QR codes can send a phone directly to a payment page, bank-payment flow or merchant website. That convenience also makes it easy for attackers to replace a genuine code with one leading to a fraudulent destination. The user often sees only a square image until after scanning.
Attackers can physically or digitally replace a genuine code
A sticker can be placed over a printed merchant QR code, or a fake invoice can contain a code pointing to an attacker-controlled payment page.
Businesses should inspect public codes and control who can generate codes in digital documents.
Users should verify the destination domain before paying
After scanning, customers and staff should check that the domain belongs to the expected merchant, bank or payment provider.
A QR code is not proof of authenticity. It only encodes a destination or data string.
Do not let QR codes bypass supplier verification
Accounts-payable teams should not pay a new bank account merely because a supplier invoice contains a QR code.
Supplier-master controls and independent bank-detail verification still apply, especially when the code creates a bank transfer.
Use tamper-evident placement and routine inspection
Restaurants, events and physical locations using payment QR codes should inspect them regularly and avoid placing them where stickers can be changed unnoticed.
Where practical, display the merchant name or short trusted URL beside the code so customers know what destination to expect.
Protect the system that generates codes
An attacker who compromises a merchant dashboard can replace thousands of legitimate QR destinations without touching the physical code.
Use MFA and change logs for payment-link and QR-generation tools.
Remove fraudulent codes and notify affected parties quickly
If tampering is found, disable the malicious destination where possible, preserve the code as evidence and alert the payment provider or bank.
Review how long the code was active and whether customer payment records indicate losses.
Worked example: a café puts one QR code on every table linking to a payment page. A fraudster covers one table's code with a sticker that looks identical but opens a fake checkout. Daily visual inspection and a printed trusted domain beside the code can make the substitution easier to detect.
Train staff not to scan unsolicited QR codes in emails or documents on company phones simply because the message claims to be from a bank or courier. The code can hide a phishing URL more effectively than visible text.
Use unique codes or table identifiers where useful, but keep customer verification simple. Security measures should not require users to understand technical payment routing before paying.
Worked example: an accounts-payable employee receives a supplier PDF with a QR code labelled "Scan to pay updated invoice". The code opens a bank-transfer page prefilled with new account details. The employee should still verify the beneficiary through the supplier master and Confirmation of Payee where available rather than assume the PDF itself is authentic.
Use short branded URLs beside customer-facing QR codes so the user can compare the visible domain after scanning. A sticker that leads to a completely different domain becomes easier to spot.
For printed codes, keep master artwork and replacement authority controlled. Staff should not create their own payment QR codes from free online generators without finance approval because destination data can be entered incorrectly or stored by an unknown service.
Monitor customer reports of unusual landing pages. One complaint about a code asking for unexpected personal data can be the first sign of tampering and should trigger an immediate physical inspection.
Where QR codes open bank-payment journeys, display the expected payee name so customers can compare it with Confirmation of Payee or the bank screen. A mismatch should prompt the user to stop rather than proceed because the QR came from a branded poster.
Replace compromised printed codes completely instead of placing another sticker over them. Layered stickers make future tampering harder to identify and can leave the malicious code physically present underneath.
Use a change log for digital QR destinations. Marketing teams can legitimately update campaigns, but payment destinations should not be editable without finance or platform approval because a single dashboard change can redirect every scan instantly.
For invoices sent electronically, consider signing or authenticating the document through a known portal rather than relying on the QR code itself. Customers should have another way to verify that the payment instruction came from the genuine business.
For customer service, maintain a reference image or URL of genuine payment QR codes. Staff responding to a suspicious-code report should be able to compare the customer's screenshot with the official version quickly.
Never ask customers to scan a second unknown QR code to "verify" the first. Verification should move to a trusted website, bank app or known support channel.
Editorial Verdict
QR codes are convenient payment shortcuts, not authentication.
Protect the generation system, inspect physical codes and verify the destination before payment. A company should never allow a hidden QR destination to bypass the same fraud controls applied to visible bank details.
Sources
- National Cyber Security Centre, phishing guidance: https://www.ncsc.gov.uk/guidance/phishing
- Action Fraud, phishing and scam guidance: https://www.actionfraud.police.uk/
- Pay.UK, Confirmation of Payee: https://www.wearepay.uk/what-we-do/overlay-services/confirmation-of-payee/