If you've scanned a QR code and something feels wrong — a page that looked fake, a login prompt that seemed off, or you've just realized the code itself was suspicious — what you do in the next few minutes matters more than what already happened.
Step 1: Figure out what actually happened
Not every bad scan is equally serious. Ask yourself which of these applies:
- You only opened a webpage and didn't enter any information — lower risk, but still worth checking the page's behavior.
- You entered a password or personal information — this needs immediate action (see Step 2).
- You entered payment details — treat this as urgent; move to Step 3.
- A file downloaded or you were prompted to install something — don't open it, and see Step 4.
Step 2: If you entered a password
- Go directly to the real website (type the address yourself, don't use any link from the scam) and change that password immediately.
- If you reuse that password anywhere else, change it there too — attackers routinely test stolen passwords across other accounts.
- Turn on two-factor authentication on the affected account if it isn't already enabled.
- Check the account's recent activity or login history for anything unfamiliar.
Step 3: If you entered payment or card details
- Contact your card issuer or bank right away — most have a fraud line specifically for this and can freeze or replace the card quickly.
- Review recent transactions for anything unfamiliar, and flag them immediately if found.
- Set up transaction alerts if you haven't already, so any further unauthorized use is caught fast.
Card issuers and account providers are far more effective at stopping fraud when you report it quickly. There's no downside to acting immediately, even if it turns out to have been unnecessary.
Step 4: If a file downloaded or you were prompted to install something
- Don't open the file or complete the install if you haven't already.
- If you already installed something, run a reputable antivirus/security scan on the device.
- If the device is a work device, contact your IT or security team right away rather than trying to handle it alone.
Step 5: Report it
Reporting doesn't undo the incident, but it helps flag the threat for others and, for financial fraud, is often a required step for dispute processes:
- In the U.S., you can report phishing scams to the FTC.
- If it was a parking meter or public sticker scam, report it to the property owner or local authority so the physical sticker can be removed.
- Report the domain to your browser or email provider if the phishing page is still active — most have a built-in "report phishing" option.
Going forward
None of this means you did something unusually careless — quishing is specifically designed to slip past normal caution. The most useful habit going forward is simple: check the destination of a QR code before you visit it, especially before entering any password or payment information. See our guide to checking a QR code before scanning, or use CheckThisQR directly next time.