Skip to content

Quishing: how to spot a malicious QR code

Quishing is phishing through QR codes: a fake code leads to a fake site that steals a payment or login. Before opening a code you found on the street or received in the mail, read the domain; when in doubt, enter nothing.

By The QRTada team7 min read

What is quishing?

The word blends "QR" and "phishing". The trick is old, the medium is new: instead of a link in an email, the scammer uses a QR code. That has two advantages for them. The link stays invisible until you scan, and an image slips past some email security filters, which scan the text of links.

Much of the measurement comes from security vendors, so read their numbers as vendor data. Keepnet Labs estimates that about 12% of phishing attacks contained a QR code in 2025, and cites a 331% year-over-year increase reported by Cofense between 2023 and 2024.

Why do scammers love QR codes?

Three reasons. The link is hidden: you can hover over a link in an email, but a printed QR code is just a pattern. Scanning is routine: since 2020 we scan to read menus, pay for parking and check in to events without thinking. Scanning happens on phones, often less protected than a work laptop, with small screens where a lookalike address slips by. Fake sites copy real ones closely: the city logo, the parking operator's colors, a familiar card form. Often the only visible difference is the address.

What does a quishing attack look like, step by step?

  1. The scammer prints stickers with a QR code pointing to a lookalike domain, such as a city name with an extra word or a slightly misspelled operator.
  2. They stick them over the real codes on parking meters in busy areas, usually at night.
  3. A driver scans, lands on a page with the city's logo and a familiar payment form, and enters card details.
  4. The page shows a fake confirmation. The card is charged or resold, and the driver may still get a parking ticket because nothing was actually paid.

The email version works the same way: a message about a package, an invoice or a locked account includes a QR code instead of a link, pushing you to scan with your phone, outside your work computer's security tools.

Where do fake QR codes show up?

  • Parking meters and EV chargers: a sticker placed over the real code leads to a fake payment page. Several US cities have warned drivers about it.
  • Emails: fake delivery notices, invoices or account security alerts with a QR code "to verify".
  • Unsolicited packages: the FTC (January 2025) and the FBI's IC3 (July 2025) warned about unexpected packages containing a QR code "to find out who sent it".
  • Restaurant tables, posters, flyers: a fake code stuck over the business's own.

How do you check a code before opening it?

  1. Look at the surface: a sticker layered over another, misaligned, on public equipment is a red flag.
  2. Read the domain in your phone's banner before tapping. It should match the city, operator or brand, with no misspellings.
  3. Distrust shorteners (bit.ly, tinyurl and the like) on official signage: they hide the destination.
  4. Resist urgency: "your parking expires" or "your account will be locked" are classic pressure tactics.
  5. Pay through the official app rather than a page opened from a QR code on the street.

The QRTada online scanner shows a code's content and checks the link (domain, encryption, shortener) without opening it. Handy for a code that arrived by email on your laptop.

What if you entered your details?

  • Card details: call your bank to dispute the charge and replace the card, then watch your statements.
  • Password: change it everywhere you use it, and turn on two-factor authentication.
  • Report it: at reportfraud.ftc.gov, and to the FBI at ic3.gov if money was lost. Tell the city or operator about the fake sticker.
  • Keep evidence: screenshots of the page and a photo of the code.

Teaching your team and family

The best defense is a shared habit. At work, add QR codes to phishing awareness training: an email asking you to scan a code to "reactivate an account" or "sign a document" is a suspicious link like any other. At home, explain to less tech-savvy relatives that a QR code is neither a guarantee nor a danger in itself: it is a link, and you check a link before paying. One simple rule helps: never enter a payment or password on a page opened from a code found on the street.

How do businesses protect their codes?

Protection steps for businesses
StepEffect
Branded frame with your nameA generic fake sticker stands out
Your own domain (qr.yourbrand.com)Customers see your name before opening
"Our codes only lead to ..." noticeCustomers know which domain to expect
Regular checks of outdoor piecesSpots stickers placed on top
No direct payment by QR on public equipmentRemoves the incentive

At QRTada, every destination is checked against malicious site lists at creation and on every edit, and reported codes are blocked after review. Custom domains are included on Pro. The glossary sums up quishing on one page.

Frequently asked questions

Can scanning a QR code hack my phone?

Scanning alone does not. The danger is the page it opens: entering data, paying, installing an app.

How can I tell if a QR code is a scam?

Read the domain before opening, check the surface was not covered, and distrust any request for payment or credentials.

Are restaurant QR codes safe?

Usually, but a fake sticker can be placed on a table. The domain should match the restaurant or its menu provider.

Are QR codes in bank emails trustworthy?

Be skeptical by default: a bank has no need to make you scan a code to verify an account. Use the app or site you normally use instead.

Sources

Ready to print a QR code that never dies?

7 days for $0, card required, a reminder 2 days before the first charge, cancel in 2 clicks.