Skip to content
FIN-CSIRT
RS
Report an incident

FIN-CSIRT / Practical lesson

Check where the code or link really leads

Recognise a substituted domain, an overlaid QR sticker and a form requesting information it does not need.

Online payment and service usersAbout 5 minutes of reading + 3 questions
Start with the example Already entered details or downloaded a file?

What you will learn

  • Check the domain before entering information.
  • Handle a QR code in a public place more safely.
  • Respond after entering information or downloading content.

Practice example

A QR code on a parking machine

Page opened after scanning
A QR code on a parking machine

Enter your card number, security code and email password to pay for parking.

Fictional example for practice.
Show the example explanation
The code may have been covered
Look for an added sticker and use another official payment method if uncertain.
The domain is unexpected
The address must belong to the service, not merely contain a familiar word.
Another service's password is requested
A parking payment does not need your email password.

Why do QR codes work in scams?

A QR code does not reveal its address until scanned. It can appear in a fraudulent message or advert, or be placed over a genuine code on a parking machine, menu or poster. The destination can then imitate a bank, courier or payment service.

Check the complete domain

Before signing in or paying, read the address displayed by the phone. Look for substituted letters, extra words and a different domain ending. bank-check.example is not a bank subdomain merely because it contains “bank”.

HTTPS means that the connection is encrypted; it does not prove that the site belongs to the organisation you expect. Logos, colours and forms can be copied.

Open the service more safely

  1. Where possible, use a known app or type the official address instead of scanning.
  2. In a public place, inspect whether the code was covered or physically changed.
  3. Check whether the requested information matches the purpose. A basic information page does not need card details or a password.
  4. Do not install an app or configuration profile simply because the scanned page offers it.

If you have already acted

  • If you only opened the page, close it without entering information or downloading anything.
  • If you entered a password, change it through the official service from a trusted device and end unknown sessions.
  • If you entered card or banking information, contact the bank immediately.
  • If you downloaded or installed content, disconnect if the device behaves suspiciously and follow the device recovery guide.

Preserve a photograph of the code, the page address and time without reopening suspicious content.

Check your knowledge · 3

Your turn to choose the next step.

Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.

Questions and explanations are also available without JavaScript.

A scanned QR code opens a page with a familiar logo and HTTPS. Is that enough?

Why does this matter? A logo can be copied, while HTTPS protects a connection without confirming the expected owner.

  1. Yes, both signs prove ownership.

    Neither sign alone proves who owns the domain.

  2. No; I check the full domain and the official way to access the service.Correct answer

    The full domain and an independently found channel provide a better origin check.

  3. Yes, if the page loads quickly.

    Page speed says nothing about ownership.

A QR sticker looks as if it covers another one on a parking machine. What do you do?

Why does this matter? A replacement sticker can redirect users to a fraudulent site.

  1. Use the official app, number on the machine or another verified payment method.Correct answer

    Another official route avoids the suspicious code.

  2. Scan it because it is attached to the machine.

    Its location does not prove who placed the sticker.

  3. Enter only the card number, not the security code.

    Partial card data can still be exposed.

You entered card details on a page opened from a QR code. What first?

Why does this matter? The information may already be outside your control even if no charge appears.

  1. Contact the bank immediately through an official number.Correct answer

    The bank can assess protective action for the card and account.

  2. Only clear browser history.

    Clearing history does not retrieve information from the fraudulent site.

  3. Wait to see whether a receipt arrives.

    Waiting delays possible protection.

No registration. Your answers are not sent; the result is just for you.

A QR code is only a route to an address

Read the domain and verify the service independently before continuing.

Recognise phishing

References

Sources and further reading

Domain and data checks follow the Serbian National CERT’s phishing recognition guidance and its electronic commerce publication.

Content last reviewed