Guide

The complete guide to QR phishing (quishing)

QR codes hide their destination by design. That single property is what makes them such an effective phishing vehicle - and what makes a verification step so valuable.

What quishing is

Quishing is phishing delivered through a QR code. Instead of a visible link a victim could inspect, the attacker supplies a pattern of squares. The destination is only revealed after the phone has already opened it.

The technique bypasses many habits people were taught about links: hover to preview, read the domain, look for https. None of them apply to a printed square on a parking meter.

Where you will meet it

  • Payment stickers

    A fake code pasted over a legitimate one on a terminal, meter or donation sign.

  • Fake invoices

    A PDF that looks like a supplier bill, with a code pointing to the attacker's payment page.

  • Delivery notices

    A card claiming a missed parcel, asking for a small redelivery fee.

  • Chat forwards

    A code forwarded through a group with an urgent story attached.

How to protect yourself

  • Decode the code before opening it, and read the full destination host
  • Be suspicious of any code that arrives unexpectedly and asks for money or a login
  • Check for lookalike domains - swapped letters, extra words, unusual endings
  • Prefer typing a known address or using the organisation's official app
  • Look for physical tampering: a sticker over another code is a strong warning sign
  • Never enter card details or passwords on a page you reached only through a QR code

What tools can and cannot do

A scanner that shows the destination and flags risky patterns removes the blind tap, which is where most quishing succeeds. That is a meaningful improvement over a camera that opens links automatically.

No tool can promise a link is safe. Treat risk signals as a prompt to slow down and verify through a channel you already trust.

Frequently asked

Check a code before you tap it