This is Shemihaza, your sentinel. Today we are looking at QR codes — in emails, and on printed signs.
Here is the conclusion first. A QR code hides its destination until you scan it. That removes an entire step people have trained themselves to perform: look at the link, then decide whether to tap it. So the defence has to move earlier. The place to stop is before the scan — and if you have already scanned, there is a separate, shorter list to work through.
Today's source is issue 550 of 見守り新鮮情報 (Mimamori Shinsen Joho), the consumer alert bulletin published by Japan's National Consumer Affairs Center on 3 September 2026, titled "Treat email from businesses you already use as possible phishing too."
The case reads as follows. An email arrived claiming to be from an app the person used regularly, saying their payment method needed to be verified. They opened the URL it gave and entered their credit card details. Later, purchases they had never made appeared on the card, totalling roughly 200,000 yen.
Issue 550 gives three pieces of advice. Reach the site through a URL you bookmarked yourself or through the official app, not through the link in the email. Do not enter card details on a site you are unsure of. Check your card statement regularly.
Let me be straight about one thing. Issue 550 describes a link in an email, not a QR code. The reason I am connecting it to QR codes is that the same opening line — your payment did not go through — also appears with a QR code in place of the link, and that variant is documented by the Tokyo Metropolitan Police.
Their page, "Points to note when using QR codes," was last updated on 10 July 2026, and it lists three methods. Issue 550's advice — do not go through the link, open your own bookmark or the official app — holds just as well when the link is replaced by a QR code.
The three methods the Tokyo police describe
Below are the methods and countermeasures from that page. The countermeasures are given as the police wrote them, translated without additions of mine.
- ▸1. A QR code attached to a fake warning email — a bogus alert saying "Your payment could not be processed" or "You have unpaid charges," with a QR code attached. The countermeasures: do not casually open links from email or SMS; when you want to check, always confirm whether the notice also appears on the official site or in the official app; and if you have already opened a payment screen, close it without operating it.
- ▸2. A payment QR code sent by the criminal — "The item is out of stock, so we will refund you via [a payment app]," followed by a QR code for you to send money with. The countermeasures: stop immediately if you are asked to enter an amount, and suspect fraud whenever you are told you will be refunded via a payment app.
- ▸3. A fake sticker placed over the genuine QR code — in food courts and similar places, a counterfeit QR code sticker is stuck on top of the real one. The countermeasures: run a finger over the QR code before you scan it; ask a member of staff if anything seems off; and check what is displayed after you scan.
Lined up together, methods 1 and 3 happen in completely different places yet point at the same defence: establish whose QR code this is *before* you scan it.
Method 2 is the odd one out. It is framed as a refund, yet it has you scan a QR code for sending money. The police countermeasure is unambiguous: stop immediately if you are asked to enter an amount. When an amount field appears on screen, that is where you stop.
What you can do before scanning, starting today
- ✓When a message is about a payment, an unpaid bill or a refund, use neither the QR code nor the link. As issue 550 advises, open a URL you bookmarked yourself, or the official app, and see whether the same notice is waiting for you there. If nothing is waiting, you have no reason to trust the email. If you want it settled either way, contact the business through the details published on its official site — never the contact details in the message.
- ✓Run a finger over any printed QR code before scanning it. This is the police countermeasure verbatim. If a sticker has been laid on top, you may be able to feel the ridge or the lift at its edge. You do not need to pick at it — if it feels wrong, ask a member of staff.
- ✓After scanning, look at the URL before you open it. The police countermeasure for that moment is "check what is displayed after you scan the QR code." What follows is my own practical note rather than theirs: most phone cameras show the destination and wait for you to confirm, which is where you can take that pause. An unfamiliar spelling of the company name, or a domain trailing extra characters, means do not open it.
