WebVetted
← Back to guides

Guide

What Is Quishing? The QR Code Scam Explained (With Real Examples)

What is quishing and how does QR code phishing actually work? Learn real examples, red flags, and how to check a QR code before you scan it.

You scan a QR code on a parking meter, a restaurant table tent, or a flyer taped to a pole, and it takes you to a payment page that looks fine, or maybe just slightly off. Or a QR code arrives in an email claiming to be from your bank or IT department, asking you to scan it to verify your account. Either way, something makes you pause before typing in a password or card number.

That pause is worth trusting. Quishing, QR code phishing, has grown quickly precisely because QR codes are so ordinary now that most people scan them without a second thought. Unlike a suspicious link in an email, a QR code hides its destination until after you have already scanned it.

This guide explains what quishing is, walks through real examples of how it has played out, and covers how to check a QR code is safe before you tap anything on the page it opens.

What Is Quishing, Exactly

Quishing is a form of phishing where a scammer embeds a malicious link inside a QR code instead of sending it as a clickable link directly. When you scan the code, your phone opens the link automatically, often taking you to a fake login page, a fraudulent payment form, or a page that silently installs malware.

The name combines "QR code" and "phishing," and the underlying goal is identical to any phishing scam: trick you into handing over credentials, payment details, or personal information, or get you to install something malicious. What changes is the delivery method.

QR codes are effective for this specific reason: the destination is invisible until after you scan it. A traditional phishing email link can sometimes be checked by hovering over it before clicking, but a QR code gives you nothing to inspect visually. You are trusting the code completely until your phone has already opened whatever it points to.

How Quishing Actually Plays Out

Quishing shows up in both everyday physical settings and more targeted digital attacks, and the mechanics differ slightly between them.

Physical quishing often targets places where people expect to scan a code without thinking twice: parking meters, restaurant menus, event flyers, and public charging stations. A scammer prints a fake QR code sticker and places it directly over a legitimate one, so a driver paying for parking or a diner ordering from a table menu scans what looks like the normal code and lands on a convincing fake payment page instead.

Email and workplace quishing tends to be more targeted. A message arrives appearing to come from IT, HR, or a bank, asking the recipient to scan a QR code to verify an account, reset a password, or review a document. Because the QR code appears as an image rather than a text link, it frequently slips past email security filters built to catch suspicious URLs, and because people often scan it on a personal phone, it can also bypass whatever security software protects a work computer.

Government cybersecurity agencies have tracked this shift closely. The FBI's Internet Crime Complaint Center documented a spearphishing campaign using QR codes embedded in fake conference invitations, where scanning the code led to a convincing fake login page designed to harvest credentials. The pattern in that case mirrors what shows up in smaller-scale consumer quishing: a plausible pretext, urgency, and a QR code standing in for a link that would otherwise draw more scrutiny.

How to Check a QR Code Is Safe Before You Scan It

The verification here has to happen mostly before you scan, since the whole risk of quishing is that the destination is hidden until it is too late.

Inspect the physical code for tampering if it is in a public place. Look for a sticker that seems slightly misaligned, raised, or different in material or print quality from the surrounding sign, which can indicate a fake code has been placed over a real one.

Use your phone's built-in preview feature. Most modern phone cameras show a preview of the URL before you tap through to open it, rather than opening the link immediately. Read that URL carefully before proceeding. Look for misspelled domain names, unusual subdomains, or a link shortener hiding the real destination.

Never enter payment or login information on a page you reached by scanning a QR code from an unfamiliar or unverified source, especially in public settings like parking or dining, where you can usually pay through the official app or website directly instead.

For QR codes received by email or text, treat them with the same skepticism as any unexpected link. Verify independently by contacting the organization directly through a known phone number or official website, rather than through any contact information provided in the same message.

If you already scanned a code and are unsure whether the page it opened is legitimate, you can scan a QR code before you tap anything further, which checks the underlying URL and payload for known scam patterns before you enter any information.

As with any check, this is about narrowing risk, not eliminating it entirely. A URL preview that looks clean is a good sign, but new scam domains appear constantly, and no single check catches every fraudulent link. When something feels off about a QR code, the safer move is always to navigate to the organization's known website directly rather than trusting the code.

Who Gets Targeted, and What to Do If You Scanned a Bad Code

Quishing targets everyday situations more than sophisticated ones, which is exactly what makes it effective. Drivers paying for street parking, diners scanning a table menu, and employees responding to what looks like a routine internal request are all common targets, precisely because none of these moments usually trigger much suspicion.

If you scanned a QR code and entered payment or login information on a page that now seems suspicious, act quickly. Change the password on any account you entered, especially if you reused that password elsewhere. Contact your bank or card issuer if you entered payment information, since a quick fraud alert can prevent further charges.

Report a physical fake QR code sticker to the property owner, such as the parking authority or restaurant, so they can remove it and warn other customers. If the quishing attempt was part of a broader scam involving financial loss, file a report with the FBI's Internet Crime Complaint Center (IC3), which tracks these patterns across regions and can connect related reports.

Quishing vs. Regular Phishing: Why Your Usual Instincts Don't Always Catch It

Most people have developed a decent instinct for spotting a suspicious email link: checking the sender, hovering over the URL, noticing poor grammar. Quishing sidesteps nearly all of that. There is no sender to check when the code is on a printed sticker, no text to hover over, and often no email at all involved in the physical version of the scam.

This is also why spam filters and email security tools, which are generally good at catching malicious text links, often miss quishing entirely. The QR code is just an image to most scanning systems, and the real destination only becomes visible once a human scans it with a personal device, outside whatever security tools protect the corporate network.

A Quick Pause Before You Scan Is the Whole Defense

Quishing relies on QR codes feeling too routine to question. Restoring a small amount of friction, checking the physical code for tampering, reading the URL preview before tapping through, and verifying independently when something feels off, closes most of the gap that makes this scam work.

No single habit guarantees you will never encounter a malicious code, since scammers continue to adapt their methods. But treating a QR code with the same healthy skepticism you would give an unexpected link, rather than scanning on autopilot, is what actually keeps you safe. A quick check before you tap through is a small habit that prevents a much larger problem later.

Related guides