What Is Quishing? QR Code Phishing Explained

What Is Quishing? QR Code Phishing Explained

Quishing is phishing done with a QR code. Instead of sending you a link, the scammer puts the link inside a QR code, so you scan it with your phone and land on a fake login page, a fake payment form or a malicious download. The name is “QR” plus “phishing,” and the goal is the same as any phishing attack: your passwords, your card number or a foothold on your device.

It works because a QR code hides its destination. You can hover over a suspicious link in an email, but you can’t read a QR code by looking at it.

How does quishing work? #

Most quishing attacks follow the same four steps:

  1. The code gets in front of you. It might be a sticker on a parking meter, a code in an email or text, a flyer, or a card in a package you didn’t order.
  2. There’s a reason to scan now. A parking fine, a failed delivery, a locked account, a security check, a refund. Urgency is the tell.
  3. You land on a convincing copy. The page looks like your bank, a parking app, a delivery company or your employer’s sign-in screen. It almost always uses https, so the padlock shows.
  4. You hand something over. Card details, a password, a one-time code, personal information, or permission to install an app.

The FTC describes both main outcomes: the code can send you to a spoofed site that steals your information, or install malware that collects data without you noticing.

A few reasons make QR codes attractive to attackers:

  • The destination is invisible. People scan first and read later, if they read at all.
  • Phones make the address hard to check. Mobile browsers show a shortened address bar, and it’s easy to miss a strange domain on a small screen.
  • It moves you off a protected device. A code in a work email gets scanned on a personal phone, outside the company’s email filters and managed security.
  • Filters may not read images. Email security tools are built to inspect text links. A link inside an image is harder for them to catch.
  • Physical codes borrow trust. A sticker on a city parking meter looks official because the meter is official.

Common quishing scams #

Fake parking meter codes #

The best-known version. Scammers put their own QR stickers on parking meters and pay stations, sometimes directly over the real code. The FTC names this scam specifically. You pay a fake site, the city never gets the money, and the scammer keeps your card number. We cover the warning signs in detail in how to spot a fake parking meter QR code.

“Your package couldn’t be delivered” and account alerts #

The FTC also warns about codes sent by email or text that claim the sender couldn’t deliver your package, that there’s a problem with your account, or that suspicious activity was detected. Each one is designed to make you scan before you think.

“Payment failed” emails #

The FBI’s 2022 warning on QR code tampering tells people who receive an email saying a payment failed to call the company using a number from a trusted source rather than pay through a code.

Packages you didn’t order #

In 2025 the FBI warned about unsolicited packages containing QR codes, a twist on the “brushing” scam. The package often has no sender information, which makes you more likely to scan the code to find out who sent it. The code then leads to a site that asks for personal and financial details, or tries to get you to install something.

Workplace security notices #

Some quishing emails pose as an IT or security message: re-verify your account, review a shared document, set up a new sign-in method. The QR code leads to a fake sign-in page built to capture your work password and, sometimes, the one-time code that goes with it.

What are the signs of a quishing attempt? #

No single sign proves a code is malicious, but these should slow you down:

  • The code is a sticker, especially one covering printed text or another code.
  • It arrived by email, text or mail you weren’t expecting.
  • The message is urgent: pay now, verify now, avoid a fine or a locked account.
  • The link is shortened, so you can’t see the destination.
  • The domain doesn’t match the organization, or matches it only at the start (yourbank.com.secure-login.net belongs to secure-login.net).
  • The page asks for more than the task needs, such as your date of birth to pay for parking.
  • It asks you to download an app from a link instead of the App Store or Google Play.

How to protect yourself from quishing #

The government advice is consistent. From the FTC and FBI:

  1. Inspect the URL before you open it. Look for misspellings and swapped letters.
  2. Don’t scan codes you weren’t expecting, especially ones pushing you to act immediately. Contact the company through a number or site you already know.
  3. Check physical codes for tampering, like a sticker placed over the original.
  4. Be careful about entering logins or payment details on any site you reached through a QR code. For payments, the FBI suggests typing a trusted address yourself.
  5. Get apps from your phone’s app store, not from a code.
  6. Keep your phone updated and your accounts protected with strong passwords and multi-factor authentication.

Step 1 is only possible if your scanner lets you see the address before anything opens. QR Handler shows the full contents of every code on a result screen and never opens a link by itself. For links, it names the real host and flags plain http, shortened links, raw IP addresses, addresses that hide the real site behind an @, and look-alike characters. It can’t tell you that an ordinary-looking domain is a scam, and nothing else on your phone can either, so the judgment is still yours. Our step-by-step guide to checking a QR code before opening it goes through what to look at.

What should you do if you fell for a quishing scam? #

Act on what you shared:

  • Card or bank details: call the number on the back of your card and report the charge.
  • A password: change it, and turn on multi-factor authentication. If you reuse it elsewhere, change it there too.
  • Personal information: go to IdentityTheft.gov for a recovery plan.
  • An app: delete it and run a security check.

Then report it at ReportFraud.ftc.gov and ic3.gov. Our full guide on what to do if you scanned a malicious QR code covers each situation in order.

Frequently asked questions #

Is quishing the same as phishing? #

It’s a type of phishing. The trick and the goal are the same; only the delivery changes, with a QR code taking the place of a clickable link.

Can you get quished just by scanning a code? #

Scanning only reads the code. The damage comes from opening the link and then typing in information or installing something. Previewing the address and walking away is safe.

Do antivirus apps stop quishing? #

Some security apps and browsers block sites that have already been reported as phishing. A brand-new scam page may not be on any list yet, so reading the address yourself still matters.

Where do I report a quishing scam? #

In the US, report it to the FTC at ReportFraud.ftc.gov and the FBI at ic3.gov. If the code was on a parking meter or a business’s sign, tell the city or the business too so they can remove it.