updated · 2026-08-07
Is it safe to scan a QR code in a nightclub to pay for a song?
Usually yes, provided you check the page rather than the code. Scanning only opens a link — it cannot charge your card or install anything by itself. The risk is typing card details into the convincing fake a tampered code can send you to. Three checks cover almost all of it: read the domain in the address bar before you type a card number, refuse any code that demands an app install, and run a fingernail over the code to see whether it is a sticker pressed on top of another one.
What actually goes wrong when a QR code is malicious?
A QR code is an encoded link. It cannot debit your card, install software by itself, or read your phone. What it does is hide the destination until you have already scanned it — that is the whole trick. The scam has a name: quishing, from QR plus phishing.
Two flavours. The digital one arrives in your inbox: a code inside an email or PDF, put there to dodge email filters. The physical one is a sticker — someone prints a code, walks in, and presses it over the real one. The FBI's public service announcement I-011822-PSA (18 January 2022) is blunt about it: "If scanning a physical QR code, ensure the code has not been tampered with, such as with a sticker placed on top of the original code."
Then a page opens. Right colours, plausible logo, an amount to pay. You type sixteen digits. That is where the money goes.
How common is this really in 2026?
| Source | What was measured | Figure | Published |
|---|---|---|---|
| Unit 42, Palo Alto Networks | QR codes seen by its web crawlers | "an average of 75,000 detections of QR codes each day, with 15% of these pages containing QR codes leading to malicious links" — "an average of over 11,000 detections of malicious QR codes each day" | 13 Feb 2026 |
| Microsoft Threat Intelligence | QR phishing delivered by email, mostly PDF attachments | 7.6 million attacks in January 2026, 18.7 million in March — "a 146% increase over the quarter" | 30 Apr 2026 |
| Action Fraud, UK | Quishing reported by the public | 784 reports, almost £3.5m lost, April 2024–April 2025; most frequent in car parks, "criminals using stickers to tamper with QR codes on parking machines" | 20 Jun 2025 |
| NCSC, UK | Overall risk | "this type of scam is relatively small compared to other types of cyber fraud" | 8 Feb 2024 |
Read that table for what it actually says: the headline numbers are not about clubs. Microsoft's 146% is email-delivered QR phishing — attachments, not stickers. No public data we could find measures sticker fraud inside bars, clubs or music venues specifically. The physical version is real, but the reported cases cluster where payment happens unattended: meters, parking machines, charging points.
The NCSC's position is the one worth carrying into a venue: "The QR codes used in pubs or restaurants are probably safe for you to scan", while "scanning QR codes in open spaces (like stations and car parks) might be riskier." That assessment dates from February 2024 and we found no newer official UK revision of it.
A nightclub sits between those two cases. Indoor venue, staff, a licence to lose — closer to the pub. But it is dark, you are three drinks in, and nobody is watching the flyer taped by the smoking area.
What can you check in ten seconds, in the dark?
1. Read the domain before you type anything. Your camera shows the link before it opens it — read it, then read it again once the page loads. What matters is the registered domain sitting immediately before the first slash, extension included. venuename.com/pay/... is venuename.com. venuename.secure-pay-tickets.net is not — the real domain there is secure-pay-tickets.net, and everything to its left is decoration. Scammers know you read left to right.
2. Card numbers belong on the payment provider's page. A legitimate small business does not build its own card form; it redirects you to a hosted one. Stripe's Checkout documentation describes exactly that redirect, and its custom domains page calls checkout.stripe.com and buy.stripe.com the default Stripe domains, adding that a business paying for the custom-domain feature must serve the page from a subdomain of its own existing domain — payments.example.com, for instance. Either way the domain is one you can name out loud. A card form on a domain that reads like a random string ends the conversation.
3. Touch the code. The most underrated check, and the fastest. Run a fingernail across the edge. Raised, bubbled, slightly crooked, a different white from the paper around it, or a corner you can lift — that is a sticker on top of something else. Exactly the pattern Action Fraud describes on parking machines — nothing stops it working on a club flyer.
4. Refuse any QR code that wants you to install an app. The FBI is explicit: "Do not download an app from a QR code. Use your phone's app store for a safer download." A code that pushes an install before it will let you pay is not a shortcut, it is the payload.
5. Use your phone's built-in camera, not a scanner app. The NCSC recommends "that you use the QR-scanner that comes with your phone, rather than using an app downloaded from an app store." A third-party scanner adds a middleman between you and the link, and buys you nothing.
6. Ask the staff. Ten seconds: hold up the code, "is this yours?" Bar staff know what belongs on their own furniture. If nobody recognises it, you have found a sticker — tell them; you are not the first to scan it tonight.
What will a legitimate payment page never ask you for?
