Skip to content
Digital Safety

// article

How to Use QR Codes Safely in Public Places

Simple steps to inspect a QR code, destination link, and payment request before scanning or opening it.

5 Jun 2026 4 min read
How to Use QR Codes Safely in Public Places

// statistical data

Real statistics for this topic

Verified sources

Phishing, social engineering, QR traps, and messages that pressure you into split-second decisions: the numbers are stark.

Figures are summarized from public reports. Use the source links to review methodology, geography, and reporting period.

A QR code hides its destination. Your eyes cannot read where it leads until the phone processes it. That is what makes QR codes so handy and so dangerous at once: one sticker placed over a real QR code can send you to a fake payment page or a malicious app download.

Why public QR codes are risky

Attackers stick a fake QR sticker over the real one on a parking sign, a restaurant table, or a donation box. The victim scans it, sees a page that looks legitimate, then pays into the attacker's wallet or enters credentials. Because a QR does not reveal its URL before scanning, caution has to come before the scan, not after.

Practical steps to use QR codes safely

Work from a visual check to a final decision. Each step takes only seconds.

1. Inspect the QR visually before scanning

Look for a sticker placed over the QR, whether the surface is smooth, and whether it is printed with the official poster or seems added later. A sticker that sits slightly crooked or is a different material is a sign the QR was covered.

2. Use a scanner that shows the destination URL

Use the built-in camera or a scanner app that displays the destination address before opening it. Avoid scanners that forward straight to the browser without showing the link. The URL gives you a chance to judge.

3. Assess the address before opening it

Check the domain: is it official, spelled correctly, and using https. Watch for look-alike domains with typos such as g00gle or amaz0n. If unsure, do not click. Type the official address into the browser manually instead.

4. Do not pay or log in straight from a QR

A payment or login page that appears from a QR needs a second check. Compare the recipient name and destination number with the official one. Do not enter an OTP, PIN, or credentials into a page that pops up unexpectedly from a QR.

5. For important transactions, use the official app

Pay for parking, buy tickets, or donate through an official app you already installed from the app store, not from a random QR link. Official apps verify the recipient internally and are far harder to fake.

Example: a parking QR covered by a sticker

At a parking lot, a rider scans the QR at the gate to pay. What opens is an e-wallet page with the recipient name "Official Parking" and an unfamiliar number. They pay the rate. Days later, the parking operator reports the real QR was covered by a sticker. Checking the recipient name and number, or paying through the official parking app, would have saved the money.

If you scanned a suspicious QR

Do not enter anything on the page that opened. Close the tab and, if unsure, clear the download history or force-close the app. If you did enter credentials, change the related account password from a trusted device and turn on 2FA. Watch your e-wallet and bank transactions for foreign activity.

Common mistakes to avoid

  • Scanning QR codes from posters promising prizes. A free prize is a classic lure to a malicious page.
  • Opening a link without reading the URL. A few seconds reading the domain can prevent a large loss.
  • Sharing an OTP that a QR page requests. A legitimate service does not ask for your OTP to "verify a payment".

Frequently asked questions

Can a QR code be dangerous?

Yes. A QR only stores text, usually a URL, and the destination can be anything, including a scam page.

Which scanner is safest?

One that shows the destination URL and asks for confirmation before opening. The built-in phone camera is usually enough.

Are restaurant menu QR codes safe?

Most are safe, but still check whether a sticker has been placed over it and whether the menu domain makes sense before ordering.

Sources and further reading

Editorial note: This article is educational and defensive. QR behavior differs between payment apps. Use your provider's official guidance.

About the author

Syukra
SyukraIndependent Cybersecurity Researcher

Saya riset threat intelligence dan hardening. Saya pakai Microsoft DR, Verizon DBIR, FBI IC3, ENISA sebagai sumber primer. Saya uji panduan di perangkat saya.

Comments

comments powered by Disqus