Threats & Scams

QR Code Scams: What to Check Before You Scan

QR codes make it easy to hide a malicious link in plain sight. Here's what to check before scanning one.

4 min read · Cybersecurity & Privacy

A QR code can point anywhere, and because the destination is invisible until scanned, attackers have started placing fake codes over legitimate ones in public places like parking meters and restaurant tables.

Why QR codes are an appealing target

Unlike a suspicious link in an email, a QR code offers no visible text to scrutinize beforehand, and most people scan them with an implicit trust that doesn't extend to clicking an unfamiliar link directly.

What to actually check before scanning

Looking for signs of tampering, like a sticker placed over the original code, checking the URL preview most phone cameras show before opening a link, and avoiding entering payment or login details on a page reached through a QR code in an unfamiliar public location are all reasonable precautions.

What long-term support actually looks like

A good first impression doesn't guarantee good long-term support. Software updates, replacement availability, customer service responsiveness, and whether the company behind a product is likely to still be around in a few years all matter more than they get credit for at the point of purchase.

That's a harder thing to research than specs or price, but it's often the more important number in cybersecurity & privacy, where a product's usefulness a year or two in depends heavily on whether it's still being maintained. We go deeper on this in phishing scams.

What to look for if you're evaluating this yourself

If you're trying to decide how much weight to put on any of this, it helps to look past the top-line claim and ask a few concrete questions: what does it actually cost, who benefits most from it, and what happens in the cases where it doesn't work as advertised.

It's also worth checking whether the claims being made are specific and testable, or vague and aspirational. Specific, falsifiable claims are usually a better sign than confident-sounding generalities, regardless of how polished the presentation is or how it's framed within threats & scams.

Where this is headed

The current state of things is very unlikely to be the final one. This is an area that's still moving quickly, and what looks like a settled best practice today can look outdated within a year or two as the underlying tools, costs, and expectations shift.

That doesn't mean it's pointless to form an opinion now, just that it's worth holding it loosely. Keeping an eye on how threats & scams evolves, rather than assuming today's snapshot is permanent, is generally the safer bet.

How this plays out in practice

In day-to-day use, results tend to show up unevenly. Something can work brilliantly in one context and fall flat in another that looks superficially similar, which is part of why blanket claims about it (in either direction) tend to age badly. This fits within our broader Threats & Scams coverage.

The people who get the most out of this in threats & scams are usually the ones who treat it as a tool with specific strengths rather than a silver bullet. That means testing it against a real task, watching where it struggles, and adjusting expectations accordingly rather than taking either the hype or the skepticism at face value.

How it compares across the options on the market

Rarely is there a single dominant choice; there's usually a small cluster of options that each make different trade-offs between cost, performance, ease of use, and long-term support. The right pick depends heavily on which of those you weight most.

In cybersecurity & privacy especially, chasing whatever is labeled “best” in a headline is a weaker strategy than matching the options against your own actual constraints, since most “best of” rankings are written for a generic reader, not for you specifically.

Where people most often get this wrong

The most common mistake isn't picking the wrong option outright; it's skipping the step of defining what “right” would even look like before comparing anything. Without that, every comparison ends up anchored to whichever feature happens to be marketed loudest.

Slowing down just enough to name the actual requirement, before getting pulled into specs and rankings, is a small habit that consistently produces better outcomes in threats & scams than jumping straight to a recommendation. Something similar is playing out around two-factor authentication.

How to read reviews and recommendations critically

Any single review, including this one, reflects one set of priorities and one use case. A glowing recommendation from someone with different needs, budget, or tolerance for friction may simply not transfer to your situation, even if the underlying facts are accurate.

The more useful approach in threats & scams is to look for the specific reasoning behind a recommendation, not just the verdict, and check whether that reasoning actually applies to your own circumstances before treating it as an instruction.

The bottom line

None of this means the answer is a simple yes or no. The more useful stance is somewhere in between: understand roughly how things work, know what's good and bad about them, and make the call based on your own situation rather than someone else's summary of it.

That's a less satisfying takeaway than a clean verdict, but it's a more durable one. Threats & Scams tends to reward people who stay curious about the details a little longer than the average headline encourages, and “QR Code Scams” is worth revisiting once you've had a chance to see it play out in your own use.