- Your online banking username or password. No payment page needs them, ever.
- Your card PIN. A PIN is for terminals and cash machines, not web forms.
- A transfer to "verify" your account, or a small payment "to confirm your identity".
- A photo of your ID to buy a song request.
- Turning off 3-D Secure, or reading an SMS code out to someone on the phone.
- An app install before you can pay.
Any of those appears, close the tab. No legitimate version of that request exists.
You already paid on a page you now think was fake. What next?
Block the card first, before you finish reading this. Then dispute the transaction in writing with your bank, and keep the URL you landed on — it is the most useful thing an investigator can get from you.
In the United States, the CFPB states that "if someone steals and uses your account number, you generally have no liability for unauthorized use", and that where a physical card is lost or stolen and used before you report it, "the most you will owe for unauthorized charges on the card is $50". Deadlines and protections differ by country and card type: report the same night.
This section describes published consumer-protection rules; it is general information, not legal or financial advice. For your own case, ask your bank or a qualified adviser in your country.
Where does REQ fit into this?
REQ is a song-request tool DJs put on a QR code in the booth — exactly the kind of code this article is about, including on the night someone tries to fake one. So: don't trust us, check us. Four things you can verify in the dark, knowing nothing about the product.
- The address bar says reqdj.com. Not a lookalike, not a subdomain of something else.
- There is nothing to install for the public. The request page is a web page in your browser; the app is the DJ's side.
- The card form is Stripe's hosted checkout, on Stripe's own domain — REQ never shows its own card fields.
- For a song request, the card is authorised, not charged, until the DJ accepts. A refused request releases the authorisation: no charge, and no refund to chase.
Fail any of those four and it is not REQ. The same test works on whatever tool your venue uses — a domain you can name, a hosted checkout, nothing to install. Anything else, ask the bar.
Frequently asked questions
Can scanning a QR code hack my phone?
A QR code is only an encoded link. Scanning it cannot charge your card, install software on its own, or read your data. The danger begins after the page opens: a fake page can ask you for card details, banking logins or an app download. Read the domain shown in the address bar before typing anything, and close the page if it does not match the business you are standing in front of.
How do I know if a payment page is really Stripe?
Stripe's documentation refers to checkout.stripe.com and buy.stripe.com as the default Stripe domains for its hosted payment pages. A business can pay for Stripe's custom domain feature, and Stripe requires that domain to be a subdomain of the business's own existing domain, such as payments.example.com. Look at the text immediately before the first slash in the URL. If a page collects your card number on a domain you cannot tie to either the business or the payment provider, do not enter it.
What does a QR code sticker scam look like in real life?
Someone prints a QR code on an adhesive label and presses it over a legitimate one — on a parking machine, a table card, a poster. Action Fraud, the UK's national fraud and cybercrime reporting service run by the City of London Police, said in June 2025 that quishing happens most frequently in car parks, with criminals using stickers to tamper with QR codes on parking machines. The physical test is to run a fingernail across the edge of the code: if it is raised, bubbled, crooked, a different shade of white, or liftable at a corner, it is a sticker.
I entered my card details on a fake payment page. What should I do?
Call your bank immediately and block the card, before anything else, then dispute the transaction in writing and keep the URL you landed on. In the United States, the Consumer Financial Protection Bureau states that if someone steals and uses your account number you generally have no liability for unauthorised use, and that if a physical card is lost or stolen and used before you report it, the most you will owe is 50 dollars. Rules and deadlines differ by country and card type, so report the same night rather than the next morning. This is general information, not legal advice.
Should I use a QR scanner app instead of my phone camera?
No. The UK National Cyber Security Centre recommends using the QR scanner that comes with your phone rather than an app downloaded from an app store. The camera app on a current iPhone or Android phone shows you the destination link as a preview before it opens it, which is exactly the check you need, and a third-party scanner app adds a party between you and the link for no benefit.
Sources
- 01FBI IC3 Public Service Announcement I-011822-PSA — Cybercriminals Tampering with QR Codes to Steal Victim Funds (18 January 2022)
- 02NCSC (UK) — QR Codes: what's the real risk? (8 February 2024)
- 03Action Fraud (City of London Police) — New quishing alert: £3.5 million lost last year to fraudulent QR codes, press release of 20 June 2025, republished by WIREDGOV
- 04Unit 42 (Palo Alto Networks) — Phishing on the Edge of the Web and Mobile Using QR Codes (13 February 2026)
- 05Microsoft Security Blog — Email threat landscape: Q1 2026 trends and insights (30 April 2026)
- 06Stripe Docs — Use your custom domain (Checkout)
- 07Stripe Docs — How Checkout works
- 08Consumer Financial Protection Bureau — Am I responsible for unauthorized charges if my credit cards are lost or stolen?