Skip to content

Quishing: phishing through QR codes

A QR code does not show you where it goes. That is convenient for everyone — including the people who would rather you did not look.

What is quishing?

Quishing is phishing that arrives as a QR code instead of a link. The tactics are the same: send you to a page that imitates something you trust, and collect what you type there. What changes is that you cannot read the destination first. A link in an email can be hovered over; a square of dots cannot.

Where it shows up

Anywhere a code is printed rather than displayed, because printed codes can be covered by a different one.

  • Parking meters and charging points, where a sticker over the real code sends payment somewhere else.
  • Restaurant tables, where the menu code is swapped for one asking you to log in.
  • Parcel notices claiming a delivery needs a small fee.
  • Emails containing a code instead of a link, specifically to get past link scanners.
  • Posters and flyers in public places, where nobody notices an extra sticker.

How to spot one

You usually cannot, from the code itself. What you can check is the context around it and the destination before you act on it.

A sticker on top

Feel the surface. A code stuck over printed material is the most common trick there is.

Urgency

Fines, expiring parcels, accounts about to close. Pressure is meant to stop you checking.

A shortened link

The destination hides behind a short domain. Legitimate too, which is exactly why it works.

It asks you to log in

A menu does not need your password. A parking meter does not need your bank login.

Dynamic codes change after printing

Many QR codes point at a redirect service rather than the destination itself, so the owner can change where it leads without reprinting. Useful for a restaurant updating its menu — and equally useful to someone who wants a code to be harmless while it is being checked and hostile afterwards.

We recognise the services behind these codes and tell you which one was used. See the providers we recognise.

What to do instead

  1. 1 Do not scan straight from the camera app into a browser. Scan here first, or paste the link if you already have it.
  2. 2 Look at where it actually ends up, not just the first hop. We follow every redirect and show you the whole chain.
  3. 3 If it asks for a login or a payment you were not expecting, go to the site yourself instead of through the code.

Check before you scan

Free, no account needed, nothing stored.

Check a QR code