Are QR code payments safe? How to spot a fake code
QR code payments are safe when the code leads where it should. How QR scams work, how common they are in 2026, and how to make your own code hard to fake.
A QR code is a web address drawn as a grid of squares. Nothing more. Scanning one is like tapping a link a stranger handed you. So skip "is this QR code safe?" Ask where it goes, and who put it there.
This guide is for both sides of the counter. If you pay by scanning, you'll learn what a fake code looks like and what to check in the five seconds before you pay. Take payments with a code? You'll learn how to make yours hard to tamper with and easy for a customer to check before they pay.
Are QR code payments safe?
Yes, when the code opens a real checkout. A legitimate payment page runs on a known processor and shows who you're paying and the exact amount. It asks for a card or a phone wallet. That's all.
The weak point is the code itself. Nobody can read a QR code by eye, so a swapped code looks exactly like the original. Scammers count on that. They don't break into the payment system at all; they put their own code where yours should be and wait for someone to scan it.
So the risk is real but narrow. A few habits cover most of it.
How common are QR code scams in 2026?
Common, and climbing. Microsoft's threat researchers counted QR-code phishing attacks rising from 7.6 million in January 2026 to 18.7 million in March, a 146% jump. Codes embedded right in email bodies rose 336% in March alone, which tells you where the volume is.
Street codes get hit too. In January 2026, WRAL reported fake "Scan here to pay for parking" stickers on meters in Raleigh, North Carolina. The city said it uses QR codes only for violations and garage tickets.
The wider fraud numbers are large:
| Source | What it counted | Figure |
|---|---|---|
| FBI Internet Crime Complaint Center, 2025 | Reported losses | $20.9 billion, up 26%, from over 1 million complaints |
| FTC, 2025 | Consumer fraud losses | $15.9 billion across about 3 million reports |
| Federal Reserve household survey, 2025 | Adults who experienced fraud or a scam | 20% |
Now the gap. None of these totals separates QR codes from other scams, and Microsoft's count covers email, not stickers on a counter. Nobody measured how often a tip code gets swapped. So: habits, not panic.
What is quishing?
Quishing is phishing through a QR code. The code sends you to a fake page that asks for card details, a login, or an app download. Whoever runs it keeps what you type.
US agencies have warned about it more than once:
- Fake stickers on parking meters. In a December 2023 consumer alert, the FTC described scammers covering QR codes on parking meters with codes of their own.
- Tampered codes to steal funds. A January 2022 FBI public service announcement warned that criminals were tampering with QR codes to steal victims' money.
- Codes in unexpected packages. In January 2025 the FTC warned about packages nobody ordered that carry a QR code leading to a phishing site. The FBI followed in July 2025 with its own warning about unsolicited packages whose codes ask for personal and financial details.
See the pattern? Each code showed up somewhere unexpected. Or on top of something trusted.
How do you spot a fake QR code before you pay?
Look before you scan, then read before you pay. Most of what follows comes straight from published FTC and FBI advice, and none of it takes more than a few seconds.
- Look at the code. The FBI's first tip is to check that a physical code hasn't been tampered with, for example with a sticker placed on top. Run a finger over it. A raised edge or a second layer means stop.
- Read the address before it opens. Your phone camera shows a preview of the link. The FTC says to inspect the URL first when a code appears somewhere unexpected. Look for misspellings, extra words, or a domain that has nothing to do with the business.
- Check the page once it loads. The FBI advises confirming the site is the one you meant to reach. On a payment page, the name should match the person in front of you, and the amount should be what you agreed.
- Don't install anything. The FBI says not to download an app from a QR code, including a "QR scanner" app. Your camera already reads codes, and a real payment page works in the browser.
- Skip codes you didn't ask for. The FTC's advice is not to scan a code in an email or text you weren't expecting. Same for a code in a package you didn't order.
- Type the address yourself when you can. If you know a business's website, the FBI suggests going there directly instead of paying through a scanned link.
The FTC adds two habits that limit the damage if something slips through: keep your phone's software updated, and protect your accounts with strong passwords and multi-factor authentication.
Red flags at a glance
| What you see | Why it's a problem |
|---|---|
| A sticker on top of another code | The classic swap the FBI and FTC describe |
| An address that doesn't match the business | You may be on a copy of the real page |
| A request to download an app | A payment page doesn't need one |
| A login or password field | A guest checkout has no reason to ask |
| A different name than the person you're paying | Your money would go to someone else |
| A code in a text, email or package you didn't expect | The FTC's own example of when not to scan |
How do you make your own payment QR code hard to fake?
