Guide
The complete guide to QR phishing (quishing)
QR codes hide their destination by design. That single property is what makes them such an effective phishing vehicle - and what makes a verification step so valuable.
What quishing is
Quishing is phishing delivered through a QR code. Instead of a visible link a victim could inspect, the attacker supplies a pattern of squares. The destination is only revealed after the phone has already opened it.
The technique bypasses many habits people were taught about links: hover to preview, read the domain, look for https. None of them apply to a printed square on a parking meter.
Where you will meet it
Payment stickers
A fake code pasted over a legitimate one on a terminal, meter or donation sign.
Fake invoices
A PDF that looks like a supplier bill, with a code pointing to the attacker's payment page.
Delivery notices
A card claiming a missed parcel, asking for a small redelivery fee.
Chat forwards
A code forwarded through a group with an urgent story attached.
How to protect yourself
- Decode the code before opening it, and read the full destination host
- Be suspicious of any code that arrives unexpectedly and asks for money or a login
- Check for lookalike domains - swapped letters, extra words, unusual endings
- Prefer typing a known address or using the organisation's official app
- Look for physical tampering: a sticker over another code is a strong warning sign
- Never enter card details or passwords on a page you reached only through a QR code
What tools can and cannot do
A scanner that shows the destination and flags risky patterns removes the blind tap, which is where most quishing succeeds. That is a meaningful improvement over a camera that opens links automatically.
No tool can promise a link is safe. Treat risk signals as a prompt to slow down and verify through a channel you already trust.