The square black-and-white code has become part of everyday life — scan it to see a menu, pay a meter, or track a package. That convenience is exactly what scammers are exploiting. A fraudulent QR code slapped over a real one, or printed on a fake notice, can send a phone straight to a counterfeit website built to capture bank logins and card numbers. Because a code hides where it leads until it is scanned, an older adult can be handing over account access without ever seeing the trap.
What “quishing” is and why the code hides the danger
Security experts call it “quishing” — phishing carried out through QR codes. The mechanics are simple and that is the point. A QR code is just a link in visual form, and a person cannot read it with the naked eye the way they might notice a suspicious web address in an email. Scanning it opens the destination immediately, so any warning signs a careful reader would normally catch in a URL are skipped over entirely.
According to the Federal Trade Commission, that hidden destination is often a lookalike website designed to harvest card numbers and banking credentials, or a page that quietly installs malware on the phone. The victim believes they are paying a bill or claiming a refund; in reality they are typing their login into a fake page controlled by criminals.
Free retirement updates: Scam calls targeting retirees change every week. Our free Retirement Shield newsletter flags the ones going around and the one tell that stops each. Sign up free.
Where the fake codes turn up
Two setups are especially common. The first is a physical sticker: a scammer prints a QR code and places it over a legitimate one, on a parking meter for example, so a driver trying to pay for parking scans the fraudulent code instead. Everything looks official because the code is exactly where a real one belongs.
The second arrives on paper or in a message. Fake package-delivery notices, toll bills, and “refund” letters carry a QR code and urge the recipient to scan it to reschedule a delivery, settle a small toll, or claim money supposedly owed. The FTC points to these unexpected notices as a frequent delivery method, because the promise of a refund or the worry about a missed package pushes people to scan before they think.
Why retirees have money directly at risk
The goal of a quishing attack is financial access, which is what makes it costly. A fake site that captures a banking login hands a criminal the keys to a checking or savings account, and card numbers entered on a counterfeit page can be used for fraudulent charges. For a retiree whose accounts hold the savings meant to cover years of expenses, the exposure is not abstract — it is the balance that pays for housing, medicine, and groceries.
The “refund” version is particularly pointed at older adults, because the offer of money back plays on the sense that a legitimate reimbursement might really be waiting. The scanned code leads not to a refund but to a form that collects the very details needed to drain an account.
How the FTC says to scan safely
A few habits close off most of the risk. Before scanning a code in public, the FTC advises inspecting it for a sticker placed over another code — a peeling edge, a raised layer, or a code that does not match the surrounding surface is a signal to stop. On a parking meter or similar terminal, paying through the official app or by card at the machine sidesteps a tampered code altogether.
When a code does get scanned, the phone usually shows a preview of the web address before opening it, and that preview deserves a look: a misspelled or unfamiliar domain is a reason not to proceed. The FTC also warns against scanning codes that arrive in unexpected messages or notices, since a real business rarely forces a person to scan a code to handle a delivery, a toll, or a refund. When in doubt, contacting the company directly through a number or website found independently — not through the code — confirms whether anything is actually owed.
Locking down the accounts a fake site targets
Because quishing aims at logins, strong protection on financial accounts limits the damage if a credential is exposed. The FTC recommends using strong authentication — such as a one-time code from an authenticator app or a second verification step — so that a stolen password alone is not enough to get into a bank or brokerage account. Keeping a phone’s software updated helps guard against the malware some fake codes try to install.
The underlying rule is worth carrying anywhere a code appears: a QR code is an unlabeled link, and it deserves the same caution as a link from a stranger. Pausing to check the source, previewing the destination, and refusing to scan codes from unexpected messages keep a moment of convenience from turning into a compromised bank account.
This article was produced with AI assistance and reviewed by The Financial Wire editorial team.
More Financial Reading
- How many CDs can you park at 1 bank? FDIC rules you must know
- The ideal retirement withdrawal rate so your savings actually last



