RESOURCES · SECURITY & EMAIL

QR code phishing,
or 'quishing'

That handy square barcode you scan for menus and parking? Scammers love it too. "Quishing" is phishing hidden inside a QR code — because you can't see where a QR code leads until you've already scanned it. Here's how the scam works, and how to scan safely.

Applies to: Anyone with a phone camera Read: ~4 min Level: Non-technical
Quick answer

A QR code is just a link you can't read with your eyes. Attackers put malicious QR codes in emails, in documents, and on fake stickers placed over real ones (parking meters, posters), to send you to a fake login page or a malware download. Always check the web address after scanning — before you tap, log in or type anything.

WHY QR CODES ARE PERFECT FOR SCAMS

You can't see where they go.

A QR code has one big weakness for you, and one big advantage for a scammer:

COMMON CONS

Where quishing shows up.

The same trick turns up in a few familiar disguises:

RED FLAGS

When to be suspicious.

None of these are proof on their own, but any of them is a good reason to slow down:

HOW TO SCAN SAFELY

Look before you leap.

  1. Preview the web address firstWhen you scan, your phone shows the link before it opens. Read it. If it doesn't match the business you expected, don't open it.
  2. Never log in via a scanned codeIf a code takes you to a login page, stop. Go to the official app or website directly and sign in there instead.
  3. Be extra wary in emails and public placesCodes in unexpected emails and codes on posters, meters and flyers are the two spots scammers love most.
  4. Keep your phone and apps updatedUpdates fix the security holes that malicious pages and downloads try to exploit.
A simple habit. If a QR code leads to a page asking you to log in or pay, stop. Open the real app or type the official website address yourself instead.
BEYOND THE OBVIOUS SCAMS

Your team is being targeted in newer ways than email.

Quishing is just one of the newer tricks slipping past old defences. Our free IT Health Check reviews your email security, sign-in protections and monitoring — and we offer security awareness training that keeps your staff current on newer tactics like quishing, so they spot the con before it works.

KEEP READING

Related resources