This time it was a sad kitten. It could just as easily have been quishing: QR-code phishing. A QR code is just a link you can't read, and you followed it blind.
- Fake login pages A pixel-perfect copy of your bank, email, or work SSO, waiting for your password.
- Malicious downloads An "update" or app install that hands your phone to someone else.
- Payment scams Stickers pasted over real codes on parking meters, menus, and invoices reroute your money.
- Instant actions QR codes can pre-fill payments, join Wi-Fi networks, or draft messages before you notice.
Next time, before you scan
- Ask who put the code there, and why.
- Read the URL preview before opening it. No preview, no tap.
- Check for stickers slapped over an original code.
- Never enter credentials or pay via a scanned link. Type the address yourself.
- If it arrived by email demanding urgency, it's bait.
This page was the harmless version of that lesson. The next random code you scan might not be.