What is quishing?
Quishing is phishing through a QR code. Instead of a suspicious link in an email, the attacker hides the link inside a code. Nobody can read a QR code with the naked eye, so you only see the destination after you scan it.
The code itself is just a container for text, usually a web address. Scanning it does not install anything on its own. The danger starts on the page it opens: a fake login form, a copied payment page or a prompt to download an app.
Consumer protection agencies and police in several countries have published warnings about QR scams. The reassuring part: a few simple habits protect you against the most common tricks, and none of them require special apps.
Why scammers like QR codes
A printed code looks official, and people trust the place where it hangs – a parking meter, a restaurant table, a letter with a logo. Email filters also have a harder time checking a link that is stored inside an image.
What a scammer is after
Usually one of three things: your login details, your card details, or a way to get unwanted software onto your phone. Every tip in this guide blocks at least one of those routes.
Common QR code scams to know
Most QR scams follow a handful of patterns. Recognising them is already half the protection.
Stickers over real codes
A fraudster prints a code and sticks it over the genuine one on a poster, meter or menu. The sticker leads to a look-alike page. Raised edges, a second layer or a code that sits slightly crooked are warning signs.
Fake payment and parking codes
Codes on parking meters, charging stations or invoices are popular targets, because you already expect to pay. The fake page collects your card details and sometimes quietly adds a recurring charge.
QR codes in emails and letters
A message claims your account is locked, a parcel is waiting or a fine is unpaid, and asks you to scan a code. Urgency, threats and deadlines are classic phishing signs, whether the link is typed or hidden in a code.
Codes that start downloads
A code that opens a file download or an unfamiliar app page can lead to unwanted software. Install apps only from the official app store, and only when you were looking for that app anyway.
Too-good-to-be-true offers
A code on a lamp post or flyer that promises a prize, a free gift card or a refund deserves the same suspicion as an email promising the same thing.
How to check a QR code before you open it
Your phone gives you a moment between scanning and opening. Use it. If you want to see a code's full content without visiting the page, decode it first with a QR code reader.
-
Look at the code itself
Is it printed as part of the sign, or stuck on top? Is the surface peeling or misaligned? If something looks off, don't scan it – ask staff or find another way to reach the service.
-
Read the link preview
iPhone and Android cameras show the web address before opening it. Check the domain, the part right before the first single slash: “pay.cityparking.example” is not the same as “cityparking-pay.example”.
-
Check the page before typing
Does the page clearly belong to the place where you found the code? Does the address start with HTTPS? Be wary of pages that immediately ask for passwords, card numbers or an app install.
-
When in doubt, go direct
Type the company's web address yourself or open its official app. You lose a few seconds instead of your card details.
Red flags in a scanned link
-
A domain that is almost right
Swapped or doubled letters, extra hyphens, or added words such as “secure”, “verify” or “login” next to a brand name.
-
An unfamiliar short link
Short links hide the final destination. Many legitimate codes use them, so this alone is not proof of fraud – but check the page it lands on even more carefully.
-
Instant requests for data
A menu, a timetable or a product page never needs your password. A login or card form right after a scan should make you stop and think.
-
Pressure and countdowns
“Pay within 10 minutes or your car will be towed” is designed to stop you thinking. Genuine operators give you time and official channels.
-
Unexpected downloads or permissions
A page that starts a download or asks to install a profile, certificate or app is a strong reason to close it.
Extra care with QR payments and parking meters
Payment codes deserve the most attention, because the damage is direct.
-
Prefer the official app or the machine
If the meter takes cards or the operator has an app, use it instead of a code whose origin you can't confirm.
-
Compare with the signage
Operators usually print their name and website on the sign. The domain in the scanned link should match it.
-
Read the payment page
A one-off parking fee should not come with a membership, a monthly plan or a pre-ticked subscription box.
-
Check your statement afterwards
Look for the exact amount in your banking app. Report any charge you don't recognise to your bank as soon as possible.
-
Ask at restaurants
A table code that opens the menu is normal. If a code asks for payment, check with staff that it belongs to the venue's own ordering or payment system.
QR code security tips for businesses
If you put QR codes in front of customers, you can make them much harder to abuse – and easier for people to trust.
Use a branded domain
A link on your own domain, such as go.yourbrand.com, is easier to recognise in the phone preview than a generic short link. With a custom domain, your dynamic codes use your own address, so customers see a name they already know.
Make tampering visible
Print codes directly on the material instead of adding stickers, place them behind glass or under lamination, and position them where staff can see them. A line such as “Our code only opens yourbrand.com” tells customers what to expect.
Check your codes regularly
Add QR codes to routine rounds, such as opening or cleaning checks. Look for stickers, scan each code and confirm it opens the right page.
Use dynamic codes you can switch off
A dynamic QR code points to a short link you control. If a code is copied, damaged or misused, you can deactivate it or change its destination without reprinting everything else.
Keep an eye on scan data
Scan statistics help you notice changes. A sudden drop in scans at one location can mean a code has been covered. QR code analytics show scans over time, by operating system and by approximate location.
Never ask for sensitive data straight after a scan
Design your flows so a scan leads to useful content first. If you take payments, use a checkout your customers recognise and explain it on the sign.
Static vs dynamic QR codes: the security angle
Both kinds are equally safe to scan. The difference is how much control you keep once the code is printed. Our guide to static and dynamic QR codes explains the rest.
| Static | Dynamic | |
|---|---|---|
| Works without any third-party service | Yes | No |
| Deactivate the code if it is misused | No | Yes |
| Fix a wrong destination after printing | No | Yes |
| Scan statistics to spot unusual changes | No | Yes |
| Link can use your own domain | Yes | Yes |
What to do if you scanned a malicious code
Opening a suspicious page is rarely the real problem. What matters is what happened next, so act according to how far you got.
- You only opened the page: close the tab and don't go back to it.
- You entered a password: change it right away on the real website, plus anywhere you reused it. Turn on any extra sign-in protection the service offers.
- You entered card details: contact your bank or card issuer immediately and ask them to block the card.
- You installed something: remove it, run your phone's built-in security check and install pending system updates.
- Tell the owner: let the shop, venue or operator know so they can remove the fake code. You can also report it to the police or your national cybercrime or consumer protection authority.
Make your QR codes easy to trust
Put dynamic QR codes on your own domain and switch any code off from your dashboard if it is ever misused.