You sit down at a cafe, point your phone at the square stuck to the table, and the menu loads.
Nobody thinks about it, and that habit is exactly what scammers have learned to use.
It starts with a sticker
The method is almost boring. Someone prints a QR code of their own and sticks it over the real one.
The café's systems aren't touched and nothing gets hacked. All that changes is where your phone lands after the scan. Stickers are cheap to print, and from a metre away a fake code looks exactly like the real one.
A QR code is only a web address drawn as a pattern of small squares. Scanning it works like tapping a link, except you can't read the address first. Security people call this scam "quishing", which is QR plus phishing, and phishing just means a fake page built to grab your passwords, card details or money.
Some of this is on record. New York City's transport department has warned that fake payment codes are turning up on parking meters, and Montreal's parking agency put up signs telling drivers not to scan the codes on its meters. The US Federal Trade Commission has also said scammers hide harmful links inside QR codes. Restaurant tables, hotel rooms and public flyers all show up in these warnings.
Be careful with one figure that gets repeated. A US cybersecurity strategist told a local TV station that more than 30% of phishing campaigns have moved to QR codes. That is one security firm's estimate, not an official count.
In India, UPI is the real target
Here the fake website matters less than the payment screen. Two versions come up again and again.
The first is the swap. A fraudster pastes their own payment code over the one at a shop, a roadside stall or a temple donation counter. You scan it, pay what you owe, and the money goes to a stranger.
The second is "scan to receive". A so-called buyer on OLX or WhatsApp says they'll pay you, but first you must scan the code they've sent. When you do, your UPI app opens a payment screen, and entering your PIN sends money out, not in. NPCI, which runs UPI, says scanning a code and entering a PIN is only for paying. Getting paid never requires either step. One news report described an OLX seller who lost ₹1.9 lakh after scanning repeatedly, though that is a single reported case.
Small checks that take a few seconds
Nothing here needs special software, only the habit of looking before you scan.
Touch the code. A raised edge, a lifting corner or a second pattern showing through the paper means a sticker may be sitting on top of the original.
Read the preview your camera shows before you open anything. Misspelt names, strange endings and shortened links are reasons to stop.
On a UPI app, look at who you're paying and how much. If the amount is already filled in and you never agreed to it, cancel.
For anything involving money, such as parking, tolls or your bank, skip the code and use the official app or type the address yourself.
And if a stranger sends you a code so you can "get paid", just say no.
If you've already scanned
If a page opened and you typed nothing, close it and move on. If you entered card details or a password, call your bank at once and change that password. If money has left your account, call the national cybercrime helpline 1930, file a complaint at cybercrime.gov.in, and tell your bank or UPI app straight away. Speed helps, but getting the money back is never guaranteed once it has been moved on.
The code isn't the dangerous part. The danger is how quickly we trust a square that anyone with a printer can copy.