Is a QR code at a concert or event venue safe to scan?
Usually yes if it is an official sign, but scammers sometimes place fake QR code stickers over legitimate venue codes to redirect you to phishing pages.
Last reviewed: 1 August 2026
Explanation
QR code sticker attacks ('quishing') occur when fraudsters print and stick fake QR codes over official ones in high-traffic locations such as event venues, museum displays, and public transport. At a venue the fake code may lead to a convincing fake merchandise shop or 'exclusive offer' page that harvests your card details. Warning signs include a QR code that is slightly misaligned, has a sticker texture different from the sign behind it, or leads to a URL that does not match the event's official domain. Before scanning any QR code at an event, check whether it looks physically authentic and preview the URL before opening it fully. If the URL looks unfamiliar, close it and visit the official event website directly.
Events concentrate the conditions quishing needs: crowds of distracted people, an expectation of scanning codes for menus, merchandise, and Wi-Fi, and enough noise and queueing that nobody studies a poster closely. Payment-related placements are the priority targets — codes at parking machines, drink-ordering stations, and merchandise stands sit exactly where people expect to type card details seconds after scanning, so the fake checkout raises no suspicion. The physical attack costs a sheet of sticker paper, and one evening's placement can harvest cards until someone peels it off.
Calibrate trust by what the destination asks for rather than where the code is displayed: a menu or schedule that asks for nothing is low-stakes even if you cannot fully verify it, while anything leading to payment or a login deserves the extra seconds — read the full URL, prefer typing the vendor's address yourself, and pay through the event's official app where one exists. Treat card details entered after a casual scan as the risk moment, and if it has already happened, watch the card's transactions and tell your bank at the first unfamiliar charge. Reporting a suspect sticker to venue staff protects the hundreds scanning after you.
Common red flags
- QR code appears to be a sticker placed over another surface
- Code is slightly misaligned or has a different texture to the sign beneath
- URL preview does not match the event's official domain
- Page asks for card details to access a 'special offer'
- Multiple QR codes in the same area with subtle differences
What to do now
- Check the QR code physically for sticker overlays before scanning
- Preview the URL before opening and verify it matches the official domain
- Access merchandise and offers directly through the official event website
- Report suspect codes to venue staff
Frequently asked questions
How do I preview a QR code URL before visiting it?
Most phone cameras show a URL preview before you tap to open it. Some QR scanner apps also show the full link first. Read the URL carefully before proceeding.
Which QR codes at a venue carry the most risk?
Ones that end in payment or login — parking machines, drink ordering, merchandise, Wi-Fi portals. A tampered menu code wastes your time; a tampered payment code takes your card. Give payment codes the extra seconds of URL checking.
I typed card details after scanning a code at an event — what should I do?
Watch the card's transactions closely and contact your bank at the first unfamiliar charge — or pre-emptively if the checkout felt wrong in hindsight. Report the code's location to venue staff so the sticker gets removed.