Think Before You Scan: A Fake QR Code Can Lead to a Scam Website

QR codes are now almost everywhere. We use them to pay for food, open restaurant menus, access parking services, complete forms, and receive promotions.

All it takes is pointing your camera at the code and tapping the link that appears.

It is quick and convenient, but scammers have also started taking advantage of that convenience.

A fraudulent QR code can be placed over a legitimate payment code or delivered through a message, email, poster, or unexpected package. Once scanned, it may direct users to a fake website designed to steal passwords, card information, or personal data.

Scanning a QR code should therefore be treated like clicking any other link: check the destination before trusting it.

How Does a Fake QR Code Work?

A QR code simply stores information, including website addresses. The problem is that you cannot see its destination by looking at the pattern alone.

Scammers can create a code that opens an imitation website. The page may look almost identical to a bank, digital wallet, store, parking service, or another legitimate platform.

Victims may then be asked to:

  • Enter a username and password.

  • Provide payment card details.

  • Share a PIN or one-time password.

  • Download an application or file.

  • Send money to a different account.

Any information submitted through the fake page may go directly to the scammer.

You can also read our guide on how to recognize a fake website to help distinguish legitimate pages from imitations.

Inspect the Physical QR Code

Before scanning a QR code in a public location, examine its surface.

Check whether another sticker has been placed over the original code. Look for raised edges, different colors, fresh adhesive, or signs that the label has been replaced.

This is especially important when the code appears on:

  • Parking payment machines or signs.

  • Restaurant and cafĂ© tables.

  • Donation boxes.

  • Event posters.

  • Vending machines.

  • Payment counters.

If anything looks unusual, confirm the code with an employee or the business owner before paying.

Preview the Website Address

Most smartphone cameras display a preview of the address before opening it. Do not tap it immediately.

Check the following details:

  1. Is the domain name spelled correctly?

  2. Are there additional letters or spelling mistakes?

  3. Does the address contain a long and unusual series of characters?

  4. Does the domain belong to the company mentioned?

A scammer may replace the letter “o” with the number “0” or add official-looking words to make a fraudulent address appear trustworthy.

Remember that HTTPS and a padlock icon do not automatically prove that a website is legitimate. Scam websites can also use HTTPS.

Learn about common warning signs of phishing messages, especially when a QR code arrives with an urgent or threatening message.

Be Careful When Making QR Payments

When making a QR payment, do not rely solely on the printed code.

Use a payment application you trust and check the merchant name displayed after scanning. It should match the store, restaurant, company, or person you intend to pay.

Before entering your PIN or confirming the transaction, review:

  • The merchant or recipient’s name.

  • The payment amount.

  • The source of the QR code.

  • The transaction details.

If the recipient’s name does not match, cancel the payment and speak directly with the merchant.

For payments in Indonesia, official information can be found on the Bank Indonesia QRIS page.

Avoid QR Codes in Unexpected Packages

You may receive a package you never ordered and find a card containing a QR code with messages such as:

“Scan to discover who sent this package.”

“Scan to activate your reward.”

“Scan to return this item.”

Curiosity is often used to persuade people to open dangerous links. If you do not recognize the package, do not scan the code merely to identify the sender.

Contact the delivery company through its official application or manually typed website address instead.

Do Not Install Apps from Suspicious QR Codes

Be cautious when a scanned page asks you to download an application, particularly an Android APK file.

Applications obtained from unofficial sources may contain malware, steal messages, read notifications, or request access to sensitive information.

Download applications only from the Google Play Store, Apple App Store, or a verified official website.

Never grant accessibility, SMS, camera, microphone, or device administrator permissions to an application you do not recognize.

Never Share a PIN or One-Time Password

A legitimate company should not ask for your PIN or one-time password through a page that unexpectedly appears after scanning a QR code.

A one-time password can be used to access an account or approve a transaction. Giving it to another person may allow them to take control of your account.

You can add another layer of protection by following our guide on securing accounts with two-factor authentication.

What Should You Do After Scanning a Suspicious Code?

If you only opened the page and did not enter any information, close it immediately. Do not download files, install applications, or approve requested permissions.

Check your downloads folder for unfamiliar files. You should also update your phone and browser to the latest versions.

If you entered a password:

  1. Open the official application or manually type the correct website address.

  2. Change your password immediately.

  3. Change passwords on other accounts if you reused the same one.

  4. Enable two-factor authentication.

  5. Sign out of unfamiliar devices or sessions.

If you provided payment information or completed a transaction, contact your bank or payment provider through its official number immediately. Temporarily freeze your card or account if that option is available.

Read what to do after giving information to a scammer so you can secure your accounts as quickly as possible.

The 20-Second Check

Before scanning a QR code, complete this short check:

  • Look for a replacement sticker.

  • Identify who placed or sent the code.

  • Preview the website address.

  • Verify the merchant name and payment amount.

  • Never enter a PIN, password, or one-time code because of an unexpected request.

  • Never download an application from a suspicious page.

A 20-second check can prevent a problem that may take days or weeks to resolve.

Conclusion

QR codes are not something we need to fear. They remain useful and convenient when handled carefully.

The danger begins when we scan without checking the source, website address, or payment recipient.

The next time you scan a QR code, pause before opening the link. Examine the address, verify the merchant, and cancel the process if anything appears unusual.

Scanning may take only one second, but checking first can protect your accounts, personal information, and money.

Support My Work

If you found this article helpful and would like to support me in creating more content, you can support me through SAWERIA.

You can also explore my work and support me through LYNK.ID Every contribution means a lot and helps me continue sharing useful knowledge and creating new work.

Thank you for your support.

For you:

“Not every battle has to be won. Sometimes, simply surviving is enough. Let that perspective comfort you and protect you in the harsh world out there.”

“There is no single right answer in life. If there is one, it is to live according to your own decisions and beliefs—and to follow your heart.”

“Live the life you want. Follow your heart and build a life that brings you happiness.”

MAY YOU ACHIEVE EVERYTHING YOU HOPE FOR. AND MOST IMPORTANTLY, TAKE GOOD CARE OF YOUR HEALTH.

Comments

Popular posts from this blog

TIDAK BISA MAIN GAME HAGO DI IOS, coba cara ini!!!

THE ADVENTURES OF DONAT | Made from figma