Skip to content
Wednesday, August 26, 2026
KAJ NEWSCYBER · PRIVACY · SECURITY
Home / Threats
Threats

Quishing explained: why scammers love QR codes, and how to scan safely

Quishing is phishing delivered through QR codes — the pattern hides the URL from security tools and your own eyes, so the defense is never scanning codes from unsolicited messages.

Brandi Reed, · March 8, 2026 · 4 min read
ShareXFacebookLinkedInTelegramEmail
Parking meter with a suspicious sticker placed over its QR code

Quishing — QR-code phishing — embeds a malicious link in a QR code instead of clickable text, sending you to a fake login page or a malware download the moment you scan. The trick works because the QR image defeats both of the habits that protect you in email: you cannot hover a QR code to preview its URL, and email security filters read far less reliably inside images than in text. The rule that neutralizes nearly all of it: scan QR codes only from physical materials you have reason to trust — parking meters, restaurant menus, product packaging — and never from emails, texts, or stickers you did not seek out.

How does a quishing attack work?

The attacker generates a QR code pointing to a lookalike domain — a fake Microsoft 365 login, a parcel-redelivery payment page, an office-coffee-list sign-in — and delivers it where your guard is down. Reported variants include fake unpaid-parking invoices mailed as letters, codes on stickers pasted over real codes on parking meters and shared-bike docks (the parking meter and EV-charger sticker scam has recurred in multiple countries), codes inside PDF attachments that evade email link scanners, and codes on posters urging immediate action. Scanning opens the URL in your phone's camera browser, which typically has no password-manager integration, fewer protections than your main browser, and — critically — no address-bar skepticism until the page has already loaded. From there the page is ordinary phishing: harvest credentials, prompt an app install, or process a small fraudulent payment.

Because QR codes move the attack to the device and channel with the weakest defenses. Corporate email filters inspect URLs and attachments aggressively; a code inside an image or PDF often passes untouched. The scan itself shifts the victim from a managed laptop onto a personal phone, outside corporate proxies and endpoint protection. And the destination URL is invisible until after the jump — no hovering, no reading the domain before committing. Cybersecurity agencies including the U.K.'s National Cyber Security Centre and the FBI have issued public warnings about malicious QR codes as adoption of codes for payments and menus has grown.

What are the signs of a malicious code?

Context is nearly everything, but the markers recur:

How do you scan safely?

Four habits, in order of usefulness:

  1. Interrogate the source before raising the camera. Did this code come from something I sought out, or something that sought me out? Treat any code delivered inside a message as a link you would not click — because that is exactly what it is.
  2. Check the preview before opening. Modern phone cameras and QR apps show the decoded URL before visiting. Read the domain with the same skepticism as a link in an email: last two segments, lookalike letters, nothing about "login-secure-verify" in a subdomain.
  3. Prefer the official route. If a code claims to be your bank, parcel service, or parking authority, ignore it and open their app or site yourself. The code adds nothing legitimate that the official channel lacks.
  4. Inspect public codes physically. A sticker placed over another sticker, a code that looks newer than the sign it is on, or a meter whose original payment screen still works — pay the way the machine originally intended and peel or report the overlay.

What if you already scanned and entered something?

The response is the standard phishing playbook, executed on the phone: change the password for the account you entered (and everywhere it was reused), revoke sessions in that account's security settings, contact your bank immediately if payment details were entered, and report the code — to the venue where the sticker was placed, and for U.S. users to the FBI's IC3. Phones are not immune to what follows credential capture, so watch for unexpected app installs and configuration-profile prompts in the days after, and reject any profile you did not deliberately install.

Frequently Asked Questions

Can a QR code itself infect my phone?
No — a QR code is just a text string, usually a URL. The danger is where it sends you: a phishing page or a download. Danger follows after you visit the destination and enter something or install something.
How do I check where a QR code leads before opening it?
Phone cameras and dedicated scanner apps show a preview of the decoded URL before opening it. Read the domain the same way you would read a link in an email — the last two segments of the domain are what count.
Why do scammers use QR codes instead of links?
The code hides the URL from your eyes and from email security filters, and it moves the victim from a protected laptop to a personal phone's browser, which usually has fewer defenses and no password-manager checks.
Are restaurant menu QR codes safe?
Generally yes when printed by the venue on its own materials. The risky codes are those delivered in messages, or physical stickers placed over legitimate codes on meters and chargers — those deserve inspection before scanning.