Skip to content

Quishing

Quishing is phishing delivered by QR code. The attack works for one structural reason: a printed square reveals nothing about where it goes, so the usual advice about checking a link before clicking it has nothing to act on.

It has become common enough that it is worth understanding as a category rather than as a series of individual scams.

Why a code is a better disguise than a link

In an email, a suspicious address is visible on hover, and mail filters have decades of practice reading links. A QR code sidesteps both: the destination is an image as far as the filter is concerned, and the reader has no way to inspect it before pointing a camera at it.

It also moves the victim onto a phone, where the address bar is short, the screen is small, and a convincing lookalike domain is much harder to spot than on a desktop. That shift is deliberate rather than incidental.

The swapped sticker

The most common physical version is an adhesive code placed over a legitimate one: parking meters, EV chargers, restaurant tables, charity collection points, church giving cards. The building looks normal and the code looks official because it is in the place an official code belongs.

Defending printed codes means making replacement obvious: print codes into the material rather than applying stickers, laminate or frame them, print the destination address as text beneath so an altered code is visibly inconsistent, and check them as part of a round somebody already does.

What the payload usually is

A lookalike payment page, a fake login for a service the victim uses, or a prompt to install something. The tell is usually urgency — a fine to pay, an account to re-verify, a delivery to reschedule — because urgency is what stops somebody pausing to check.

A less obvious variant is a WiFi payload that joins the phone to a network the attacker controls, and a code that opens a message or dials a premium number. Those are rarer, but they are why "it is only a code" is not a safe assumption.

How to check one safely

Read it rather than scan it. A reader shows the payload as text and does nothing with it, so you see the destination before anything acts on it — which is the step the format otherwise removes. Our own reader runs entirely in the browser and never uploads the image.

Then judge the address as you would any link: the real domain is the part immediately before the first single slash, not whatever words appear earlier in the string. And if a code arrived unexpectedly, in a letter, an email or on a sticker, prefer typing the organisation address yourself over following it at all.

If you run codes, you are also a target

An organisation whose customers are trained to scan printed codes is an organisation whose customers will scan a fraudulent one. The reputational cost lands on you regardless of who placed the sticker.

Using your own domain for dynamic codes helps materially here, because customers can be told what your addresses look like and a fraudulent code will not match. A code pointing at a generic shortener gives people nothing to verify against.

Common questions

What is quishing?
Phishing delivered by QR code. It works because a printed square reveals nothing about its destination, so the usual advice to check a link before clicking has nothing to act on, and because it moves the victim onto a phone where lookalike domains are harder to spot.
How do fake QR code stickers work?
An adhesive code is placed over a legitimate one on a parking meter, EV charger, restaurant table or collection point. It looks official because it is where an official code belongs, and nothing about the square itself looks wrong.
How can I check a QR code before acting on it?
Read it instead of scanning it. A reader shows the payload as text without acting on it, so you see the destination first. Then judge the address normally — the real domain is the part immediately before the first single slash.
How do I stop my own printed codes being replaced?
Make replacement visible: print codes into the material rather than applying stickers, laminate or frame them, print the destination as text beneath so an altered code is inconsistent, and check them during a round somebody already does.
Does using a custom domain help against quishing?
Materially. Customers can be told what your addresses look like, so a fraudulent code will not match. A code pointing at a generic shortener gives people nothing to verify against, which removes their only defence.

Related terms

Quishing — QR Code Phishing Explained