TTemp90
T
← Back to BlogPrivacy

What Is Quishing? QR Code Phishing Explained

Learn what quishing (QR code phishing) is, how attackers use malicious QR codes to steal your information, and how to scan QR codes safely.

What Is Quishing? QR Code Phishing Explained

What Is Quishing?

Quishing (a blend of "QR" and "phishing") is a phishing attack that uses QR codes to direct victims to malicious websites or trigger harmful actions. As QR codes have become ubiquitous — on restaurant menus, payment systems, parking meters, advertisements, and packaging — attackers have adopted them as a new vector for phishing, exploiting the trust and convenience people associate with scanning codes.

Quishing is particularly insidious because a QR code's destination is not visible to the human eye. You cannot see where a QR code leads until you scan it, making it easy for attackers to disguise malicious links as legitimate ones.

Why Quishing Works

Hidden destinations: Unlike a clickable link where you might see the URL, a QR code's destination is invisible until scanned. You cannot evaluate it beforehand.

Trust and convenience: People have grown comfortable scanning QR codes quickly without scrutiny, especially in everyday contexts like restaurants and payments.

Bypasses some email security: QR codes embedded in emails as images can bypass security filters that scan for malicious links, since the malicious URL is hidden in the image.

Mobile context: QR codes are scanned with phones, where smaller screens and mobile browsers make it harder to scrutinize the destination, and where security awareness may be lower.

How Quishing Attacks Work

Malicious QR codes: Attackers create QR codes leading to phishing sites and distribute them through various channels.

Physical placement: Placing malicious QR codes in public — stickers over legitimate codes on parking meters, payment terminals, restaurant tables, or posters.

Email and digital quishing: Embedding malicious QR codes in phishing emails, often claiming you need to scan to verify an account, view a document, or complete an action.

The phishing destination: Scanning leads to a fake site that steals credentials, payment information, or personal data — or prompts a malicious download.

Common Quishing Scenarios

Fake payment codes: Malicious codes replacing legitimate ones on parking meters, payment terminals, or invoices, directing payments or capturing card details.

Account verification scams: Emails with QR codes claiming you must scan to verify or secure an account, leading to credential phishing.

Fake promotions: QR codes promising deals, prizes, or content that lead to phishing or malware.

Tampered public codes: Stickers placed over legitimate QR codes in public spaces, redirecting to malicious sites.

How to Scan QR Codes Safely

Preview the URL before opening: Most modern phone cameras and QR scanners show the destination URL before opening it. Read this URL carefully — verify it matches the expected, legitimate domain before proceeding.

Be cautious with unexpected codes: Treat QR codes in unsolicited emails, messages, and unexpected contexts with the same skepticism you apply to suspicious links.

Inspect physical codes: Before scanning a QR code in public (payment terminals, parking meters), check whether it appears tampered with — a sticker placed over another code is a warning sign.

Do not scan codes from untrusted sources: Be wary of QR codes from unknown senders, random flyers, or suspicious placements.

Verify payment codes carefully: For payments, confirm the QR code and destination are legitimate. When in doubt, use official apps or websites rather than scanning a code.

Do not enter credentials after scanning: If scanning a code leads to a login page, be especially cautious — navigate to the service directly instead of logging in through a scanned link.

Keep your phone secure: Updated software and security settings help protect against malicious actions triggered by quishing.

The Email Quishing Defense

Quishing in emails is increasingly common because QR codes can bypass link-scanning security. When you receive an email asking you to scan a QR code — to verify an account, view a document, or take action — apply phishing skepticism:

  • Be suspicious of unexpected requests to scan codes
  • Verify the request through official channels
  • Navigate to the service directly rather than scanning
  • Remember that legitimate account actions rarely require scanning a QR code from an email

Frequently Asked Questions

How can I see where a QR code leads before opening it?

Most modern phone cameras and QR scanner apps display the destination URL before opening it. When you scan, pause and read this URL carefully — verify it matches the expected, legitimate domain before tapping to proceed. This preview is your main defense against quishing.

Are QR codes on restaurant menus and payment terminals safe?

Generally yes, but check for tampering — attackers sometimes place malicious stickers over legitimate codes. Inspect physical codes for signs of tampering, preview the URL before proceeding, and be cautious if a scanned code unexpectedly asks for login credentials or payment details in an unusual way.

Can scanning a QR code automatically hack my phone?

Simply scanning a QR code typically just opens a URL or prompts an action — it does not automatically compromise your phone. The danger comes from what you do next: visiting a phishing site and entering information, or downloading malicious content. Previewing the URL and not entering information on suspicious sites protects you.

Conclusion

Quishing exploits the convenience and hidden destinations of QR codes to direct victims to phishing sites and malicious actions. Because a QR code's destination is invisible until scanned, attackers easily disguise malicious links — placing tampered codes in public, embedding them in phishing emails to bypass security filters, and exploiting the casual trust people place in scanning. The key defense is to preview the destination URL before proceeding, treat unexpected QR codes with phishing-level skepticism, inspect physical codes for tampering, and never enter credentials on sites reached by scanning. As QR codes become ever more common, this awareness protects you from an increasingly popular attack vector.

More from Temp90

Privacy resources made simple

FAQCommon temporary email questions. Trust CenterService status and transparency. Privacy PolicyHow Temp90 protects privacy. Terms of UseRules for using Temp90 safely.