Google Account QR Code Scam: What to Do After Scanning

A QR code that asks you to sign in to Google, approve a device, or re-enroll authentication deserves caution. Scanning alone usually is not the dangerous step. Typing credentials, approving a prompt, or granting access is.

Common Google account QR scams

  • Fake Google login pages. A QR code in an email, invoice, classroom post, or workplace message opens a page styled like Google sign-in and captures your password.
  • Device approval lures. The page asks you to approve a new device, browser, or session without explaining why.
  • Authenticator re-enrollment scams. A message claims your MFA is expiring and sends a QR code to "reset" Google Authenticator.
  • Third-party access traps. You are asked to grant an unfamiliar app access to Gmail, Drive, Calendar, or contacts.

This is a form of QR code phishing in email and overlaps with Google Authenticator QR code scams.

What to check now

  1. Open your Google Account directly. Type the address yourself or use the official Google app. Do not return through the QR page.
  2. Review recent security activity. Look for unfamiliar sign-ins, devices, locations, browsers, or recovery changes.
  3. Remove unknown devices. Sign out anything you do not recognize.
  4. Change your password if you entered it after scanning the QR code.
  5. Revoke suspicious app access. Remove third-party apps that can read Gmail, Drive, contacts, or Calendar if you did not approve them intentionally.
  6. Check Gmail forwarding and filters. Attackers often add rules that silently forward messages or hide security alerts.

If emails were sent from your account, use the recovery steps in I scanned a QR code and emails were sent from my account.

When the risk is lower

If you scanned the code, saw a page, and closed it without typing, approving, installing, or granting anything, the risk is usually low. Still, it is reasonable to check recent security activity and watch for new alerts.

The warning sign is context. A Google QR code shown inside the account settings you opened yourself is different from a QR code pushed through a message that says urgent action is required.

Frequently asked questions

Can a Google account QR code be a scam?

Yes. A QR code that asks you to sign in, approve a device, reset MFA, or verify your Google account can be part of a phishing or account-linking scam, especially if it came by email, text, chat, PDF, or a support message.

Did scanning alone compromise my Google account?

Usually no. Scanning alone is lower risk. The account risk rises if you typed your password, approved a login, entered a one-time code, installed a profile or app, or granted access to an unfamiliar third-party app.

What should I check in my Google account now?

Review recent security activity, remove unknown devices, change your password if you entered it, revoke suspicious third-party app access, check forwarding rules in Gmail, and turn on stronger two-step verification.

How can QRsafer help with Google login QR codes?

QRsafer previews the destination URL before the page opens, which helps you spot lookalike Google login pages and suspicious redirect chains before entering credentials.

Check login QR codes before they open

QRsafer previews QR destinations so fake login pages and suspicious redirects are easier to spot before you enter credentials.

Related guides