Make tampering obvious and give customers something to check. A swapped code hurts you too: the money meant for you goes to the scammer, and you may never find out.
- Check your printed codes every shift. Look at every sign, sticker and card when you start. Scan one yourself. Does it open your page?
- Make tampering visible. A code under a laminate or in a frame is harder to cover cleanly than a paper sign taped to a wall.
- Put your name next to the code. A sign that says, for example, "Scan to tip Sam, your stylist" gives a customer a name to match on the page.
- Show your name on the page. Turn on your name or photo wherever new customers pay.
- Print what the address looks like. One line such as "Opens a secure page at" followed by the domain gives careful scanners a reference.
- Show the code on your phone in person. Nobody can stick a label over your screen.
- Avoid codes that pass through someone else's link. Some free QR generators make "dynamic" codes that route every scan through the generator's own short link first. That puts a company you don't control between your customer and your page.
For placement that's easy to see and hard to reach with a sticker, see where to put your tip QR code.
How does tipme keep its QR payments trustworthy?
By putting the checks above on the page itself.
- One address, on tipme's own domain. Every tipme QR code opens a page at payment.tipme-app.com, followed by a short code for that page. Customers can check the domain in the camera preview.
- Codes that never change. Each page's link and QR code stay the same for as long as the page exists. Scan your sign and get anything else? Someone tampered with it. More on sharing with a QR code.
- No app, no account, no password. Customers pay in the browser with Apple Pay, Google Pay or a card. A page that asks them to install something or sign in isn't your tipme page.
- Your name where customers can see it. You choose whether a page shows your profile, and you set the name on the customer's card statement. See customizing your payment page.
- Card details never reach you or tipme. Stripe processes every payment, and tipme never sees or stores card numbers. The customer sees the exact total before confirming.
What tipme can't do is stop someone from sticking a fake code over your printed one. That part is on you. More on account protection is on the security page, and the QR code tipping guide covers setup and costs.
What should you do if you scanned a fake code?
Act fast, in this order.
- Stop. Close the page. Don't enter anything else.
- Call your card issuer if you entered card details or paid. Ask them to block the card and dispute the charge.
- Change any password you typed on the fake page, and turn on multi-factor authentication for that account.
- Tell the business. If the code was on their sign, they need to replace it before someone else scans it.
- Report it to the FTC and, if you lost money, to the FBI's Internet Crime Complaint Center.
If you're the worker and a customer says something odd happened, take the sign down right away and check every other copy of your code.
Frequently asked questions
The FTC and FBI warnings focus on where a code leads, not on the scan itself. The harm comes next, from a phishing page that collects your details or a link that pushes you to install malware. Read the preview. Decline downloads.
It saves you from typing card details into a page, which helps if that page turns out to be fake. Apple says Apple Pay helped prevent more than $1 billion in fraud in 2025. A wallet doesn't fix a swapped code, though. You'd still be paying whoever's page you landed on, so check the address and the name first.
No. Modern phone cameras read QR codes and show you the link first. The FBI specifically warns against downloading a scanner app from a QR code.
Not by editing it. The code holds your page's address. That address never changes, and edits to your page don't touch it. The realistic risk is someone covering your code with a different one, which is why regular checks matter.
Sources
- Microsoft Threat Intelligence, Q1 2026 email threat trends (April 2026)
- WRAL, report on fake parking QR codes in Raleigh (January 2026)
- CyberScoop, on the FBI Internet Crime Complaint Center's 2025 report (April 2026)
- PYMNTS, on FTC testimony about 2025 consumer fraud losses (March 2026)
- Federal Reserve, Survey of Household Economics and Decisionmaking, banking findings for 2025 (May 2026)
- Federal Trade Commission, "Scammers hide harmful links in QR codes to steal your information" (December 2023)
- Federal Trade Commission, "Scam alert: QR code on an unexpected package" (January 2025)
- FBI Internet Crime Complaint Center, "Cybercriminals Tampering with QR Codes to Steal Victim Funds" (January 2022)
- FBI Internet Crime Complaint Center, "Unsolicited Packages Containing QR Codes Used to Initiate Fraud Schemes" (July 2025)
- Apple Newsroom, Apple services 2025 year in review (January 2026)
- Stripe, "Security at Stripe" (accessed October 2026)
Get your own payment page
Free to sign up, no monthly fee. Your QR code and link are ready in minutes.