By J. Mesa
QR codes sit on restaurant tables, parking meters, shipping labels, and holiday advertisements. You scan them without a second thought, and scammers have noticed. A QR code hides its destination until after you point your camera at it. That makes it a handy wrapper for a phishing link, and holiday shopping season gives criminals more chances to use one.
What is quishing?
Quishing is phishing delivered through a QR code. The word combines “QR” and “phishing.” The code sends your phone to a fake website that steals your password or card number, or prompts you to install a malicious app.
How do QR code scams work?
A QR code is a picture of a web address. Your phone reads the picture and opens the address. You can’t read the pattern with your eyes, so you can’t judge the link before you scan.
The scammer’s part is simple. They create a code that points to a site they control, then place it where you expect a legitimate code. The fake site copies a parking payment page, a Microsoft 365 sign-in, a delivery tracker, or a bank login. You type your details, and the criminal collects them.
Where do fake QR codes show up?
- Parking meters and pay stations. Criminals paste stickers over or beside the real payment code. Cities across the United States have warned drivers about this. You pay the scammer, receive a parking ticket anyway, and hand over your card number.
- Restaurant tables and counters. A sticker over the menu code leads to a fake ordering page.
- Emails. A message claims your password expires, your multi-factor authentication needs renewal, or a document awaits your signature. The email holds a QR code in place of a link.
- Packages you did not order. A box arrives with a card that says “scan to see who sent this gift” or “scan to claim a prize.” This pairs with the brushing scam, in which sellers ship unsolicited items.
- Text messages about unpaid tolls or missed deliveries.
- Paper mail and flyers, including fake notices from a city, a utility, or a court.
- Cryptocurrency ATMs. A caller pretending to be a government office or a bank tells you to scan a code at the machine to “protect” your money. The code holds the scammer’s wallet address.
- EV charging stations and donation jars.
Why do scammers put QR codes in emails?
Three reasons.
First, many email security filters scan links and attachments, and a QR code is an image. The filter may see a picture and let the message through.
Second, the code moves you from a work computer to a personal phone. The computer sits behind the company firewall and web filter. The phone, on cellular data, has neither.
Third, phone screens show a shortened address bar, which makes a fake web address harder to spot.
A legitimate company rarely needs to send you a QR code by email. You are already on a device that can click a link. Treat any emailed QR code that leads to a sign-in page as a phishing attempt and report it.
Can scanning a QR code hack my phone?
Scanning alone almost never harms a phone that is up to date. The code only opens an address or suggests an action. The harm comes from what you do next: entering a password, typing a card number, approving a payment, installing an app or a configuration profile, or joining an unknown Wi-Fi network.
Keep the phone’s operating system current. Decline any download a scanned page offers.
How do I check a QR code before I trust it?
- Look at the physical code. Run a finger across it. A sticker on top of a printed sign, a crooked label, or a code that covers another code is a warning.
- Preview the address. The iPhone and Android cameras display the web address before opening it. Read it.
- Check the domain. The real name sits just before the “.com” or “.gov.” An address like “parking-city-pay.com” is not your city’s website. Watch for misspellings and extra words.
- Be wary of shortened links such as bit.ly, which hide the destination.
- Ask yourself who placed the code. A code printed on a menu inside the restaurant carries less risk than one on a flyer under your windshield wiper.
- Go around it. Type the company’s address yourself, or use the official app. For parking, use the app named on the meter or pay at the machine.
Do I need a QR scanner app?
No. Use the camera built into your phone. Third-party scanner apps add risk, and some of them have carried malware or aggressive advertising. Delete the ones you have.
How do I protect my business from quishing?
- Train the staff. Add QR codes to your security awareness training and to your phishing tests. Teach one rule: never scan a code from an email to sign in to a work account.
- Check your email filter. Ask your provider whether the filter reads QR codes inside images and attachments. Microsoft and other vendors added this capability.
- Use phishing-resistant sign-in. Passkeys and security keys refuse to work on a fake site, even when an employee falls for the code.
- Manage the phones. Staff phones that reach company email should meet minimum requirements: current software, a screen lock, and enrollment in mobile device management where practical.
- Create an easy way to report. One email address or one button. Thank the people who use it.
How do I protect my customers if my business uses QR codes?
If you print QR codes on menus, signs, invoices, or packaging, criminals can cover or imitate them.
- Print codes directly on signs and menus. Avoid stickers, which make a pasted fake look normal.
- Display the destination address in text next to the code, so customers can compare.
- Point codes at your own domain. Skip link shorteners and free QR generators that route through their own servers and can expire or redirect.
- Inspect your posted codes on a schedule. Add it to the opening checklist.
- Tell customers what you will never ask for through a QR code.
What should I do if I scanned a bad QR code?
Act based on what you entered.
- Scanned but entered nothing. Close the page. Clear your browser history and site data. You are almost certainly fine.
- Entered a password. Change it right away from a different device, change it anywhere else you used it, and turn on multi-factor authentication. For a work account, tell IT at once so they can end active sessions and check for forwarding rules.
- Entered card details. Call the card issuer, dispute the charge, and request a new card.
- Installed an app or a profile. Remove it, update the phone, and run a security check. If the phone holds work data, report it.
- Sent cryptocurrency. Report it to the FBI at ic3.gov and to the machine’s operator. Recovery is unlikely, and speed gives you the only chance.
Report the scam at ReportFraud.ftc.gov. For a fake sticker on a meter or a sign, call the city or the business so they can remove it.
Are QR codes safe to use at all?
Yes, with the same care you give a link. The code itself is neutral. Trust depends on where it sits and where it sends you. Slow down for any code that asks for money, a login, or a download.
Your next step
Before the holiday rush, show your staff one example of a QR phishing email and one photo of a tampered parking meter. It takes five minutes at a staff meeting. For training that covers quishing, phishing, and phone scams, review our cybersecurity training or contact Cerberus Cybersecurity.