By Jackson Godwin. Cybersecurity Analyst & Penetration Tester

How a Simple QR Code Could Lead to a Scam: What Every Smartphone User Should Know
Disclaimer: This story is fictional but inspired by real scam techniques used by cybercriminals. It is written for cybersecurity awareness and educational purposes.
It Started With a Free Cup of Coffee
It was a busy Saturday morning.
I had decided to stop at a small coffee shop after attending a cybersecurity meetup.
The place was packed.
People were working on laptops.
Others were chatting with friends.
Some sat quietly scrolling through their phones while waiting for their orders.
As I stood near the counter, something caught my attention.
A bright poster was taped to the wall.
It read:
🎉 Scan Here and Get 20% Off Your Next Coffee!
Below the message was a large black-and-white QR code.
I smiled.
QR codes had become part of everyday life.
Restaurants used them for menus.
Parking lots used them for payments.
Shops used them for promotions.
Even business cards now included QR codes.
Without thinking, I reached for my phone.
One Small Detail Made Me Stop
Just before I scanned the QR code, something didn’t feel right.
I couldn’t explain why.
Maybe it was instinct.
Maybe it was years of working in cybersecurity.
Instead of scanning immediately, I looked more closely at the poster.
The edges looked unusual.
It wasn’t professionally printed.
It looked like a sticker had been placed over another QR code.
Most customers would never notice.
But once I saw it…
I couldn’t ignore it.
Curiosity Took Over
Rather than walking away, I decided to investigate.
I politely asked one of the staff members.
“Did you recently change your promotional poster?”
The cashier looked confused.
“No,” she replied.
“We’ve had that promotion for months.”
That answer immediately raised another question.
If the coffee shop hadn’t changed the poster…
Who had?
The Original QR Code Was Hidden
The manager came over after hearing our conversation.
Together, we carefully lifted one corner of the sticker.
Underneath it…
There was another QR code.
The original one.
Someone had printed a fake QR code and placed it directly over the legitimate one.
The customers scanning the sticker weren’t reaching the coffee shop’s promotion at all.
They were being redirected somewhere else.
The manager looked shocked.
So did everyone standing nearby.
Where Did the Fake QR Code Lead?
Out of curiosity—but without entering any personal information—I examined the destination in a safe environment.
The website looked almost identical to the coffee shop’s official promotion.
It had:
- The company logo.
- Similar colours.
- Promotional images.
- A discount offer.
It looked convincing.
Then I noticed something.
The website asked visitors to:
“Log in to claim your discount.”
That didn’t make sense.
Why would someone need to log in just to receive a coffee discount?
Even more suspicious…
The web address wasn’t the coffee shop’s official domain.
It looked similar.
But not identical.
That tiny difference could easily be missed by someone in a hurry.
That’s When I Realized What Was Happening
This wasn’t really about coffee.
It wasn’t about discounts.
It wasn’t even about QR codes.
It was a phishing attack.
More specifically…
It was a form of phishing known as QR phishing, often called “quishing.”
Instead of sending victims a fake email or text message, attackers use a malicious QR code to direct people to a fraudulent website.
The goal is usually the same:
- Steal usernames and passwords.
- Collect payment card information.
- Trick people into downloading malicious software.
- Capture other sensitive information.
The QR code itself isn’t dangerous.
The danger comes from where it sends you.
Why QR Codes Make People Lower Their Guard
One reason these scams can be effective is that people often trust QR codes.
Unlike suspicious-looking email links, QR codes don’t immediately reveal where they lead.
You simply point your camera.
Tap the notification.
And the website opens.
Most people don’t stop to ask:
“Where is this actually taking me?”
Cybercriminals understand that.
They know QR codes have become part of everyday life.
That’s why they’ve started using them more often.
It Could Have Happened to Anyone
As I watched customers continue walking toward the counter, I realized something.
Most of them would have scanned the fake QR code without thinking twice.
Not because they were careless.
Because they were doing what technology had trained them to do.
Scan.
Tap.
Continue.
That’s exactly what attackers rely on.
Not advanced hacking.
Not sophisticated malware.
Just ordinary people moving quickly through an ordinary day.
And that’s what makes QR phishing such a growing cybersecurity threat.
I Reported It Immediately
I showed the manager exactly what we had found.
The fake sticker was removed immediately.
The original QR code was visible again.
The manager thanked me and promised to inspect every promotional poster in the store.
As I left the coffee shop, one thought stayed with me.
If I had scanned that QR code without paying attention…
I might have entered my login details on a fake website.
And if that had happened, the consequences could have been much more expensive than a cup of coffee.
That experience reminded me that cybercriminals are constantly adapting.
Years ago, they relied mainly on fake emails.
Today, they also exploit QR codes, messaging apps, social media, and countless other everyday technologies.
The question is no longer whether QR codes are useful.
They absolutely are.
The real question is:
How can you tell the difference between a legitimate QR code and one designed to steal your information?
In the next section, we’ll explore exactly how QR phishing—or quishing—works, why it has become so popular with cybercriminals, and the warning signs every smartphone user should know before scanning their next QR code.








