QR Code Phishing (Quishing): What It Is and How to Recognize It
Learn how QR phishing works, why hidden destinations can be persuasive, and what checks reduce the risk of fake login or payment pages.
Quick answer
Quishing is phishing that uses a QR code to deliver the malicious link or action. The attacker may place the code in an email, document, package, poster, parking sign, or sticker over a legitimate QR. The code can send the user to a convincing fake login or payment page. The protective habits are the same as for other phishing: question unexpected urgency, verify the source through another channel, preview the destination, and never submit sensitive information until the domain and context are trustworthy.
Key points
- The QR hides the human-readable destination until a scanner decodes it.
- Attackers can copy branding while changing the underlying URL.
- Physical replacement attacks are possible because a sticker can cover a legitimate code.
- Urgency, account warnings, prizes, and payment requests are common phishing pressure tactics in many channels.
- Independent verification is more reliable than trusting the appearance of the message or sign.
What to do
- 1Pause when a QR request is unexpected or urgent.
- 2Check the sender, physical placement, and any signs of tampering.
- 3Preview the domain and compare it with the organization's known official domain.
- 4Open the official app or manually navigate to the service when sensitive action is required.
- 5Report suspicious QR placements or messages to the relevant organization or administrator.
Common mistakes to avoid
- Assuming a QR in a branded email bypasses normal phishing checks.
- Scanning an unknown code just to see what happens.
- Trusting a login page because its logo and colors look correct.
- Entering credentials after being redirected through multiple unfamiliar domains.
Frequently asked questions
What is quishing?
Quishing is phishing that uses a QR code as the path to a malicious or deceptive destination.
How is QR phishing different from email phishing?
The social engineering is similar, but the destination is encoded in an image rather than shown as ordinary link text.
Can a scammer replace a real QR code with a fake one?
Yes. Physical sticker replacement is one reason to inspect public QR placements for tampering.
What should I check before opening a QR link?
Check the source, context, previewed domain, and whether the requested action makes sense.
What if a QR says my account will be closed?
Do not rely on the QR. Open the service through a trusted route and check the account directly.
Can a fake QR look identical to a real one?
The black-and-white pattern will differ for a different payload, but a person generally cannot recognize the destination by visual inspection alone.
Should I scan a QR from an unexpected package or message?
Treat unexpected QR prompts cautiously and verify the sender or purpose before interacting.
How should a business reduce QR tampering risk?
Use durable branded placement, inspect public codes, use recognizable domains, secure management accounts, and give customers a way to report suspicious signs.
Sources and further reading
Technical or policy-sensitive statements in this guide are grounded in primary or authoritative references where available.
Related QR guides
Understand QR security risks, trustworthy destinations, tampered stickers, suspicious redirects, scanner permissions, and safer publishing practices.
Understand the difference between decoding a QR locally and visiting a trackable web destination, including scan analytics and privacy considerations.
Learn how dynamic QR codes use redirects to let you update destinations, track scans, and manage printed campaigns.