The attacks that actually happen
Sticker swaps on parking meters and EV chargers, harvesting card details on cloned payment pages. Fake 'Wi-Fi login' codes in cafés leading to phishing pages. Codes in emails ('your parcel fee') that bypass spam filters because the bad link is inside an image. Fake codes on restaurant tables replacing the real menu code with a payment page.
Notice the pattern: every attack needs you to take an action — enter details, approve a payment, log in. The code itself never harms you.
If you print codes for the public
Businesses are the other side of this. If you display codes where customers pay or log in, use tamper-evident labels, inspect them regularly, and print the destination domain next to the code ('scans to pay.yourcouncil.gov') so customers can verify. Framing your codes with your branding also makes a bare sticker swap visually obvious.
Checking a code you don't trust
The scanner on this site decodes a code from a photo and shows the raw content without opening anything — the safest way to inspect a suspicious code. What to look for in the decoded URL: lookalike spellings, unexpected URL shorteners, domains that have nothing to do with the organisation in front of you.
QR codes versus NFC: the same risks, one difference
NFC tags — the tap-to-pay and tap-to-open chips in posters, payment terminals and product labels — are often discussed together with QR codes, and the threat model is nearly identical: the tag holds a small payload, usually a link, and the danger is what you do on the page it opens. A rogue tag stuck under a genuine poster is the NFC equivalent of a sticker over a code. Modern phones show you the link before opening it for both.
The one real difference is visibility. A QR code is printed and can be inspected, photographed and decoded before you act; an NFC tag is invisible and can be hidden under any surface, and phones read it the moment they touch. That's why payment terminals and public tap points deserve the same caution as parking-meter codes: if a tap opens a page asking for details you didn't expect to give, walk away. Contactless card payments themselves are protected by the card's own cryptography — the risk is the fake page, not the tap.
The eavesdropping attacks written about in early NFC research — intercepting, corrupting or inserting data between two devices — require an attacker within a few centimetres with specialised equipment, and are impractical against today's encrypted payment protocols. In practice, both technologies fail the same way: a human enters credentials on a page they shouldn't trust.
Mistakes to avoid
- A code in an unexpected email or text is phishing-bait until proven otherwise.
- Don't assume 'it scans, so it's official' — printing a sticker costs pennies.
- Never log in or pay on a page reached from a code you weren't expecting.
Common questions
Can a QR code contain a virus?
No. It can only contain data — usually a link. The danger is always what you do on the page it opens.
Is scanning a code enough to get hacked?
Simply decoding and even opening a link is very low risk; harm requires you to enter details or install something.
How do I check a code safely?
Photograph it and decode it with our scanner — you read the destination without opening it.
Are codes on this site safe to use commercially?
Yes — they're static, with no redirect through us, so scans go straight to your destination with nobody in the middle.