QR Code Scams (Quishing): How to Stay Safe
QR codes are everywhere, and that ubiquity is exactly what scammers exploit. We have been trained to scan first and think later โ at restaurant tables, on parking meters, on package labels. "Quishing," a blend of "QR" and "phishing," is the rise of scams that hide behind that little square. The good news is that quishing relies almost entirely on human trust rather than any clever hack, which means a few simple habits defeat most of it. This guide explains how these scams work and how to stay one step ahead.
What quishing is
Quishing is phishing that uses a QR code as the delivery method. Traditional phishing arrives as a link in an email or text; quishing wraps that link inside a QR code instead. The aim is the same: get you onto a fraudulent page and persuade you to hand over something valuable โ a login and password, a one-time security code, card details, or an approval for a payment.
The reason it works is psychological. A QR code is opaque โ you cannot read a URL by looking at the pattern, so you cannot judge where it leads until you scan it. Scammers count on the fact that many people scan and tap through without ever checking the destination. The code also lends a false sense of legitimacy, because we associate them with official menus, posters, and payment signs. Understanding what a QR code actually contains โ just encoded text, usually a link โ takes away a lot of that mystique; our explainer on what a QR code is covers the fundamentals.
How the attacks work
Quishing comes in a handful of recognizable forms. Knowing the playbook makes each one easier to spot.
Stickers over real codes. The classic physical attack. A scammer prints a fake QR sticker and pastes it directly over a legitimate one โ on a parking meter, a restaurant table tent, an EV charger, or a payment sign. You scan what looks like the official code and land on the attacker's page. This is cheap, low-tech, and surprisingly common in busy public places.
Fake phishing pages. The code opens a page that imitates a brand you trust โ your bank, a delivery service, a parking authority, an email login. It looks right down to the logo, but the web address is subtly wrong. When you "log in," your credentials go straight to the attacker.
Fake payment requests. A code claims to settle a parking fine, a delivery fee, a tax bill, or a small "verification" charge. Following it leads to a payment page controlled by the scammer, or to a request to approve a transfer that actually goes to them. These overlap with payment fraud; our guide on how QR code payments work explains the safe way to pay by code.
Codes in emails and messages. Increasingly, quishing arrives digitally. A QR code embedded in an email or PDF slips past filters that would have flagged a raw link, and asks you to scan it with your phone โ moving you off a monitored work computer onto a personal device where you may be less cautious.
Red flags to watch for
Most quishing attempts give themselves away if you pause for a moment. Be suspicious when you see any of these:
- A sticker on top of a sticker. Edges that peel, a code taped onto a printed sign, or a fresh-looking square over a worn surface.
- Pressure and urgency. "Pay within 24 hours or face a fine," "verify your account now," "your delivery is on hold." Urgency is the scammer's favorite tool.
- A request for credentials. Any page reached via QR that asks for a password, a one-time code, or full card details deserves deep suspicion.
- A mismatched or odd domain. The URL preview shows a misspelled brand, a random string, or a shortener you cannot verify.
- An unexpected code. A QR in an unsolicited email, a flyer under your windshield wiper, or a letter about a refund you never requested.
- Out-of-place placement. A payment code handwritten on a slip of paper, or a code in a context where the real business would never use one.
How to scan safely
Safe scanning is a short, repeatable routine. None of it takes more than a few seconds.
- Preview the URL before opening it. Modern phone cameras show the link as a banner before you tap. Read it. If it does not match where you expect to go, do not open it.
- Check the domain carefully. Look at the part right before the first single slash โ that is the real domain.
yourbank.comis real;yourbank.secure-login.cois not. Watch for misspellings and extra words. - Inspect the physical code. Before scanning a code in public, run a finger over it. A sticker layered on top of another is a clear warning to stop.
- Never enter credentials after an unexpected scan. Legitimate menus and information pages do not ask you to log in or pay. If a scanned page demands a password or card number out of nowhere, close it.
- Go direct when money or logins are involved. Instead of paying or signing in through a scanned link, open the official app or type the known website address yourself. This single habit defeats nearly all quishing.
- Keep your phone and apps updated. Updates close the browser and OS gaps that a malicious page might try to exploit.
If you are unsure how previewing works on your device, our walkthrough on how to scan a QR code shows where the URL preview appears.
Run your own codes from a source you trust
One of the best defenses for a business is to control its own codes. Generate clean, legitimate QR codes for free with QRbug, and use dynamic codes to monitor scans and update destinations without reprinting.
Try QRbug FreeHow businesses can protect customers
If you put QR codes in front of customers, you share responsibility for the trust they place in them. A few practices make tampering harder and reassure the people who scan:
- Use tamper-evident placement. Print codes directly onto menus, signage, or laminated cards rather than relying on loose stickers that are trivial to cover.
- Inspect public codes regularly. Staff should glance at customer-facing codes during opening checks and remove anything pasted on top.
- Show the destination openly. Print a short, readable URL or your brand next to the code so customers can confirm where it should lead. A code with no context is easier to fake.
- Use codes from a reputable generator. Create your codes with a trusted tool โ you can make them free with the QRbug QR code generator โ and keep a record of where each one points.
- Prefer dynamic codes you control. A dynamic code routes through your own short domain, so you can see scan activity and swap a destination instantly if something looks wrong โ far safer than a static code you cannot monitor.
- Educate your customers gently. A small note like "Our menu link only goes to our website" sets the expectation that makes a fake code obvious.
For the bigger picture of using QR codes responsibly across your operation, see our overview of QR codes for business.
Frequently asked questions
What is quishing?
Quishing is QR code phishing โ a scam that uses a QR code to send you to a fake website or payment page. The goal is to trick you into entering passwords, card numbers, or login codes, or into approving a payment to the attacker.
Can a QR code give my phone a virus just by scanning it?
Scanning alone almost never installs anything. The danger comes after the scan, when you visit the linked page and are persuaded to enter credentials, approve a payment, or download an app. The code is the lure, not the weapon.
How can I tell if a QR code is safe before I act?
Preview the URL your scanner shows before opening it, check that the domain is the real one you expect, and look at the physical code for signs of a sticker pasted over the original. Never enter passwords or payment details on a page a QR code opened unexpectedly.