What Is Quishing? QR Code Scams Explained
What Is Quishing (QR Code Scams)?
Quishing — a blend of "QR code" and "phishing" — is the use of malicious QR codes to trick people into visiting harmful websites, revealing information, or taking harmful actions. As QR codes have become common for menus, payments, and information, scammers have started exploiting the fact that you cannot tell where a QR code leads just by looking at it. This makes QR codes an effective tool for phishing and fraud. This guide explains what quishing is, how it works, where it appears, and how to scan QR codes safely, in plain terms.
How Quishing Works
Quishing exploits the opacity of QR codes:
You cannot read a QR code: Unlike a written link you can inspect, a QR code is just a pattern — you cannot tell where it leads by looking at it. You only find out after scanning.
Malicious destinations: A scammer's QR code can lead to a phishing site (mimicking a legitimate login or payment page), a malware download, or a fraudulent payment — all disguised behind the harmless-looking code.
Exploiting trust in QR codes: Because QR codes are now common and trusted in everyday contexts, people scan them readily, often without suspicion — which scammers exploit.
The phishing connection: Once you scan to a malicious site, quishing becomes ordinary phishing — trying to steal credentials, payment information, or personal data, or to install malware.
Where Quishing Appears
Malicious QR codes turn up in various places:
Physical tampering: Scammers place fake QR code stickers over legitimate ones — on parking meters, payment terminals, posters, menus, or signs — so scanning the tampered code leads to their malicious destination.
Fake notices and mail: Fraudulent letters, flyers, or notices with QR codes (e.g., fake fines, package notices, or account alerts) lead victims to phishing or payment scams.
Emails and messages: QR codes in phishing emails or messages, sometimes used to evade link-based security filters (since the malicious URL is in an image, not clickable text).
Fake promotions: QR codes promising deals, prizes, or offers that lead to scams.
Public places: QR codes in public spaces that appear legitimate but are not.
Why Quishing Is Effective
Quishing works for several reasons:
Hidden destination: You cannot vet a QR code before scanning, removing the ability to inspect a link first.
Trust and habit: People are accustomed to scanning QR codes and often do so without suspicion.
Mobile context: QR codes are scanned on phones, where it can be harder to scrutinize URLs and where security may be more relaxed.
Evading filters: QR codes can bypass some email/link security filters, since the URL is embedded in an image.
How to Scan QR Codes Safely
You can protect yourself with careful scanning habits:
Preview the URL before opening: Many phone cameras and QR scanners show the URL before opening it. Check that the URL looks legitimate and expected before proceeding — your main defense.
Be wary of unexpected QR codes: Be cautious of QR codes in unexpected places, on stickers that look applied over something, in unsolicited mail, or in messages from unknown sources.
Check for tampering: For QR codes on physical objects (payment terminals, parking meters, posters), check whether a sticker has been placed over the original.
Don't enter sensitive information after scanning: Treat sites reached via QR codes like any link — do not enter credentials or payment information unless you have verified the site is legitimate. Apply anti-phishing caution.
Navigate directly for sensitive actions: For payments or logins, prefer typing the known address or using the official app rather than scanning a code, especially for anything sensitive.
Be skeptical of urgency and offers: QR codes pushing urgent action or too-good-to-be-true offers deserve suspicion, like other scams.
Verify independently: For QR codes claiming to be from an organization (a fine, a bill), verify through the organization's official channels rather than trusting the code.
Frequently Asked Questions
What is quishing in simple terms?
Quishing (QR code phishing) is the use of malicious QR codes to trick people into visiting harmful websites, revealing information, or taking harmful actions. It exploits the fact that you cannot tell where a QR code leads just by looking at it — you only find out after scanning. A scammer's QR code can lead to a phishing site, a malware download, or a fraudulent payment, all hidden behind the harmless-looking code. Because QR codes are now common and trusted, people scan them readily, which scammers exploit.
Where do malicious QR codes appear?
In various places: physical tampering (fake QR code stickers placed over legitimate ones on parking meters, payment terminals, posters, or menus), fake notices and mail (fraudulent letters or flyers with QR codes, like fake fines or package notices), phishing emails and messages (sometimes used to evade link-based security filters since the URL is in an image), and fake promotions promising deals or prizes. Public places with seemingly legitimate but malicious QR codes are also common. The key is that a tampered or fake code leads to the scammer's malicious destination.
How do I scan QR codes safely?
Preview the URL before opening it (many phone cameras and scanners show it first) and check that it looks legitimate and expected — your main defense. Be wary of QR codes in unexpected places, on stickers that look applied over something, or in unsolicited mail and messages, and check physical codes for tampering. Treat sites reached via QR codes like any link — do not enter credentials or payment information unless you have verified the site. For sensitive actions like payments or logins, prefer typing the known address or using the official app, and verify QR codes claiming to be from an organization through its official channels.
Conclusion
Quishing (QR code phishing) is the use of malicious QR codes to trick people into visiting harmful websites, revealing information, or taking harmful actions — exploiting the fact that you cannot tell where a QR code leads just by looking at it. A scammer's code can lead to a phishing site, malware download, or fraudulent payment, hidden behind the harmless-looking pattern, and because QR codes are now common and trusted, people scan them readily. Malicious QR codes appear through physical tampering (fake stickers over legitimate codes), fake notices and mail, phishing emails and messages (evading link filters), and fake promotions. Quishing is effective because the destination is hidden until scanned, people scan out of habit, the mobile context makes scrutiny harder, and codes can bypass some filters. You can protect yourself by previewing the URL before opening it, being wary of unexpected or tampered codes, not entering sensitive information on sites reached via QR codes unless verified, navigating directly for sensitive actions like payments and logins, being skeptical of urgency and offers, and verifying organizational claims through official channels. By understanding that a QR code is just an un-inspectable link and applying the same caution you would to any link, you can scan QR codes safely while avoiding the scams quishing enables.