What was once a technical resource reserved for logistics environments has become an everyday element in Spain. We're talking about the QR code , that square with black and white patterns that we scan daily to view a menu, pay for parking, access an event, or connect to the bar's Wi-Fi. But its convenience has a downside: the very ease with which it is generated and used has opened the door to new scams that thrive on its popularity.
Everything accelerated in 2020. With the arrival of the coronavirus pandemic, businesses had to adapt quickly and found in QR codes a fast track to offering paperless and contactless menus. That change in habits is here to stay, and today the code is not only still present in the hospitality industry, but is also used for payments, digital tickets, administrative procedures, or even to access Wi-Fi networks without typing long passwords. However, over time it has also become an attractive target for cybercriminals, who have dubbed their new attack method QRishing . And in this story, the weakest link is usually the user's haste.
What is a QR code and how does it work?
A QR code (Quick Response code) is an optical tag that stores information two-dimensionally. Unlike a traditional barcode, which stores data in only one direction, a QR code distributes it both horizontally and vertically within a grid. This structure allows for significantly more content to be included in the same space and also incorporates error correction systems that allow it to be read even with partial damage or a small smudge.
The creation process is simple: a generator transforms the desired content (a URL, text, a phone number, or Wi-Fi connection data) into bits, places them in the grid, and adds three corner squares that help the camera orient itself. This ease of creation has multiplied its use, but it has also opened the door for anyone to create a QR code for malicious purposes without needing technical knowledge.
Among the most common types of QR codes are static and dynamic ones. Static QR codes store information in a fixed format, so if you need to change the content, you must generate a new code and redistribute it. This is useful for data that doesn't change, such as a serial number or a one-off registration. Dynamic QR codes, on the other hand, work through a short redirect: the QR code points to an intermediate address that can be modified, so if you change the destination after printing it, you don't need to reprint anything. This is the option chosen by restaurants and shops because it allows them to update menus or offers without generating a new code every week.
The dark side: this is how QRishing works
The problem arose when cybercriminals began to see QR codes as a perfect channel for deception. QRishing is a variant of traditional phishing in which the attacker prints a fake code and pastes it over a legitimate one or places it in public locations such as parking meters, parking signs, walls, or bulletin boards. When the victim scans it, they are taken to a fraudulent website that impersonates a company, bank, or official service, with the aim of stealing passwords, personal data, or banking information.
One of the most common tricks involves placing a sticker over the original QR code , for example, on a restaurant table or a parking payment sign. If the code appears peeled, misaligned, or of a different print quality than the rest of the sign, it's best not to scan it. There have also been cases of unsolicited packages arriving at homes with a QR code to "confirm delivery" or "track shipment," which actually lead to a fraudulent website. WhatsApp messages inviting users to scan a code to link a device, when in reality they are granting third-party access to the account, are another frequently used scam in Spain and the rest of Europe.
The holiday season significantly increases the risk. In August, coinciding with end-of-year closing procedures and seasonal hiring, experts warn that cybercriminals expand their campaigns to encompass the entire travel environment: airline tickets arriving via "urgent" mail, impersonation of booking platforms, and fraudulent refunds for delays or outstanding fees. Furthermore, vishing (voice impersonation) has evolved with the use of AI-powered voice cloning to deceive employees and obtain transfers or bank account changes. In these cases, the experts' recommendation is clear: when faced with an urgent call or message, be suspicious and verify its origin through another channel before taking any action.

How to detect a fake QR code before scanning it
The Spanish National Cybersecurity Institute (INCIBE) has been issuing warnings about this for some time. The main recommendation is to preview the URL before opening it . On both Android and iPhone, the destination address appears after scanning the code, so take a couple of seconds to review it. If the domain doesn't match the company's official name, if it has typos or strange characters, or if it's a shortened link, it's best to leave without clicking.
Another red flag is if your phone asks you to download an APK file, which is especially dangerous on Android devices because it can install malware. You should also be wary if it asks you to enter passwords or bank details immediately after opening the page. Legitimate websites rarely request this type of information on the first visit via a QR code.
Among the practical tips that experts repeatedly emphasize are:
- Scan only codes from trusted sources, preferably on fixed supports and not on added stickers.
- Verify the web address before opening the link and don't trust link shorteners.
- Use your phone's native camera instead of third-party apps for scanning.
- Avoid entering personal or banking information if the site raises even the slightest doubt.
- Keep your phone's operating system and applications up to date.
If you've already scanned a suspicious code and entered an unfamiliar website, the first thing you should do is close it immediately. If you entered a password, change it as soon as possible on the service's official website and enable two-step verification. If you downloaded an unknown app, uninstall it and run a security scan on your device. Additionally, it's a good idea to review the activity on any linked bank accounts and, if you notice any unusual transactions, contact your bank to block the card. Acting quickly can make the difference between a major scare and a simple inconvenience.
Beyond fraud: QR codes also have their positive side
Despite the risks, QR codes shouldn't be demonized. They remain a useful, economical, and highly versatile tool for businesses and government agencies. They allow access to documents and videos, payments, digital tickets, museum information, location sharing, and Wi-Fi connection without entering a password. Their ease of transition from paper to mobile explains why, even after the pandemic, they remain an integral part of our daily lives. The key is to use them wisely and heed the advice cybersecurity experts often give: never act impulsively and always verify the channel before taking any action.
So the next time you take out your phone to scan a code on the street, in a taxi, or at a bar, take a few seconds to carefully examine the device and the website address it leads to. Technology has made opening a page a matter of a second, but that same speed also works in favor of those who want to scam you. With a little attention, QR codes will continue to be something that makes our lives easier without putting our data at risk.