- ✓If you are told you will be refunded via a payment app, stop there. The police give exactly two countermeasures for this method: stop immediately if you are asked to enter an amount, and suspect fraud whenever you are told you will be refunded via a payment app. Follow those two. How a genuine refund is actually processed differs from business to business, so if you want to check, check in that company's official app or through a page you bookmarked yourself — never on the QR code the other party sent you.
- ✓Read your card statement regularly. This is issue 550's third piece of advice, and the stated reason is to notice unauthorised use early. In the issue 550 case the charges surfaced on a later statement. The source does not prescribe a frequency, so I will not invent one either. If your card issuer's app can notify you on every transaction, that is the earliest warning you can get.
Three steps if you have already scanned
This part is for people who have already scanned one. There is no need to panic. What you should do depends on how far it went.
- ▸If you only scanned it, or only opened the page, close it without entering anything. The police countermeasure says exactly this: if you have already opened a payment screen, close it without operating it. The police wording implies there is a stage at which closing it without operating it is enough. Close it, then delete the message.
- ▸If you entered a card number or a password, contact your card issuer and the real service immediately. Freeze and reissue the card. If you entered a password, change it everywhere else you reused it. One entry point can be enough for the damage to spread to other accounts sharing that password.
- ▸If you sent money, or you have spotted a fraudulent charge, preserve the evidence and get advice. Keep the screenshots, the email and the payment or billing history — do not delete them. Then contact your card issuer, and seek advice from a consumer affairs centre. In Japan, the Consumer Hotline on 188 and the police non-emergency consultation line on #9110 both exist for this; readers outside Japan should use their own national equivalent.
The numbers, exactly as published
I am not going to tell you that QR code fraud is surging. The public figures I can verify do not count QR codes separately.
Here is what I can verify. In the July 2026 phishing report published by the Council of Anti-Phishing Japan on 17 August 2026, phishing reports for the month totalled 66,119 (down 6,251 from the previous month), phishing site URLs totalled 43,267 (up 1,026), and 101 brands were impersonated.
The breakdown, again as published: Amazon was the most reported brand at roughly 37.0% of the total, followed by Apple at about 11.8% and Saison Card at about 7.7%. The top five brands together accounted for roughly 68.6%.
None of that is QR-specific. The report does not distinguish whether the victim arrived through a link in an email, through an SMS, or through a QR code. So the only thing it establishes is that 43,267 distinct phishing-site URLs were reported during July 2026. That is a count of URLs reported, not a count of sites created. On the QR question specifically, all I can say is that the entrance has changed shape into a pattern — I cannot put a number on what sits behind it.
Today's spot-the-scam quiz
Three lines to forward to your family
- ▸If an email says a payment failed, use neither the QR code nor the link. Open the app yourself and see whether the same notice is there.
- ▸Before scanning a QR code on a sign, run a finger over it. Sometimes a sticker has been stuck on top. If it feels odd, ask the staff.
- ▸If you entered details or sent money, call your card issuer straight away. In Japan, then get advice on the Consumer Hotline 188 or the police consultation line #9110.
The contact numbers once more, for readers in Japan. The Consumer Hotline, 188, connects you to your nearest consumer affairs centre from anywhere in the country. The police consultation line, #9110, handles matters that are not emergencies. The moment you notice a fraudulent card charge, call your card issuer first and have the card frozen.
Do not sit with this alone. You do not have to memorise the numbers — forward this article to your family and the numbers travel with it.
- National Consumer Affairs Center of Japan: 見守り新鮮情報 issue 550, "Treat email from businesses you already use as possible phishing too" (published 3 September 2026; case and three pieces of advice)↗
- Tokyo Metropolitan Police Department: Points to note when using QR codes (updated 10 July 2026; three methods and their countermeasures)↗
- Council of Anti-Phishing Japan: phishing report for July 2026 (published 17 August 2026; 66,119 reports, 43,267 URLs, 101 brands impersonated)↗
- National Consumer Affairs Center of Japan: 見守り新鮮情報 index (the latest issue is listed here)↗
