QR Safety, Scams & Exploits

QR Code Scams: What Is Quishing?

'Quishing' is phishing with QR codes. How attackers use codes to steal logins and money, and how to protect yourself.

Quishing is QR-code phishing: a scam where the bait is a scannable square instead of a clickable link. The code looks harmless, but it quietly carries you to a fake login page, a bogus payment request, or a malicious download. Understanding how quishing works is the first step to shrugging it off. 🐾

Phishing has always followed people to wherever they read. It moved from postal mail to email, then to text messages, and now it has learned a new trick: hiding the destination inside a QR code. Because a code is just a picture, most of the warnings we've trained ourselves to notice — a weird link, a misspelled domain — are invisible until the moment you scan. Let's unpack exactly what quishing is, why it slips past defenses that catch ordinary phishing, and how to stay a step ahead.

What does "quishing" actually mean?

The word is a blend of "QR" and "phishing." In a quishing attack, a criminal encodes a link to a malicious website into a QR code, then places that code somewhere a victim will trust it: an email that looks like it's from IT, a flyer on a wall, a sticker on a parking meter, or a letter about an "unpaid" bill. When the victim scans, their phone opens the attacker's page — often a convincing copy of a real login screen — and any username, password, or card number they type goes straight to the criminal.

The crucial thing to hold onto is that the QR code itself does nothing clever. It's a container for text, usually a web address. The danger is entirely in where that address leads. We explore that idea in depth in can a QR code hack your phone?

How does a quishing attack unfold?

Most quishing follows a simple, repeatable script:

  1. The lure. You receive or encounter a QR code with a plausible reason to scan it — "verify your account," "pay for parking," "view the menu," "reset your MFA."
  2. The scan. You point your phone camera at the code. It decodes a URL and offers to open it.
  3. The look-alike page. The link opens a page dressed up as a service you recognize: your email provider, your bank, a delivery company, your employer's sign-in portal.
  4. The harvest. You enter credentials or payment details, believing you're logging in normally. The attacker captures them in real time.
  5. The exploitation. With your details, the criminal drains an account, makes purchases, or uses your login to break into a company network.
A quishing code isn't magic. It's a signpost pointing to a trap — and the whole scam depends on you not checking the sign before you follow it.

Why does quishing slip past filters that catch email phishing?

Ordinary phishing emails get caught because security systems are very good at reading text. They scan the body of a message, extract every link, and check those links against blocklists of known-bad domains. A QR code defeats this in a beautifully simple way: to a text scanner, it's just an image. There's no clickable link to inspect — only a picture of black and white squares.

This is why criminals increasingly embed a code as an image inside a phishing email. The message sails through filters that would have flagged the same link in plain text. We go deeper on this tactic in QR codes in phishing emails.

The PC-to-phone pivot

There's a second, subtler reason attackers love QR codes in a workplace: they move the victim from a managed, well-defended office computer to a personal phone. Your work laptop may have URL filtering, endpoint protection, and a locked-down browser. Your phone, scanned in a hurry between meetings, usually has none of that corporate armor. By putting a code on the screen, the attacker hands the victim a way to walk right around the company's defenses.

Where do people run into quishing?

Quishing thrives anywhere a code feels ordinary:

  • Email and internal messages — fake MFA resets, "your mailbox is full," shared-document notifications.
  • Public stickers — codes stuck over the real ones on parking meters, EV chargers, and restaurant tables. See fake parking meter QR codes.
  • Physical mail — letters about "unpaid tolls," missed deliveries, or tax refunds, each with a code to "resolve" it.
  • Posters and flyers — event or charity codes that redirect to donation-skimming pages.
  • Overlaid on legitimate signage — a topic we cover in how attackers sticker over legitimate QR codes.

What are the warning signs of a quishing code?

You can spot most quishing attempts with a little healthy skepticism:

Red flagWhy it matters
Urgency ("act within 24 hours")Pressure stops you from checking the destination
A code where you'd expect a normal linkOften a deliberate move to dodge filters
A sticker that looks added-on or misalignedMay be covering a genuine code
The page asks for a password or paymentLegitimate flows rarely start from a random scan
The domain looks almost-but-not-quite rightLook-alike domains are the classic phishing tell

How do I protect myself from quishing?

The single most powerful habit is to preview the link before you open it. Most modern phone cameras show the decoded URL before loading it — read that address and ask whether it truly belongs to the organization you expect. A tool that surfaces the real destination first, like the way you can scan a code safely with QR Puppy, turns an invisible link into one you can actually judge.

Beyond that:

  • Never enter credentials or card details on a page you reached by scanning an unexpected code. Instead, open the app or type the known website address yourself.
  • Distrust urgency. Real organizations don't lock your account because you took ten minutes to verify a message through another channel.
  • Check the domain closely for look-alikes and shorteners, as covered in QR codes and malicious URLs.
  • Keep your phone's OS updated so that even if you land on a hostile page, known browser exploits are patched.
  • Run through our QR code safety checklist whenever a code feels even slightly off.

Is quishing really that common?

QR codes are everywhere now — on menus, packaging, transit, and advertising — and that ubiquity is exactly what makes quishing viable. When scanning a code is a normal, everyday act, a malicious one doesn't stand out. The good news is that the defense is equally everyday: a moment's pause to read the destination defuses almost every attempt. You don't need special software or technical skill, just the habit of looking before you leap.

Frequently asked questions

Is quishing different from regular phishing?

The goal is identical — trick you into handing over credentials, money, or access. The delivery is what differs: quishing uses a QR code instead of a visible link, which hides the destination until you scan and helps the message evade text-based email filters.

Can just scanning a quishing code harm me?

Scanning alone typically only decodes a link and offers to open it. The harm comes from visiting the malicious page and then entering information or downloading something. That's why previewing the URL and not acting on it is such an effective defense.

Why do attackers put QR codes in emails?

Because a code is an image, not text, so many email security filters can't read the hidden link and let the message through. Codes also nudge victims from a protected work computer to a less-defended personal phone.

How can I check where a QR code leads before opening it?

Most phone cameras display the decoded URL before loading it — read that carefully. A scanner that reveals the true destination first lets you judge the domain for look-alikes and shorteners before you ever tap through.

What should I do if I already entered details on a quishing page?

Change the password for that account immediately and anywhere you reused it, enable multi-factor authentication, and watch for suspicious activity. If card details were involved, contact your bank. Then report it, as described in our guide to reporting malicious QR codes.

Make a QR code the honest way 🐾

Free forever, no tracking, no expiry — generated right in your browser.

🎨 Create a QR code →