Skip to content

QR Code Security: How Quishing Scams Work and How to Spot One

· 7 min read · By

QR codes earned their place by being trustworthy: point your camera, get where you meant to go. Scammers noticed. A whole category of fraud now rides on that reflex — it is called quishing, and because a QR code is a link your eye simply cannot read, it is unusually effective. This guide explains exactly how these attacks work, the four patterns you will actually run into, how to spot a malicious code in the two seconds before you tap, and — if you print codes yourself — how to keep your own audience safe.

Four steps of a quishing attack: a fake sticker over a real QR code, the victim scanning, a lookalike login page, and stolen data.
A quishing attack in four steps — the whole thing depends on you not checking the destination.

What quishing actually is

Quishing is a blend of “QR” and “phishing.” The mechanics are the same as any phishing attack — lure someone to a fake page, harvest their password or payment details — but the delivery is a QR code instead of a clickable link. That swap matters more than it sounds. A phishing email shows you a URL you can read and judge. A QR code shows you a grid of squares that encodes a URL you cannot read. You are trusting the destination sight unseen, and that blind trust is the entire attack surface.

A QR code is not malware. It cannot install anything by itself or “hack” your phone on contact. It only ever does one thing: hand a string — almost always a web address — to whatever app opens it. Every quishing scam is really a story about where that address points and how convincingly the page there imitates something you trust.

Why QR codes are a phisher’s dream

Several things line up in the attacker’s favour. The destination is invisible until you commit — unlike a link in an email, there is no hover-to-preview on a poster. Codes are almost always scanned on a phone, where the address bar is short, domains get truncated, and a careful look is awkward. They are usually scanned in a hurry and in public — a parking meter, a restaurant table, a conference badge — exactly when your guard is down.

And crucially, a QR code slips past filters built for text. Email security tools scan the words and links in a message, but a QR code arrives as an image, so a malicious link tucked inside it can sail through a corporate spam filter that would have caught the same URL typed in plain text. That single property is why quishing exploded in business email in recent years.

The four patterns you will actually meet

1. A fake sticker over a real code

The most common physical attack, and the simplest: the scammer prints their own QR sticker and presses it neatly over a legitimate one — on a parking meter, a restaurant table tent, a poster, an information board. Everything around it looks official, so you scan without a second thought. Because the overlay hides the genuine code completely, there is nothing visually wrong to notice unless you look for the edge of a sticker.

2. Fake parking and charging payment codes

A specialised version of the sticker trick, aimed straight at your wallet. Codes on parking meters and EV chargers promise a quick “scan to pay,” which makes them the perfect disguise: you already expect to hand over card details, so a lookalike payment page raises no alarm. The money and the card number go to the attacker, and the real parking session was never paid.

3. QR codes inside phishing emails and PDFs

The office variant. An email or attached PDF tells you to “scan to verify your account,” “re-authenticate your mailbox,” or “review the shared document,” with a QR code to scan with your phone. Two tricks are stacked here: the code dodges the email link scanner, and moving you from a monitored work laptop to a personal phone strips away the protections your employer put in place. The page waiting for you is a pixel-perfect copy of a familiar login.

4. Flyers, “prizes,” and street codes

Loose codes with no accountable owner: a flyer under your windscreen wiper, a “you’ve won” card in your letterbox, a sticker on a lamp post offering free Wi-Fi or a discount. There is no institution behind them to complain to, and the payoff dangled in front of you — a prize, free access, a deal — is designed to override caution. Treat any unsolicited code exactly as you would an unsolicited link.

How to spot a malicious QR before you tap

Almost every quishing attempt falls apart under a few seconds of attention. Modern phones show you the destination URL before opening it — that preview is your single most important defence. Run through this quick checklist:

If you print QR codes, protect your audience

Quishing is not only a risk to individuals — it is a risk to your brand when your codes are the ones being impersonated. A few habits make your codes far harder to abuse. Encode a domain you actually control, so a careful person who checks the URL sees your real name and trusts it. Print the destination in plain text beside the code (“Opens example.com/menu”) so people can verify what they are about to scan.

Think hard about redirect-based “dynamic” codes, too. A code that routes through a third-party short domain is convenient, but it also means your audience is trusting a domain you do not own — and if that service is compromised or lapses, every code you printed points wherever the new owner decides. Our guide to static vs. dynamic QR codes walks through the trade-off in detail. Finally, inspect your printed codes periodically for stickers or tampering, especially anything unattended in public.

Where QRStudio fits

QRStudio generates static codes entirely in your browser: the address you type is encoded directly into the pattern, with no third-party redirect in the middle and nothing about the code logged or sent anywhere. What you put in is exactly what a scanner reads out — there is no hidden hop for anyone to hijack. That said, a static code is only as trustworthy as the URL inside it, so the rule still holds: encode a domain you control, and give people the text of the destination so they can check it. The technology is neutral; safety comes from the address you choose and the two seconds a scanner spends reading it.