ARYXTOOLS

Free Online Tools

ARYXTOOLS

QR Code Scams Are Rising in 2026: How to Tell a Safe Code From a Malicious One

What the FBI and FTC have actually warned about in 2026, how quishing scams work, and the one habit that stops most of them before they start.

·6 min read

A QR code on a restaurant table, a parking meter, or the bottom of a flyer gets scanned without a second thought, because reading the destination before tapping it is far less natural than it is with a regular link. That gap between habit and scrutiny is exactly what a new wave of scams in 2026 has been built around, and both the FBI and the FTC have put out formal warnings about it this year.

None of this means a QR code is dangerous by nature. It is a container for a web address, nothing more, and the vast majority scanned every day lead exactly where they claim to. The risk is narrow and specific enough to guard against once you know what it looks like.

What the warnings say

The FTC published a consumer alert in September 2026 describing reports of scammers placing a fake QR code sticker directly over a real one on a parking meter, routing payment straight to the scammer instead of the city. Its advice is specific: many QR reader apps preview the destination link before opening it, so read that preview the same way you would check a suspicious link in an email, for misspellings or a domain that does not match.

Separately, the FBI issued a FLASH alert on January 8, 2026, describing a spearphishing campaign that used QR codes embedded in email to target people at NGOs, think tanks, and government offices, with the code leading to a fake login page built to steal credentials along with device details like IP address and location. Microsoft's own threat intelligence team tracked a 146 percent increase in QR-related phishing emails aimed at Microsoft 365 users between January and March 2026, a count of attack emails, not confirmed victims, but a real and independently measured rise over a short stretch either way.

Worth saying plainly: a lot of the more dramatic statistics circulating about QR scams cannot be traced back to any original study. Stick to what the FBI, the FTC, and threat intelligence teams have published rather than repeating an uncredited number, and the picture is still concerning enough to take seriously.

The pattern behind most of these scams

A QR code moves the attack onto a phone, often a personal one, stepping around the spam filters and link-scanning tools that protect a work email inbox on a computer. That is the structural reason attackers reach for a QR code at all: the exact same fake login page is far more likely to go unfiltered once it is opened on a phone instead of clicked straight from an email.

A sticker over an existing code on a parking meter or a public sign is one variant. A QR code inside an unexpected email or text, usually paired with urgency, a missed package, a locked account, a suspicious login, is another, and it is the one the FBI's January alert described in detail. A newer twist involves an unsolicited package arriving with no return address and a QR code inside inviting you to scan it to find out who sent it, which both agencies have separately flagged as a variant of the older "brushing scam."

The one habit that stops most of these

Read the link before you open it. That single step, repeated by both the FBI and the FTC across every alert, catches the majority of these attempts, since a spoofed domain rarely survives being read carefully. Treat an unexpected QR code the same way you would treat an unexpected link: do not scan one from a message you were not expecting, especially one pushing urgency, and never enter a password or payment details on a page you reached by scanning a code you did not fully trust going in.

Making your own code is a different situation

The risk above is about scanning someone else's code. Generating your own with the QR Code Generator is a different direction entirely, since you are the one choosing the destination. A code you made yourself, for a menu, a business card, or a link to your own profile, points exactly where you typed it to point. The safety in that case comes from you controlling the link, not from anything about the code itself, which is the same reason a link you typed yourself is safer than one someone else sent you.

If you already scanned one

If the page asked for a password and you entered one, change it immediately, on that site and anywhere else you reused it, and keep an eye on the account for anything unfamiliar. The Password Generatormakes a fresh, random replacement faster than trying to come up with one by hand. If a payment went through, check your card or bank statement for anything you do not recognize. Either way, the FTC takes reports at ReportFraud.ftc.gov, and the FBI's Internet Crime Complaint Center takes them at IC3.gov. Reporting it does not undo the scam, but it is exactly how agencies track which variants are spreading right now.

Common questions

Quishing is QR code phishing: a scammer hides a malicious web address inside a QR code instead of sending it as a clickable link. The destination can be a fake login page, a page that asks for payment details, or a page that quietly installs malware, and none of that is visible until after the code gets scanned.

Specific numbers vary by source and are worth treating carefully, since several widely shared statistics about quishing cannot be traced back to an original study. What is well documented is the FBI and FTC both issuing formal alerts in 2026, and Microsoft's own threat intelligence team recording a real rise in QR phishing emails aimed at Microsoft 365 users over the same period. Whether or not a single eye-catching percentage holds up, the pattern across independent sources points the same direction.

Most phone cameras and QR scanner apps show a preview of the destination web address before opening it. Read that address the way you would read a link in an email: check it matches the business or site you expect, and look for misspellings or an unfamiliar domain. If the preview looks wrong, do not open it.

Usually, but the FTC has specifically warned about scammers placing a fake sticker directly over a real QR code in exactly those spots, since a parking meter or a table tent gets far less scrutiny than an email. If the code looks like a sticker rather than a code printed directly on the sign or menu, or if it is peeling at the edges, that is worth a second look before scanning.

If you entered login details or payment information on the page it opened, change that password immediately and watch the account for unfamiliar activity. If the code may have installed something, check your phone for unfamiliar apps and run a security scan. Either way, the FTC recommends reporting it at ReportFraud.ftc.gov, and the FBI's Internet Crime Complaint Center takes reports at IC3.gov.

Because a QR code moves the attack to a phone, often outside the spam filters and link-scanning tools that protect a work email inbox on a computer. The FBI's January 2026 alert on a North Korean phishing campaign described exactly this pattern: a QR code in an email pushes the target from a monitored work computer onto their personal phone, where the fake login page has a clearer run at stealing credentials.

The safety comes from you controlling the destination, not from the tool itself. A code you generate yourself points exactly where you typed, so anyone who trusts your business, your flyer, or your profile is trusting a link you chose on purpose, which is a different situation than scanning an unknown code stuck on a wall.

No. The QR Code Generator builds the code in your browser from whatever text or link you type, and nothing you enter is uploaded or saved.

More from the blog