admin apps, pop-ups outside the browser, fast battery drain, and data use you can’t explain. Remove anything unfamiliar and run Google Play Protect on Android.