A QR code on a parking meter or a mailed letter can send you to a fake site that steals your bank login

Dziewczyna korzystająca z parkometru z panelem fotowoltaicznym w Tomaszowie Mazowieckim

Quick-response codes, the little square grids scanned with a phone camera, now sit on restaurant tables, parking meters, package labels, and mailed flyers. Their convenience is exactly what criminals exploit. A code reveals nothing about where it leads until the phone has already opened the link, and scammers have learned to hide a fake banking site behind a square that looks completely ordinary.

How a poisoned QR code steals a bank login

The tactic has earned the nickname “quishing,” a blend of QR and phishing, and it sidesteps a habit most people rely on to stay safe. When a suspicious link arrives as plain text, a cautious reader can study the web address, notice a misspelled company name, and decline to click. A QR code hides that address inside a pattern the human eye cannot read, so the usual gut check never happens until the browser is already loading a counterfeit page.

That counterfeit page is the whole point. It is built to mimic a real bank, retailer, or government portal down to the logo and color scheme. An account holder who types a username and password into the spoofed site hands those credentials straight to the criminal, who can then drain the account or sell the login. Some malicious codes go a step further and install software that quietly harvests information from the phone itself. Because the fake page can also relay a login straight to the real bank in the background, the victim may even see their genuine account load normally, never suspecting that the password was captured on the way through.

The Federal Trade Commission, in a consumer alert on the scam, has documented thieves pasting their own codes directly over legitimate ones on public parking meters, and mailing or texting codes wrapped in an invented reason to scan, such as a package that could not be delivered or an account that supposedly needs confirming. The common thread is a manufactured sense of urgency designed to make a person scan before they think.


Free retirement updates: Scam calls targeting retirees change every week. Our free Retirement Shield newsletter flags the ones going around and the one tell that stops each. Sign up free.

Where the fake codes turn up

Public surfaces are a favorite because they invite legitimate scanning. A parking meter, a bike-share dock, or an electric-vehicle charger that expects a scan gives a criminal a perfect place to layer a sticker on top. Mailed letters are another growing avenue: a code printed on official-looking stationery, framed as a way to claim a refund, settle a bill, or verify a benefit, lends the scam the credibility of physical mail.

Older adults can be especially exposed to the mailed version. A letter that references Social Security, Medicare, a utility, or an unpaid toll and offers a code to “resolve it quickly” borrows the authority of an agency the recipient trusts. The code, of course, leads nowhere near the real institution. Because the envelope arrived by post rather than a spam folder, it can feel more official than it is. Unpaid-toll and delivery-reschedule texts carrying a code work the same way, borrowing the look of a service the recipient genuinely uses so the demand to scan seems routine.

The habits that defeat quishing

The strongest safeguard is to treat an unexpected QR code the way one would treat an unexpected link. If a code turns up in a place it does not belong, or arrives with a story urging immediate action, the safest move is not to scan it at all. When a scan seems warranted, most phones display the destination web address for a moment before opening it, and that preview deserves a careful look for misspellings, extra words, or a domain that does not match the real company.

The FTC’s guidance points to a reliable rule: rather than trusting a code to reach a bank or agency, a person should navigate there independently, by typing the known web address into a browser or calling a number printed on a prior statement. A payment or login page reached through a code from a meter or a mailer should be regarded as unverified until the underlying address is confirmed by hand.

What to do after scanning a suspect code

Anyone who scanned a code and entered a password should change that password immediately and, if the same one is used elsewhere, update it on those accounts too. Turning on two-factor authentication adds a barrier even if a login was exposed. If financial details were typed in, contacting the bank or card issuer to watch for fraudulent charges is the next step, and a device that begins behaving strangely after a scan may need a security scan for installed malware. Reporting the scam to the Federal Trade Commission also helps regulators track where the poisoned codes are spreading and warn others in time.

QR codes are not going away, and most are perfectly safe. The danger lives entirely in the unknown destination hidden inside the pattern. A moment’s pause to ask where a code truly leads, and a refusal to scan the ones that arrive unbidden or plastered over a public fixture, keeps that hidden link from ever reaching a bank account.

This article was researched and drafted with AI assistance and reviewed against the linked primary sources.

More Financial Reading