A QR code cannot infect your phone. It's a way of writing text — usually a URL — as a pattern of squares. It carries no code and executes nothing.
What it can do is take you somewhere dangerous without showing you where that is. That's quishing: phishing delivered by QR code. The attack isn't technical; it's that you can't read a QR code with your eyes.
→ Check where a link or QR code actually goes
How quishing works
- An attacker makes a QR code pointing at a page that impersonates something you trust — a bank login, a parking payment, a package-delivery notice, a Microsoft 365 sign-in.
- They place it where you'd expect a legitimate code: a sticker over the real code on a parking meter or restaurant table, an emailed "scan to verify your account", a fake invoice, a poster in a lobby.
- You scan, the page looks right, you enter credentials or card details.
Two things make it effective:
You can't preview the destination. With a link you can hover or read the URL. With a QR code you're trusting a pattern.
It bypasses email security. Corporate email filters scan links in message text. A QR code is an image, so a URL inside it often isn't inspected at all — which is exactly why quishing in email grew so quickly. The scan then happens on a personal phone, outside corporate protection entirely.
Where you'll encounter it
Parking meters and EV chargers. A physical sticker over the legitimate code — one of the most widely reported forms.
Restaurant tables. Fake menu codes leading to card-harvesting pages.
"Scan to verify" emails. Impersonating IT, payroll, or MFA enrolment. The most common corporate vector.
Delivery notices. A card through the door: "we missed you, scan to reschedule" — then a small fee to capture card details.
Conference and event materials. Stickers over legitimate signage.
Crypto payment requests. A swapped wallet address. Irreversible.
How to protect yourself
Look at the URL before tapping. Both iOS and Android show the destination as a preview before opening it. Read it. Most people don't, and that single habit prevents most quishing.
Check for a sticker. Physical tampering is the most common attack on public codes. Run a fingernail over the edge — a sticker has one.
Be suspicious of urgency. "Your account will be suspended", "final notice", "pay within 24 hours". Standard phishing pressure, same tells.
Never scan a code in an unsolicited email claiming to be from IT, your bank, or a delivery company. Go to the site directly instead.
Watch for lookalike domains. paypa1.com, microsoftt-login.com, rnicrosoft.com. A single swapped character is the entire attack.
Type it yourself for anything financial. Banking, payments, crypto — never arrive via a scanned code.
Check the link first if you're unsure. Paste it and see the real destination, safety verdict and domain age without visiting it.
Short links and the honest problem
Short links have the same weakness as QR codes: they hide the destination. in.bio/x7Kp2 tells you nothing about where you'll land. It would be dishonest for a URL shortener to write about link safety and skip this.
So, plainly: any link shortener can be abused for phishing, including ours. What differs is what the platform does about it.
What we do:
- Every destination is scanned for phishing and malware when the link is created, and rechecked periodically. Links that fail are disabled.
- Anonymous links expire after 30 days unless claimed with an account — this deliberately limits throwaway abuse.
- Every link has a public preview page that shows its destination without following it.
- Abuse reports are actioned. Report a link →
- We never store visitor IP addresses, so a compromised or subpoenaed link doesn't expose who clicked it. Why →
What we can't do: guarantee a page that was clean at creation stays clean. A legitimate site can be compromised later. That's why the ongoing destination check matters more than any single scan at creation time.
If you're evaluating shorteners and safety matters, ask two questions: does it scan destinations, and does it offer link previews? Several popular services do neither. We compared eight of them here.
For businesses printing QR codes
You have a reputational problem to manage, not just a security one — because when someone stickers over your code, your brand takes the blame.
Use your own domain. go.yourbrand.com/menu is verifiable at a glance; a generic short domain isn't. This is the single strongest defence.
Print the destination in text next to the code. "Scan or visit yourbrand.com/menu" gives people a way to verify, and an alternative if they don't scan.
Inspect public codes regularly. Anything unattended — table tents, window decals, meters, signage — should be physically checked on a schedule.
Watch your scan analytics. A sudden collapse in scans on one placement can mean somebody covered your code. Tracking scans →
Use dynamic codes so you can repoint instantly if a destination is compromised, without reprinting. How they work →


