Inspect the physical code
Look for a sticker placed over another code, damaged signage, an unfamiliar label, or instructions that do not match the business setting. Ask an employee when the display looks altered.
QR payment security guidance
QR code payments can be a convenient way to move a customer from a physical sign, receipt, invoice, or screen to a digital payment experience. The code itself does not prove that the destination is trustworthy. Security depends on who created and displayed the code, where it sends the customer, and how the payment page and merchant workflow are managed.
A QR code stores information that a phone can read. For a payment experience, that information commonly opens a web address or starts a supported app workflow. The customer then reviews the destination and completes the next steps presented there. Because the visible square pattern is not a readable business name or web address, customers should not assume that every code leads to the merchant or payment service they expect.
The Federal Trade Commission warns that malicious QR codes can lead to spoofed websites designed to capture information or can trigger a harmful download. The FBI also advises people not to scan codes from unknown origins and to use caution before granting a site or app permissions. These risks do not mean every QR payment is unsafe; they show why the source and destination need to be verified.
Look for a sticker placed over another code, damaged signage, an unfamiliar label, or instructions that do not match the business setting. Ask an employee when the display looks altered.
Use the phone's preview when available and inspect the web address before opening it. Watch for misspellings, substituted characters, unfamiliar domains, and a destination unrelated to the merchant.
Do not enter credentials, payment details, or personal information merely because a page creates urgency. Be especially cautious if a scan unexpectedly requests an app download or broad device permissions.
A customer should stop when a destination looks unrelated to the merchant, the web address is misspelled, the page demands unusual credentials, or the scan begins an unexpected download. A secure-looking page design or familiar logo is not enough by itself because a spoofed site may imitate a real business.
If no information was entered, close the page and report the suspect code to the business. If login information was submitted, the FTC recommends changing the affected password and enabling multi-factor authentication. If payment or financial information was exposed, contact the relevant financial institution or payment provider through a known, trusted channel and monitor the affected account. Suspected scams can also be reported to the FTC, while internet-enabled fraud may be reported to the FBI's Internet Crime Complaint Center.
A legitimate code can still lead to a poorly explained checkout, and a well-designed checkout cannot make an altered sign trustworthy. Merchants should evaluate the complete path: how the code is generated, where it is displayed, what destination the customer sees, how staff verify it, what alternatives are available, and how a suspicious event is handled.
Available QR features and security controls vary by payment service, application, device, and merchant setup. Confirm the actual workflow with the providers responsible for the deployed system. Do not treat general guidance as proof that a particular product is compatible with a processor, terminal, point-of-sale system, or digital wallet.
Document where each QR code appears, the exact destination it should open, who inspects it, which fallback customers can use, and how staff escalate a suspected replacement. Then confirm provider-specific setup and incident steps with the organizations responsible for the payment flow. Never send cardholder data, passwords, bank credentials, complete account numbers, or secret API keys through a general inquiry form.
To learn more about how TSYS can help improve the way your organization accepts payments, markets to new customers, or manages its HR responsibilities, get in touch by calling 585-981-8463 to get started.
CONTACT US