QR codes

What is QR phishing?

Attackers place malicious QR codes that open fake login or payment pages. Always preview the destination before authenticating or paying.

What this means for you

This guide helps you act carefully with incomplete information—without pretending one signal is enough.

Detailed explanation

Attackers place malicious QR codes that open fake login or payment pages. Always preview the destination before authenticating or paying.

Fraudly focuses on clear signals and decision support. Always combine automated checks with your own verification when money or credentials are involved.

For Fraudly’s scoring approach, see the Trust Methodology.

Warning signs and signals

  • Pressure to act immediately
  • Requests to move money or share codes
  • Brand and domain mismatches
  • Unusual payment rails for the context

Practical verification steps

  1. Pause and verify through a known official channel
  2. Inspect the URL or QR destination before authenticating
  3. Prefer buyer-protected payment methods
  4. Use Fraudly’s website check when a link or shop is unfamiliar

What Fraudly can and cannot verify

Fraudly cannot guarantee outcomes or reverse payments.

Educational guidance is not legal, financial, or law-enforcement advice.

Key trust concepts

  • HTTPS does not prove legitimacy

    HTTPS encrypts the connection. It does not prove who runs the site or that the offer is genuine.

  • Urgent payment pressure is a social-engineering signal

    Real organisations rarely demand immediate payment with threats or secrecy.

Reviewed: 4 August 2026

This page is educational decision support. It is not legal, financial, or emergency advice.

How Fraudly assesses trust

What is QR phishing? — Fraudly Trust Knowledge | Fraudly