A QR code is a shortcut to a link. Before opening it, check where it came from, look at the address shown by your phone and ask whether the page is requesting something you expected.

Most QR codes are ordinary and useful. They open restaurant menus, parking services, tickets, apps and sign-in pages. The difficulty is that you cannot see the destination by looking at the pattern. A fraudulent code can therefore hide a fake payment or sign-in page.
If a QR code leads to payment, a password request or an app download, use the organisation’s official app or known website instead.
Where extra care is worthwhile
A QR code deserves more scrutiny when:
- it appears on a new sticker covering a code on a parking meter, charging point, sign or payment machine;
- it arrives unexpectedly in an email, text message, letter or parcel;
- the message says you must act quickly to avoid a fine, failed delivery or closed account;
- the resulting page asks for a password, security code, card details or an app download; or
- the destination shown by your phone does not match the organisation you expected.
The National Cyber Security Centre says UK QR-related fraud has often involved public places such as stations and car parks, usually alongside manipulation by a scammer. It also warns that QR codes are increasingly used in phishing emails because they disguise the link and may not be examined by every email-security system.
Check the code before scanning
For a code attached to a physical object, look at the surrounding material. A raised edge, mismatched print, extra sticker or code placed over another one can indicate tampering. Compare it with nearby machines where possible.
Do not rely on appearance alone. A well-printed code may still be fraudulent, while a worn code may be genuine. If the code is for parking or payment and you are uncertain, use the provider’s official app or type a known address yourself.
A QR code inside an unexpected parcel deserves the same treatment as an unfamiliar link. The US Federal Trade Commission has warned about unsolicited parcels containing codes that claim to identify the sender or arrange a return but instead lead to phishing pages.
Pause at the address preview
Modern phone cameras normally show a destination before opening it. Read that preview rather than tapping immediately.
- Check for misspellings, added words and unusual endings.
- Make sure the organisation’s real name appears in the important part of the address—not merely elsewhere in a longer address.
- Be wary of shortened addresses when the code is asking for payment or sign-in details.
This check can identify some scams, but it is not proof that a page is safe. Criminals can use compromised websites, legitimate hosting services and convincing addresses. If the requested action matters, verify it independently.
Match the request to the situation
Consider what the code should reasonably need. A restaurant menu should not require your email password. A parking page should not ask you to install remote-control software. An unexpected delivery code should not need your bank sign-in details.
Urgency is another warning sign. Messages about an immediate fine, expiring parcel or suspended account are designed to hurry you. Close the page and check through a route you already trust.
Use an independent route for payment or sign-in
If a scanned code leads to a payment or login page:
- Close the page if you did not expect the request.
- Open the organisation’s official app, or enter its known website address yourself.
- Check whether the payment, delivery or account problem appears there.
- Use contact details from the official app, website, statement or the back of your bank card if you still need help.
Government QR codes are not automatically suspicious. HMRC publishes a list of letters that legitimately contain them and explains where its codes should lead. If an HMRC letter is not listed or the destination is unexpected, use GOV.UK to verify the contact rather than relying on the code.
You usually do not need a separate scanner app
The NCSC recommends using the QR scanner built into your phone. On current iPhones and Android phones this is normally available through the camera. Avoid installing an unfamiliar scanner solely because a message or website tells you to.
If you already scanned the code
Scanning or opening a link does not automatically mean someone has accessed your accounts. What to do next depends on what happened.
You saw the preview but did not open it
Dismiss the preview. No account-recovery action is normally required solely because the camera recognised the code.
You opened the page but entered nothing
Close it. Do not download anything or accept requests to install an app, configuration profile or browser extension. Keep your phone and browser updated. If the device behaves unexpectedly afterwards, follow our guidance for a device that may be infected.
What to do if your device may be infected.
You entered a password or security code
Open the genuine service directly and change the password immediately. Change it anywhere else you reused it, review recent sign-ins and turn on an extra sign-in check. Contact the provider if you cannot access the account.
What to do after sharing a password or security code.
You entered card or bank information, or sent money
Contact your bank or card provider immediately using its official app or the number on your card. Tell the bank exactly what you entered or authorised. If money was sent, ask it to consider the payment under the relevant scam-reimbursement rules.
Read about scam-payment reimbursement rights and immediate steps.
You installed an app or gave someone control
Disconnect the device from the internet if somebody may still have remote access. Contact your bank from another trusted device if financial accounts were used. Remove the app only after preserving any details you may need for reporting, and seek help if you are unsure what access was granted.
Report the code or message
- Forward suspicious emails to report@phishing.gov.uk.
- Forward suspicious text messages to 7726; it is free.
- Report a suspicious website through the NCSC reporting service.
- Tell the operator when a code on a parking meter, sign or other public object appears to have been replaced.
- If you lost money in England, Wales or Northern Ireland, report it to Report Fraud after contacting your bank. In Scotland, contact Police Scotland.
The point to remember
A QR code is only a route. Check the destination and the request before deciding whether to continue.
Authoritative guidance
- National Cyber Security Centre: QR codes—what’s the real risk?
- National Cyber Security Centre: phishing prevention, recovery and reporting
- HMRC: check whether a QR code on a letter is genuine
- HMRC: recognising scam contact and QR-code limitations
- US Federal Trade Commission: unexpected parcels and QR-code phishing
- GOV.UK: report suspicious emails, texts and websites
Last reviewed: 28 August 2026. This is general online-safety guidance. A familiar address or untampered code cannot guarantee that a destination is safe.