QR Code Scams (Quishing): How to Stay Safe

Quick answer: Quishing is phishing delivered through a QR code. The code itself is harmless โ€” the danger is the page it opens, which is built to steal passwords, card numbers, or a payment. Stay safe by previewing the URL before you open it, checking the domain, watching for stickers pasted over real codes, and never entering credentials on a page a scan opened unexpectedly.

QR codes are everywhere, and that ubiquity is exactly what scammers exploit. We have been trained to scan first and think later โ€” at restaurant tables, on parking meters, on package labels. "Quishing," a blend of "QR" and "phishing," is the rise of scams that hide behind that little square. The good news is that quishing relies almost entirely on human trust rather than any clever hack, which means a few simple habits defeat most of it. This guide explains how these scams work and how to stay one step ahead.

What quishing is

Quishing is phishing that uses a QR code as the delivery method. Traditional phishing arrives as a link in an email or text; quishing wraps that link inside a QR code instead. The aim is the same: get you onto a fraudulent page and persuade you to hand over something valuable โ€” a login and password, a one-time security code, card details, or an approval for a payment.

The reason it works is psychological. A QR code is opaque โ€” you cannot read a URL by looking at the pattern, so you cannot judge where it leads until you scan it. Scammers count on the fact that many people scan and tap through without ever checking the destination. The code also lends a false sense of legitimacy, because we associate them with official menus, posters, and payment signs. Understanding what a QR code actually contains โ€” just encoded text, usually a link โ€” takes away a lot of that mystique; our explainer on what a QR code is covers the fundamentals.

Important: scanning a code does not, by itself, infect your phone. The QR is bait. The harm happens on the page it opens โ€” and only if you act on what that page asks. Recognizing this is the single most useful idea in this article.

How the attacks work

Quishing comes in a handful of recognizable forms. Knowing the playbook makes each one easier to spot.

Stickers over real codes. The classic physical attack. A scammer prints a fake QR sticker and pastes it directly over a legitimate one โ€” on a parking meter, a restaurant table tent, an EV charger, or a payment sign. You scan what looks like the official code and land on the attacker's page. This is cheap, low-tech, and surprisingly common in busy public places.

Fake phishing pages. The code opens a page that imitates a brand you trust โ€” your bank, a delivery service, a parking authority, an email login. It looks right down to the logo, but the web address is subtly wrong. When you "log in," your credentials go straight to the attacker.

Fake payment requests. A code claims to settle a parking fine, a delivery fee, a tax bill, or a small "verification" charge. Following it leads to a payment page controlled by the scammer, or to a request to approve a transfer that actually goes to them. These overlap with payment fraud; our guide on how QR code payments work explains the safe way to pay by code.

Codes in emails and messages. Increasingly, quishing arrives digitally. A QR code embedded in an email or PDF slips past filters that would have flagged a raw link, and asks you to scan it with your phone โ€” moving you off a monitored work computer onto a personal device where you may be less cautious.

Red flags to watch for

Most quishing attempts give themselves away if you pause for a moment. Be suspicious when you see any of these:

How to scan safely

Safe scanning is a short, repeatable routine. None of it takes more than a few seconds.

  1. Preview the URL before opening it. Modern phone cameras show the link as a banner before you tap. Read it. If it does not match where you expect to go, do not open it.
  2. Check the domain carefully. Look at the part right before the first single slash โ€” that is the real domain. yourbank.com is real; yourbank.secure-login.co is not. Watch for misspellings and extra words.
  3. Inspect the physical code. Before scanning a code in public, run a finger over it. A sticker layered on top of another is a clear warning to stop.
  4. Never enter credentials after an unexpected scan. Legitimate menus and information pages do not ask you to log in or pay. If a scanned page demands a password or card number out of nowhere, close it.
  5. Go direct when money or logins are involved. Instead of paying or signing in through a scanned link, open the official app or type the known website address yourself. This single habit defeats nearly all quishing.
  6. Keep your phone and apps updated. Updates close the browser and OS gaps that a malicious page might try to exploit.

If you are unsure how previewing works on your device, our walkthrough on how to scan a QR code shows where the URL preview appears.

Run your own codes from a source you trust

One of the best defenses for a business is to control its own codes. Generate clean, legitimate QR codes for free with QRbug, and use dynamic codes to monitor scans and update destinations without reprinting.

Try QRbug Free

How businesses can protect customers

If you put QR codes in front of customers, you share responsibility for the trust they place in them. A few practices make tampering harder and reassure the people who scan:

For the bigger picture of using QR codes responsibly across your operation, see our overview of QR codes for business.

Frequently asked questions

What is quishing?

Quishing is QR code phishing โ€” a scam that uses a QR code to send you to a fake website or payment page. The goal is to trick you into entering passwords, card numbers, or login codes, or into approving a payment to the attacker.

Can a QR code give my phone a virus just by scanning it?

Scanning alone almost never installs anything. The danger comes after the scan, when you visit the linked page and are persuaded to enter credentials, approve a payment, or download an app. The code is the lure, not the weapon.

How can I tell if a QR code is safe before I act?

Preview the URL your scanner shows before opening it, check that the domain is the real one you expect, and look at the physical code for signs of a sticker pasted over the original. Never enter passwords or payment details on a page a QR code opened unexpectedly.

F
The freeqrcodegenerators.com team
We produce content on QR codes and digital menu technology, in partnership with our technology partner QRbug.