Quishing (QR code phishing)
Quishing, short for "QR phishing", is a scam that uses a QR code to lead to a fake site: a payment page, a bank login or a malicious app download.
Updated September 24, 2026
Common forms
- Fake stickers on parking meters, EV chargers or restaurant tables, leading to a fake payment page.
- Phishing emails with a QR code, which slip past some filters because the link is inside an image.
- Unsolicited mail or packages with a QR code "to find out who sent it".
The FTC issued an alert in January 2025 and the FBI's IC3 in July 2025 about these schemes.
Why it matters
As a user: read the domain before opening, distrust shortened links and pay only through official apps. The online QR scanner shows the link before you open it. As a business: brand your codes with your name, use your own domain, and check outdoor stickers regularly. QRTada checks every destination against malicious site lists and blocks flagged codes.
Frequently asked questions
Can a QR code install malware by itself?
No. It leads to an address; the danger lies in what you do next, like entering a password or installing an app.
What if I paid through a fake QR code?
Call your bank right away to dispute the charge, then report the scam at reportfraud.ftc.gov.
Sources
Ready to print a QR code that never dies?
7 days for $0, card required, a reminder 2 days before the first charge, cancel in 2 clicks.