QR-code-based mobile payments have grown quickly because they remove the need for physical card terminals and let a transaction happen with nothing more than a printed code and a phone. That convenience comes with a specific, well-documented risk: unlike a card terminal, a printed QR code can be physically tampered with by anyone who has a moment of unsupervised access to it. This article explains how that risk actually works in practice and what both businesses and individual users can do to reduce it.
The core risk: code substitution, not the QR format itself
It’s worth being precise about what’s actually risky here. The QR code format itself isn’t insecure — it’s just a way of encoding text, the same as a barcode. The risk in payment contexts comes from the fact that a printed code sitting on a countertop or window can be covered with a sticker containing a different, attacker-controlled code, redirecting a payment to the wrong account. This has been documented at parking meters, storefronts, and donation boxes in multiple countries. The failure isn’t in the technology — it’s in the fact that a static printed code, once put in a public place, can be tampered with by anyone who has thirty seconds alone with it.
What businesses accepting QR payments should do
The most effective mitigation is physical: check payment codes regularly for signs of tampering, particularly a sticker or overlay that looks slightly different in texture, alignment, or print quality from the surrounding signage. Where possible, display the code behind a protective covering (like a laminated sleeve or acrylic holder) that would be visibly damaged by an attempt to place a sticker over it. For higher-value or unattended payment points — self-service kiosks, parking payment signs — consider dynamic codes that change periodically through your payment provider’s system rather than a single static code printed once and left indefinitely.
It’s also worth training staff to notice and report anything unusual about a payment code’s physical condition, the same way they’d be trained to notice a tampered card reader. A quick daily visual check of any customer-facing payment code takes seconds and closes off the most common version of this attack.
What individual users should check before scanning a payment code
A few habits meaningfully reduce risk on the customer side:
- Look before you scan. If a code looks like it’s printed on a different material, sticker stock, or slightly misaligned compared to the surrounding sign, treat that as a red flag.
- Check the preview before confirming. Most modern scanning apps and phone cameras show the destination URL or payment recipient before completing an action — read it. If it doesn’t match the business you expect, don’t proceed.
- Be extra cautious with unattended payment points. Parking meters, donation boxes, and unstaffed kiosks are the most common targets for code substitution because there’s no one nearby to notice tampering.
- Prefer official apps for recurring payments. If you pay the same vendor regularly, a dedicated app or saved, verified payment method avoids re-scanning a public code each time.
Phishing via QR code (“quishing”)
Beyond payment-specific tampering, QR codes are increasingly used in phishing attempts — a code embedded in an email or physical flyer that leads to a convincing fake login page rather than a real service, aiming to harvest credentials rather than payment details directly. The same core defense applies: check the destination before entering any information, and be skeptical of QR codes that create urgency (“scan immediately to avoid account suspension”) arriving through unexpected channels like unsolicited mail or flyers.
How this affects the codes you generate yourself
If you’re a business generating your own payment or account-related QR codes rather than receiving codes from a third party, the main responsibility shifts to protecting the physical placement, as covered above, and to making sure the destination itself uses HTTPS and clearly identifies your business, so a customer checking the preview URL before scanning has an easy way to confirm it’s legitimate. This is also a good reason to avoid routing payment-adjacent QR codes through generic, unbranded link shorteners, since an unfamiliar shortened domain in the scan preview gives customers less to verify against.
What this doesn’t mean
None of this is a reason to avoid QR payments altogether — the same tampering risk exists, in different forms, for card skimmers and fake card readers, and mobile payment systems generally include their own fraud protections and dispute processes on top of the physical code layer. The point is that QR payment security is mostly a physical-world problem layered on top of a digital one, and the mitigations are correspondingly practical: look closely, check the preview, and treat unattended payment points with a bit more scrutiny than a staffed register.
If you’re setting up a QR code for something other than payments — a menu, a contact card, a Wi-Fi network — the risk profile above doesn’t apply in the same way, but the underlying habit of checking a destination before trusting it is worth keeping regardless. You can build your own code with our free QR code generator, or read our QR code best practices guide for general placement and design guidance.
Free, unlimited, and it takes about ten seconds.