Filenary
← Back to all articles

QR Codes Can Be Malicious — How to Check One Safely First

Published 2026-09-14

QR codes went from a niche marketing gimmick to genuinely everywhere — menus, parking payments, event check-ins, package tracking. That ubiquity is exactly what makes them a useful phishing tool: a malicious QR sticker placed over a legitimate one looks identical to the real thing until your phone opens it.

What 'QR phishing' (quishing) looks like

  • A sticker placed over a real QR code on a parking meter, leading to a fake payment page.
  • A QR code in an email that routes through a shortened link to a credential-harvesting site.
  • A code on a flyer or poster claiming to unlock a discount, actually installing something unwanted.

Preview before you open

Filenary's QR Scanner reads the code from an uploaded photo and shows you the raw content — usually a URL — without automatically opening it in your browser. That gap between scanning and clicking is exactly where you get to look at the domain and decide whether it's the one you expected.

A note on browser support

This tool uses the native BarcodeDetector API built into Chromium-based browsers (Chrome, Edge). Firefox and Safari haven't implemented that API yet, so scanning currently only works in Chromium browsers — the tool tells you clearly if your browser isn't supported rather than failing silently.

What to actually check

Once you see the decoded URL, look at the domain the same way you would in a suspicious email: does it match the business you expect, or is it a lookalike domain, a raw IP address, or an unrelated shortener?