Physical tampering is a major red flag. Watch for a sticker placed over an existing code, poor alignment, unusual placement on a payment terminal or poster, or a destination that does not match the surrounding context. If the code looks altered, do not scan it and find the official link through another trusted path.
What a tampered QR code usually looks like
A QR code that has been altered often leaves visible clues. The most common warning sign is a sticker or label placed over the original code, especially when the edges do not sit cleanly or the print quality looks different from the surrounding material. Misalignment, cropping, damaged corners, or a code that looks oddly pasted onto a poster, table tent, or payment terminal are all reasons to pause.
Context matters too. A legitimate code should fit the item that carries it. If a code is on a checkout terminal but points to an unrelated domain, or if the printed destination seems disconnected from the business, treat that mismatch as a strong signal that the code may have been replaced or redirected. A tampered code often looks ordinary at a glance, so the surrounding context is part of the check.
How to judge the destination before you scan
The safest quick test is to compare the likely destination with the setting. A menu code should usually open the restaurant’s own ordering or information flow, and a payment code should stay within the expected merchant or payment experience. If a QR code seems to lead somewhere surprising, uses a shortened or unfamiliar link, or prompts a login or payment flow that does not make sense for the venue, stop and verify through another trusted path.
It also helps to inspect the code without immediately following it. If your scanner preview shows a domain that is misspelled, unrelated, or newly inserted into a context where it should not exist, that is enough to treat the code as suspicious. For public-facing QR codes, attackers rely on speed and convenience, so the warning sign is often not sophisticated malware, but a believable link placed where people expect convenience and will scan quickly.
Why QR tampering works and what to do next
QR tampering succeeds because it exploits trust in a physical object. Once a sticker is placed over the original code, the printed surface may still appear legitimate, and many users will not compare the destination against the surrounding context. The practical response is simple: if the code looks altered, do not scan it, and obtain the official address, menu, or payment page through a trusted source such as the organisation’s website, app, or verified account.
When the code is on shared infrastructure, like a payment stand, poster, or kiosk, the safest assumption is that anyone with brief access could have replaced it. That means the control is not just visual inspection, but verifying the destination independently before any action is taken. In practice, a QR code should be trusted only when the physical presentation and the destination both make sense together.
Practitioner Guidance
What to prioritise: Treat physical alterations and destination mismatch as the two highest-value checks. If either one is off, stop before scanning and use an official source path instead.
What to verify: Check whether the QR code appears layered over another print, whether the scan result matches the venue or asset, and whether the link destination is consistent with the expected service. If you manage customer-facing codes, inspect them regularly and replace any code that cannot be visually trusted.
Common mistake: People often focus on whether the code “works” and ignore whether it belongs there. A working QR code is not a safe QR code if it sends users to the wrong place.
Practitioner takeaway: For QR codes, the most reliable defence is to trust the context, not the convenience. If the physical code or its destination feels off, assume it has been tampered with until proven otherwise.
Related resources from NHI Mgmt Group
- What are the signs that a QR code phishing attempt is likely to be malicious?
- What are the signs that a source package has been tampered with even when its library code looks clean?
- What are the signs that QR code authentication is being misapplied?
- What are the signs that a QR code phishing attachment is designed to evade automated scanning?