Security Awareness

You Just Scanned a QR Code.

Good news — this one was safe.

This QR code was created by Anchor Cyber Security as part of a public security awareness campaign. Thousands of malicious QR codes are used every day to steal credentials, install malware, and defraud businesses. Take 60 seconds and learn how to protect yourself and your organization.

Show Me What Could Have Happened

What a Malicious QR Code Could Have Done

QR codes are just URLs in disguise. Unlike a link you can hover over, a QR code hides its destination completely until you scan it. Attackers rely on this — and on curiosity.

Fake login page
Captured your Microsoft 365, Google, or banking credentials
Malware download
Prompted your device to install malicious software
Payment scam
Sent you to a fraudulent payment or cryptocurrency site
Credential harvester
Served a convincing copy of a real site to steal your password
SIM swap setup
Collected enough personal info to hijack your phone number
Fake app install
Pushed a malicious app disguised as something legitimate

Could You Spot the Malicious QR Code?

Here are eight QR codes in the wild. Which ones are scams?

Free WiFi — Scan to Connect
Free Phone Charging Station
Win a $100 Gift Card
Scan to Pay for Parking
Delivery Notification — Scan to Schedule
Restaurant Menu
Event Check-In
Free Coffee Coupon

You can't tell by looking.

That's exactly the point. Every one of those labels has been used in real phishing attacks. A QR code's appearance gives you no information about where it leads. The only protection is knowing what to check before and after you scan.

Five Things to Check Before You Scan

These five questions take less than 10 seconds and catch the majority of QR phishing attempts.

1
Who placed it?
A QR code on a restaurant table or parking meter should be verified with the business. Attackers place stickers over legitimate codes.
2
Does your phone preview the URL?
Most camera apps show the destination URL before opening it. Read it. If it looks odd, don't proceed.
3
Is the domain spelled correctly?
Look for substitutions: rn for m, 0 for o, extra hyphens. Attackers register near-identical domains.
4
Does it immediately ask you to log in?
Legitimate QR codes rarely lead straight to a login page. Credential prompts after a scan are a major red flag.
5
Does something feel urgent or off?
Pressure, urgency, or an unexpected prize are social engineering tactics. Pause and verify independently.

You're Already More Aware Than Most

Most people scan first and think later — if they think at all. By reading this, you've taken a step that the majority of employees at most organizations never take.

Share this page with a coworker. It takes 60 seconds and could prevent a breach.

Want Your Organization to Be Better Prepared?

Anchor runs phishing simulations and security awareness training that help employees recognize real attacks — before they click.