24 September 2026 · By Brett Casterton

QR code scams: how to spot a sticker that’s after your card details

QR code scam showing a fraudulent sticker applied over a genuine parking payment code.
The last thirty centimetres of the payment journey — a printer and a sticker are all it takes.

Last week we covered passkeys and the login codes Microsoft is retiring. This week is a scam that needs no technology at all — just a printer, a sticker and somewhere busy.

“Why hasn’t my £20 donation arrived?”

A Greater Manchester charity called us last month after a long-standing supporter rang to ask why her £20 donation had never arrived.

She had scanned the QR code on one of their fundraising posters in a shopping centre and paid on her phone. The money left her account. It never reached the charity.

Someone had printed a sticker and placed it over the real code. The poster itself was untouched and looked completely normal. The payment page that opened carried the charity’s name and logo, lifted straight from their own website.

Nothing was hacked. No system was breached. A criminal with a printer had simply redirected the last thirty centimetres of the journey.

For the charity, the damage was not just the missing donation. It was a supporter who now hesitates before giving, and a fundraising team who had to check every poster they had in circulation.

If your organisation displays a QR code anywhere the public can reach it, somebody else can cover it.

Why this matters

Bar chart showing Action Fraud quishing reports rising from 100 in 2019 to 1,386 in 2025, a fourteen-fold increase.
Fourteen times more reports in six years — and the number keeps climbing.

The fix

Everything you learned about fake websites applies here, with one extra difficulty: you cannot read a QR code with your eyes, so you cannot check where it goes before you scan. That makes the physical check the important one. Is this code part of the sign, printed into it — or is it a sticker sitting on top?

Scan with the camera app your phone came with rather than a downloaded QR reader, since third-party scanner apps add their own risk of malware and misleading adverts. Your camera will preview the web address before it opens anything. Read that preview. If it isn’t the organisation you expected, stop. The NCSC’s phishing guidance is worth ten minutes of anyone’s time.

Three quick wins you can act on this week

🏠 At home

Before scanning anything in public, look at the code itself. A sticker placed over an existing code, sometimes slightly at an angle or peeling at a corner, is the classic sign. In open spaces like car parks the risk is higher than in a pub or restaurant, simply because it’s easier for someone to tamper with unattended.

🏢 At work

Audit your own QR codes. Donation posters, table menus, reception signage, parking instructions, event flyers — anywhere the public can physically reach one. Check them on a schedule, print codes into artwork rather than applying them as stickers, and tell staff who to report a suspected fake to.

🌍 For everyone

Prefer another payment route. Contactless, a card reader, or an official app downloaded from your phone’s app store are all safer than a code on a machine. If you must scan, read the address preview, and never enter card details on a page you reached by scanning something in the street.

If you think you’ve scanned a fake

Act quickly and in this order:

  1. Stop entering information and close the page.
  2. Screenshot the web address and note exactly where the code was.
  3. Call your bank on the number printed on the back of your card.
  4. Report it to Action Fraud, and tell the council or venue so the sticker gets removed.

How the payment options compare

Honest comparison — the routes in most common use, and how easy each is for a criminal to intercept.

How you pay Risk of a fake intercepting you Notes
Contactless or chip and PIN ✅ Lowest No web page involved at all
Official app from the app store ✅ Low Downloaded by you, not by a link
Typing the address from the sign ✅ Low You control where you land
Scanning a QR code printed into the sign ⚠️ Moderate Still check the address preview
Scanning a QR sticker applied on top ❌ Highest Treat as untrusted until proven otherwise

What this looks like locally

We work with charities, accountancy practices, law firms and manufacturers across Denton (M34), Ashton-under-Lyne (OL6), Stockport (SK1) and Trafford (M33). Quishing is the rare scam where the fix is partly physical: walk round your own premises, look at every QR code a member of the public could touch, and ask whether you would spot a sticker over the top of it. Most people find at least one they would not.

If you’d like this built into how the practical parts of your security are run — staff awareness, payment verification and the boring checks that stop a convincing scam from working — it’s all part of a SecureState review.

Frequently asked

What is quishing?

Phishing carried out through a QR code. Scanning it takes you to a fraudulent website — often a payment page — rather than the legitimate one you expected.

How can I tell if a QR code is fake?

Look for a sticker applied over an existing code, placed at a slight angle, peeling, or lacking the branding and instructions around it that the genuine sign has.

Is it safe to scan QR codes in restaurants?

Generally safer than in open public spaces, because codes indoors are harder to tamper with unnoticed. Still check whether the code is printed into the menu or stuck on.

Should I use a QR scanner app?

No. Use the camera app your phone came with. Third-party scanner apps increase the chance of malware or misleading adverts, and your camera already previews the address.

What do I do if I’ve paid through a fake QR code?

Call your bank immediately using the number on the back of your card, report it to Action Fraud, and tell the venue or council so the sticker can be removed.

How do I protect my business’s own QR codes?

Print codes into your artwork rather than applying stickers, check public-facing codes on a regular schedule, and give staff a clear route to report anything that looks added.

“This is the rare scam where the fix is physical. Walk round, look at your own codes, and ask whether you’d notice a sticker on top of one.” — Brett Casterton, Inology IT
Want a second pair of eyes on how your business handles payments and scams?

Let’s tighten up the practical stuff before a convincing scam gets through.

I’m Brett at Inology IT. We help Greater Manchester businesses and charities tighten up the practical stuff — staff awareness, payment verification, and the boring checks that stop a convincing scam from working. Drop your details below and I’ll come back to you the same day.

We’ll never sell your details. See our privacy policy.

Last reviewed by Brett Casterton, September 2026.

← Back to Weekly Tech Tips

Inology IT — managed IT support for businesses across Greater Manchester, headquartered in Tameside.