Payment fraud
How to spot a fake QR code: five checks before you scan
A small square of blocks increasingly replaces a link or a payment request. That is exactly why the trick works: you no longer type an address, so you no longer see where you are being sent. The FBI warned as early as 2022 that cybercriminals tamper with QR codes, both digital and physical, to redirect victims to sites that steal login and financial information, and that a tampered code can redirect a payment to the criminal (FBI IC3, PSA 220118). The Dutch Consumers' Association describes QR fraud literally as scanning a code that takes you somewhere other than you would expect, usually to a fake website (Consumentenbond, QR-code-fraude, updated 9 July 2026). And the national fraud desk sees the code arrive inside fake invoices: the message contains a link or a QR code "to pay" (Fraudehelpdesk, fake invoice text).
The rule that breaks the pattern: always check where the code points before you pay or enter any detail, and never scan a code that someone else placed or sent for you.
Direct answer: five checks before you scan a QR code
- See the destination first, not after paying. Your camera or payment app normally shows the web address or the payee before you continue or confirm (Consumentenbond). Read that address the way you would read a link in a phishing email, and look for suspicious characters in the domain - the same tip the police gave for fake cards pushed through letterboxes (RTL Nieuws, 9 April 2025).
- Type known destinations yourself. A letter, email or invoice with a QR code for a payment to a government body, bank or collection agency is not a reason to scan: open the app or portal yourself and look the amount up there. The Dutch tax administration never sends QR codes for payments by email (Belastingdienst, phishing), and your bank does not send you a code for a payment you did not start.
- In a public place, check whether the code was added later. Criminals paste their own code over the legitimate one at payment machines, charging points and parking meters; this happened at parking meters in and around The Hague in 2025, and earlier at charging stations in Belgium (Consumentenbond). A sticker that peels, a code next to the official one, or a code where no payment point should be: do not scan it.
- Be extra suspicious of urgency and of short links. A shortened link such as bit.ly inside a QR code is extra suspicious, because there is room enough for a full web address (Consumentenbond). The same goes for "your parcel", "your fine" or "your prize" with a deadline: pressure is the mechanism, not evidence.
- Never enter login or card details on a page you did not open yourself. The Dutch fraud desk describes a QR code at the door that led to a fake charity-lottery website where victims entered their credit card details and email address; the real organisation never asks for credit card details (Fraudehelpdesk, fake Clubactie). Avoid unknown QR-scanner apps too, as they can be malicious themselves (Consumentenbond).
Two shapes, one structure
Shape A - the pasted or rebuilt code. You stand at a machine or counter and scan what hangs there. The code has been replaced or rebuilt, and the payment goes to someone else's account (FBI IC3; Consumentenbond).
Shape B - the code comes to you. A letter, a card through the letterbox, an email or an invoice with a QR code for a payment, a parcel or a "refund" (RTL Nieuws; Fraudehelpdesk). The code leads to a fake payment page or to a login page that harvests your details.
Both shapes share one thing: the decision is not made when you see the code but when you check the destination. If you cannot see where the code leads before money moves, you do not scan it.
What a detector does and does not see
You can put a screenshot or photo of a QR code through the image detector to see whether the image carries patterns common in generated or edited imagery. That is triage, nothing more: a detector cannot see where a code points, cannot tell a legitimate code from a malicious one, and a fake code can score low. Where the code leads is only visible in your camera or payment app before you continue (Consumentenbond).
What a QR code cannot tell you
- whether the code belongs to the business named on the poster, letter or machine;
- whether the payment page belongs to the organisation named in the message;
- whether a parcel, fine or refund is genuinely waiting for you;
- whether it is fraud; only a bank or law-enforcement body can establish that.
If you already scanned or paid
- Contact your bank immediately on the number you found yourself; speed decides the chance of a block or a recall.
- Entered login or card details? Change the passwords of those accounts right away and have the card you used blocked.
- Keep everything: the letter, the card, the email, the photo of the code, the web address and the timestamp.
- Report it to the national fraud desk and to the organisation the code claimed to be from; file a police report if you lost money (Fraudehelpdesk, reporting fraud).
More checks are in the guides on spotting a fake payment proof, a fake bank call and a fake tax authority message. To check a file or a message on its own, use the free checker.
Frequently asked questions
Is scanning itself dangerous?
Not by itself: the danger is in continuing and entering details, not in the scan (Consumentenbond). Check the destination your camera or app shows before you go on.
Does a high detector score prove the QR code is fake?
No. The score describes patterns in the image and says nothing about the code's destination or the sender. A genuine code can draw a signal from compression, and a fake code can stay quiet.
May I upload a photo of a QR code to the detector?
Upload only imagery you are permitted to use and that contains no other people's personal data. A photo of your own letter, or of a sticker in the street, is usually fine; avoid codes that carry someone's name, account number or address.
