QR code fraud: “scan to receive” does not exist
A QR code is a link you cannot read. That is exactly why scammers use it: you do not see where you are going until you are there.
QR fraud (“quishing”) is growing because we have learned to trust QR codes: menus, parking, Tikkie, the banking app. A scammer sticks their code over the real one, or sends an e-mail with a QR code because spam filters do not read images.
The most important rule: with a QR code you can only pay or log in somewhere — never receive. Anyone who says “scan this code to receive your money” wants you to pay.
How to spot it
- 1A sticker.On a parking meter, charging point or terrace. Does the code feel loose, is it crooked, is there another code underneath? Do not scan.
- 2“Scan to receive.”Marktplaats buyers who pay “via Tikkie” and send you a QR. Tikkie does not work that way: the requester receives, the scanner pays.
- 3A QR code in an e-mail.Banks and government send no QR codes to log in. A QR in an e-mail is almost always phishing.
- 4A QR from the banking app that someone on the phone “just wants to see”.The login QR of your banking app is a key. Whoever scans it is logged in as you.
- 5The page after scanning asks you to log in to your bank.Parking, a menu or a survey does not need your bank login.
A real example, taken apart
- The city uses its own app or the meter itself; not a separate domain.
- The domain is not amsterdam.nl.
- The sticker sat over the original screen.
What you do
- Look at the link first.Your camera app shows the link before opening it. Read the domain. In doubt? Paste it into the checker.
- Use the official app.Parking, paying, logging in: do it through the app you already have, not a code on the street.
- Never receive money through a QR.Someone who wants to pay you asks for your account number or sends money through their banking app. That is all they need.
- Report a fake sticker.To the municipality or the owner of the meter, and to the Fraudehelpdesk.
Never do this
- Show or forward your banking login QR to anyone.
- Scan a QR from an e-mail or SMS to “log in” or “verify”.
- Scan a QR to receive a payment.
Questions people ask
I scanned a QR and opened a link. Has something happened already?
Scanning and opening is usually harmless. It goes wrong when you log in or pay on the page. If you did not: close the page and you are done.
Are Tikkie links safe then?
A real Tikkie link starts with tikkie.me and asks you to pay. Amount and name correct? Fine. A “Tikkie to receive”? That does not exist.
How can I see where a QR goes without opening it?
Most camera apps show the link while the code is in view. Otherwise: a QR reader app that shows the text without opening it.
Paste it into the checker. Thirty seconds, and you know what others already saw.