QR Safety, Scams & Exploits

How to Report a Malicious QR Code

Found a scam QR code in the wild? Here's how to report it to the right people and help protect others.

Found a malicious QR code — a sticker over a parking meter, a dodgy code in an email, a scam payment request? Reporting it well helps get it removed, warns other people, and gives investigators a trail to follow. Here's a calm, practical guide to preserving the evidence and notifying the right people. 🐾

When you spot a scam QR code, the instinct is to move on and forget it. But a few minutes of reporting can protect the next person who scans, prompt a venue to remove a malicious sticker, and feed fraud data to the people who track these schemes. This guide walks through what to do, in order, whether or not you actually fell for the scam.

First: are you or your accounts at risk?

Before reporting, handle any immediate harm. If you entered information or sent money:

  • Passwords: change the affected password immediately, and anywhere you reused it. Turn on multi-factor authentication.
  • Card or bank details: contact your bank right away to freeze the card and watch for fraud.
  • Crypto: stop any further transfers and gather transaction details — see QR codes and crypto scams.
  • A downloaded app or file: delete it, and run a security scan; keep your phone updated.

Once you're safe, move on to preserving evidence and reporting.

Step 1: Preserve the evidence

Good evidence makes a report actionable. Capture what you can before anything changes:

SituationWhat to capture
Physical sticker/overlayPhotos of the code in place, the surrounding sign, and the location; note the exact spot
Email or messageDon't delete it; note the sender address and keep full headers if possible
The destination linkThe decoded URL (screenshot the preview) — but don't enter any details on the page
Payment/cryptoThe address, amount, time, and any transaction ID
Any correspondenceScreenshots of messages, names, and phone numbers used

Reading and recording the destination is easiest with a scanner that lets you scan a code safely and shows the real link without opening it. Capture the URL; don't interact with the page. For help interpreting what you're seeing, see QR codes and malicious URLs.

Photograph first, report second. Evidence that shows the sticker in place and the link it led to is far more useful than a description from memory.

Step 2: Notify the venue or the impersonated brand

The fastest way to stop harm is often to tell whoever owns the location or the brand being impersonated.

  • Physical overlays: tell the business, parking operator, or property manager on the spot if you can, and don't remove the sticker yourself — they may want it preserved. See QR code sticker attacks.
  • Impersonated companies: banks, delivery firms, and big services usually have a "report phishing" or fraud contact. Use the address on their official website — reach it by typing the known address, not via the suspicious message.
  • Workplace codes: forward suspicious emails to your IT or security team, or use your mail client's report-phishing button. This is covered in QR codes in phishing emails.

Step 3: Report to consumer-protection and anti-fraud bodies

Every country has organizations that collect scam and fraud reports. You don't need to know the exact agency name — searching for "report a scam" plus your country will point you to the official body. Broadly, look for:

  • National anti-fraud or cybercrime reporting services — the main clearinghouse for scams and online fraud in your country.
  • Consumer-protection agencies — which track deceptive practices and scam trends.
  • Financial regulators or your bank's fraud team — if money or card details were involved.
  • Local police — particularly for a physical overlay in a specific public place, or where you've lost money.

Provide your preserved evidence: the photos, the decoded link, the sender details, and any amounts. The more concrete the report, the more useful it is.

Step 4: Report to the relevant platforms

Digital scams often ride on top of legitimate services, which usually want them reported:

  1. Email providers — use "report phishing" so filters improve for everyone.
  2. Messaging apps and social platforms — report the scam message or account.
  3. The hosting or shortener service — many let you report an abusive URL, which can get the malicious page taken down.
  4. App stores — if the code pushed a fake app, report the listing.
  5. Crypto exchanges — if a wallet or exchange was involved, report the address.

Step 5: Warn other people

Quiet, practical warnings help those around you:

  • Tell friends, family, or colleagues who might encounter the same scam, especially in a shared workplace or neighborhood.
  • If it was a public overlay, a note to a local community group can prompt others to check that meter or charger.
  • Share the general lesson, not panic: preview the link, verify the source, don't act under pressure.

What information should a good report include?

IncludeWhy
Where and when you found itHelps locate and remove physical overlays
The decoded destination URLLets investigators and hosts act on the malicious page
Photos or screenshotsConcrete evidence that's hard to dispute
What the scam asked forClarifies the type of fraud
Any losses and transaction detailsNeeded for financial and criminal follow-up

The bigger picture

Reporting a malicious code rarely feels dramatic, but it's genuinely how these scams get shut down — a removed sticker here, a blocked domain there, a pattern spotted by fraud investigators. You're not just protecting yourself; you're making the environment a little safer for everyone who scans after you. To sharpen your instinct for spotting bad codes in the first place, revisit our QR code safety checklist and our explainer on what quishing is. And when you need codes of your own, you can create a free QR code that points openly at your real link — the honest kind that never needs reporting.

Frequently asked questions

Who should I report a malicious QR code to?

Start with whoever owns the location or brand being impersonated, then report to your country's anti-fraud or cybercrime service and any relevant platform (email provider, app store, or hosting service). If money was involved, also contact your bank and the police.

Should I remove a scam sticker I find?

It's usually better to leave it in place, photograph it, and tell the venue or operator so they can preserve it as evidence and remove it properly. If you do handle it, keep it intact, but don't scan it or enter any information.

What evidence should I collect?

Photos of a physical code and its location, the decoded destination link, the sender's details for an email or message, and any payment or transaction information. Capture the URL without entering anything on the page.

Is it worth reporting if I didn't lose anything?

Yes. Reporting a code you spotted but didn't fall for helps get it removed and warns others before they're caught. It also gives fraud investigators data to track scam patterns, so even a near-miss report is valuable.

How do I report a malicious link safely?

Preview the code to capture the decoded URL without opening the page, then include that link in your report to the relevant platform, host, or anti-fraud body. Never enter credentials or payment details on the page while gathering evidence.

Make a QR code the honest way 🐾

Free forever, no tracking, no expiry — generated right in your browser.

🎨 Create a QR code →