QR codes have long become a familiar part of everyday life. They are used to pay for parking and purchases, open menus, receive tickets, visit websites, connect to Wi-Fi, or leave reviews.
A QR code itself is not dangerous. It is simply a way to transmit a link, payment details, or other information. The problem arises when a legitimate code is replaced or a fraudulent QR code is sent disguised as an ordinary document, invoice, or message.
The Cyber Police of Ukraine warns about cases of QR code substitution in public places. Fraudsters may place their own code over the legitimate one or put it where people are used to quickly scanning a code and proceeding to payment. (Cyber Police)
However, today this is only one of the ways QR codes can be used for fraud.
How fraudsters use QR codes
1. Replacing QR codes in stores or public places
A fraudulent QR code can be placed over the legitimate one on a payment sign, menu, advertising poster, parking meter, or other surface.
After scanning it, a person is taken to a fake website that may look almost identical to the legitimate one. There, they are asked to enter card details, a password, or other information.
It is virtually impossible to distinguish a well-made fraudulent QR code from a legitimate one by appearance alone.
2. Replacing payment QR codes
For a store, this poses a separate risk.
A QR code may contain the seller’s payment details. If a fraudster replaces such a code with their own, the customer may believe they are paying the store, while the money actually goes to a different account.
Therefore, before confirming a payment, it is important to check the recipient, payment details, and amount in the banking app.
In Ukraine, QR codes are also officially used to transmit merchants’ bank details. (National Bank of Ukraine)
3. Sending QR codes in emails or PDF files
This type of fraud is called QR phishing, or quishing.
The email may look like an ordinary work-related message:
-
an invoice or payment confirmation;
-
a document requiring a signature;
-
a message from a bank;
-
a delivery notification;
-
a request to verify an account;
-
a request to change a password or access settings.
Instead of a regular link, a QR code is inserted into the email or PDF file. An employee scans it with a phone and is taken to a fake Microsoft, Google, banking, or other familiar service page.
This method is especially convenient for fraudsters: the link is hidden inside an image, and the user moves from a work computer to a phone, where it is more difficult to notice the website address.
According to Microsoft Threat Intelligence, in the first quarter of 2026, the number of QR phishing attacks increased by 146%, and most of these QR codes were distributed through PDF files.
4. Offering to install an app
A QR code may also lead to a page offering to install an application or grant certain permissions on the phone.
Do not install applications from random QR codes. If you need an app from a bank, delivery service, or another provider, find it yourself in the official app store.
Where you should be especially careful
For customers, the greatest risk arises in situations where a QR code is expected to be scanned quickly and without additional checks: when making payments, parking, using public transport, attending events, visiting restaurants or cafes, or making charitable donations.
For business owners, this list should also include work email, supplier invoices, PDF documents, and messages concerning access to corporate services.
Fraudsters rely on an automatic reaction: you see a familiar logo or standard document — scan the code — perform the requested action.
How to use QR codes safely
- Check the physical QR code. If you notice an additional sticker, uneven edges, signs that the code has been covered or replaced, or any other changes — do not scan it.
- Check where the QR code leads. Before opening a link, most phones display the address. Check the domain itself rather than the logo or appearance of the page.
- Be especially careful with sign-in requests. If a QR code unexpectedly asks you to sign in to Microsoft 365, Google, your bank, email, or another important service, it is safer to open the official app yourself or manually enter the known website address.
- Check the payment recipient. Before confirming a payment, make sure the money is being sent to the correct company or Sole Proprietorship.
- Do not share verification codes with other people. A code received by SMS or in a banking app may be used to confirm your own transaction, but you should never dictate it to a «bank employee», seller, support representative, or anyone else.
- Do not install applications from random QR codes. Use official app stores instead.
What store owners should do
QR codes in a store should be protected just like other elements of the payment infrastructure.
Check all QR codes visible to customers: those used for payments, menus, Wi-Fi, loyalty programs, reviews, promotions, social media, and other services.
For QR codes that are used permanently:
-
place a clear service name or website address next to the code;
-
avoid shortened or unclear links unless necessary;
-
protect printed QR codes from being easily covered or replaced;
-
regularly check whether an unauthorized sticker has been placed over the code;
-
explain to sales staff and administrators where the store’s QR codes should lead.
If an unknown QR code appears in your sales area, remove it immediately and determine who placed it there and when.
A separate rule should be established for accounting staff and managers: a QR code in an invoice, payment email, or message about access to a work account does not make the document safe. If a request is unusual, verify it through another communication channel.
What to do if your store’s QR code has been replaced
If you find an unauthorized QR code on a payment sign, menu, or other material:
-
stop using it;
-
photograph the code and the place where it was located;
-
if possible, keep the sticker itself;
-
determine approximately how long the code may have been accessible to customers;
-
review security camera footage;
-
if the code was used for payments — notify your bank or payment provider;
-
report the information to the Cyber Police.
This will help not only stop the fraudulent scheme but also determine whether your customers may have been affected.
Already entered your details on a suspicious website?
If you entered your bank card details, immediately contact your bank using its official phone number or app and follow its recommendations for blocking the card and protecting your account.
If you entered the password for your work email, Microsoft 365, Google, or another business account:
-
immediately change the password from a trusted device;
-
sign out of all active sessions;
-
check your two-factor authentication settings;
-
check whether any unknown email forwarding or filtering rules have appeared;
-
notify the person responsible for IT or information security.
Fraudsters can use a compromised corporate email account to send fake invoices to your employees, customers, and partners. This behavior is commonly observed in modern QR phishing campaigns.
If you have become a victim of fraud, save screenshots, the website address, the QR code itself, emails, and other details, and submit a report to the Cyber Police: https://ticket.cyberpolice.gov.ua/
Save screenshots, the address of the suspicious website, messages, and other details — this information may be useful to law enforcement.

BRAMA: how to help combat harmful content online
The Cyber Police of Ukraine is developing the «BRAMA» project — a community whose participants help identify and limit the spread of fraudulent, disinformation, and other harmful content online.
Citizens, government institutions, and representatives of the private sector can join the project. No special technical knowledge is required to participate.
What BRAMA participants do
Project participants can:
-
report resources containing potentially harmful content;
-
submit complaints through the official reporting mechanisms of social networks and other platforms;
-
receive information about current fraud schemes and cyber threats;
-
use materials on media literacy and cyber hygiene.
A smartphone or computer is all that is needed to participate.
Ihor Chepur, Head of a Department at the Cybercrime Counteraction Directorate in Kyiv and Police Major, notes that user participation helps identify harmful content and respond to it more quickly.
According to him, users can report a suspicious resource, use a platform’s reporting mechanism, or verify questionable information before sharing it.
Project results
According to the Cyber Police, BRAMA users have submitted more than 140,000 reports about potentially harmful resources since the project began.
More than 26,000 sources of unacceptable content have also been blocked as part of the community’s activities.
How BRAMA will develop
The Cyber Police plans to expand the project in several areas:
-
«Cyber BRAMA» — an educational web portal with materials on cybersecurity and digital literacy;
-
«Chats Online» — a platform for education and participation in combating harmful content;
-
the BRAMA mobile application.
The project will also continue informing users about fraud schemes, cyber threats, and safe online practices.
More information about the project and how to participate is available through the official BRAMA and Cyber Police of Ukraine resources.









Go back to the previous step