QR codes make travel easier. They appear on airport signs, restaurant menus, hotel notices, attraction tickets, parking meters and public-transport machines. The same convenience, however, creates an opening for a fast-growing scam called quishing: phishing carried out through a QR code.
A genuine-looking code can take a traveller to a fake payment page, a copied login screen or a malicious download. The goal is usually to collect card details, passwords, contact information or booking data. This guide explains how QR-code phishing works while travelling, the signs to watch for and the simple habits that keep a quick scan from becoming a stressful problem.
Planning a safer trip starts well before departure. Visit Flights Gateway for practical travel guides, booking tips and destination ideas.
What is quishing?
Quishing is short for QR-code phishing. Instead of sending a suspicious web link by email or text, a scammer places that link inside a QR code. Once a phone scans it, the code can open a webpage, begin a download or prepare a message. Because the destination is hidden until the scan happens, it is harder to judge at a glance than a normal link.
Travel is an especially useful setting for criminals. People are often in an unfamiliar place, short on time and trying to solve a practical problem: find the right train platform, pay for parking, connect to Wi-Fi or check into a hotel. A code labelled “Scan to pay” or “Guest Wi-Fi” can seem completely normal when everyone is moving quickly around it.
Where travellers are most likely to see fake QR codes
Parking meters and toll payments
Parking machines are a common target because the pressure is built in. A driver may not know the local rules, may worry about a ticket and may see a code that promises a faster payment. A scammer can place a sticker over a real QR code or add a fake sign nearby. The payment page may imitate the colours and logo of a city or parking operator, but the address may not belong to that organization.
Before entering card details, read the web address carefully. If there is any doubt, use the official parking app, pay at the machine or type the authority’s website into the browser yourself.
Restaurants, cafés and attraction menus
Digital menus are now routine, especially in tourist areas. Most are harmless. Still, a menu should not need a passport number, banking password or unrelated personal information. Look at the code itself. A raised, crooked or peeling sticker on top of a printed table card deserves a second look. When it seems unusual, ask for a printed menu or ask staff to confirm the official ordering page.
The same caution applies to museums, tours and other attractions. Buy or confirm tickets through an official website or verified app, rather than trusting a random poster that claims a ticket must be purchased immediately.
Airports, stations and hotel lobbies
These locations contain many legitimate QR codes for maps, Wi-Fi, lounge access, baggage services and transport. That volume is what makes the scam effective: travellers expect to scan something. A fake code may promise free internet, a last-minute gate update or a discounted ride. It might also direct a traveller to a page asking for account credentials or a card “deposit.”
For airport transport, it is safer to arrange the service through a known provider before you arrive. For example, travellers can book an airport transfer in advance with KiwiTaxi instead of relying on an unexpected payment QR code in the terminal.
The five-second rule: stop, inspect, verify
The best protection is not a complicated technical tool. It is a short pause before acting. Use this sequence whenever a public QR code leads to a payment, login or download.
1. Stop before scanning
Do not scan merely because a sign looks official. Urgency is a warning sign. Messages that say “pay now,” “avoid a penalty,” “confirm immediately” or “your booking will expire” are designed to make people skip verification.
2. Inspect the physical code
Look for a sticker covering another code, mismatched paper, peeling corners, bubbles, uneven edges or branding that does not match the surrounding sign. A scammer does not need to alter the entire machine; adding one convincing sticker may be enough.
3. Verify the destination
Many phone cameras show a URL preview before opening a QR-code link. Read it. Look for misspellings, odd hyphens, extra words, unfamiliar endings or a domain that has no clear connection to the business. A padlock icon only means the connection is encrypted; it does not prove the website belongs to the real company.
4. Use a direct route for important actions
When money, passwords, identity documents or account access are involved, skip the code. Open the official app already installed on the phone, type the organization’s website manually or ask a staff member for the correct method. This adds only a minute and removes the scammer’s shortcut.
How to tell a suspicious QR request from a normal one
A legitimate QR code usually matches its purpose. A restaurant menu opens a menu. A train operator’s code opens a route page within its familiar website. A hotel’s code may show guest information. Be cautious when the result asks for more than expected, especially card details, a login password, a software download or a payment unrelated to the sign.
Another red flag is a request that does not fit the setting. A café QR code should not demand a government ID. An airport Wi-Fi code should not require a bank-card number. A parking code should not send a text message to an unknown number. Trust the mismatch; it is often the clearest signal that something is wrong.
For more practical protection around airport services and checked bags, read Airport Luggage Tag Scam: How to Protect Checked Bags in 2026.
What to do after scanning a suspicious code
Scanning alone does not automatically mean an account or card has been compromised. The risk becomes much higher if information was entered, a file was downloaded or a password was submitted. Close the page if it looks wrong and do not continue interacting with it.
If card details were entered, contact the card issuer using the number on the card or the official banking app. If a password was entered, change it through the legitimate website immediately and change it anywhere else it was reused. Review recent transactions and watch for follow-up emails or texts that may impersonate an airline, bank, hotel or rental company.
It also helps to report the suspicious code. Tell the restaurant, hotel, airport desk, transit authority or parking operator so it can inspect the sign and warn other visitors. In Canada, suspected fraud can also be reported to the Canadian Anti-Fraud Centre.
Keep travel plans from creating extra risk
Good preparation reduces the chance of relying on a hurried, unfamiliar payment process. Save official airline, hotel, transit and banking apps before the trip. Keep confirmation emails available offline. Use a card with transaction alerts, and avoid entering sensitive details while connected to unknown public Wi-Fi.
Travel days sometimes involve another vulnerable moment: deciding where to leave bags. Use a known booking page when reserving a service. Travellers looking for a place to store luggage can check verified luggage-storage options with Radical Storage rather than scanning an unverified code displayed nearby.
It is also useful to recognize the wider pattern of travel scams. See 12 Airline Booking Traps That Cost You More in 2026 for booking mistakes and warning signs that can cost travellers money.
Final checklist for QR-code safety while travelling
- Pause when a QR code creates urgency.
- Inspect public codes for stickers, bubbles or mismatched edges.
- Read the URL preview before opening it.
- Never enter payment or login information unless the domain is clearly official.
- Use an official app or type the website manually when in doubt.
- Contact the bank promptly if card information was submitted.
- Report suspicious codes so other travellers are not caught by the same scam.
QR codes are not inherently unsafe, and avoiding every code is not necessary. The smart habit is to treat a public code like any other unexpected link: check where it goes before trusting it. That five-second pause can protect both a travel budget and the accounts that make a trip run smoothly.
Frequently asked questions
Is scanning a QR code dangerous?
Not by itself. The danger usually starts when a scan opens a fake site and the traveller enters personal information, pays a fraudulent bill or downloads an unfamiliar file.
Can a QR code steal credit-card details?
A QR code cannot read a card on its own, but it can send a traveller to a fake payment page designed to collect card details. Always verify the website before paying.
What is the safest way to pay after seeing a QR code?
Use the official app, payment machine or website typed directly into a browser. If the code is for a legitimate service, staff should be able to confirm the correct payment method.










