Quishing (a blend of "QR" and "phishing") is a scam where a malicious link is hidden inside a QR code instead of being sent as plain text. When you scan the code, your phone's browser opens the hidden link automatically — often before you've had any real chance to check where it leads.
It works the same way traditional phishing does: a fake login page, a bogus payment form, or a page that quietly downloads malware. The difference is entirely in the delivery method, and that difference is exactly why it's spreading.
Why quishing is growing so fast
Most email security tools are built to scan text for suspicious links. A QR code is just a picture — the malicious URL is encoded as a pattern of black and white squares, not as readable text, so many automated filters simply don't see it. That lets quishing slip past defenses that would catch an ordinary phishing email in seconds.
It also exploits a habit gap. People have spent years learning to hover over links and check sender addresses before clicking — but scanning a QR code feels more like a physical action, similar to using a menu or tapping a poster, so that same instinct to pause rarely kicks in.
A QR code that looks perfectly normal can point anywhere. There's no visual way to tell a safe destination from a malicious one just by looking at the pattern itself — the only way to know is to check the link it actually contains.
Where quishing shows up
- Stickers over real codes — on parking meters, restaurant tables, event posters, and shipping labels, placed directly over a legitimate code.
- Emails and PDFs — disguised as "verify your identity," "update your MFA," or "review this document" requests, using a QR code specifically to dodge link-scanning filters.
- Fake delivery or government notices — texts or emails claiming a package couldn't be delivered, or a payment is overdue, with a QR code to "resolve it."
- Flyers and public posters — placed in high-traffic areas where people scan quickly without a second thought.
How to protect yourself
The core defense is simple: never let a QR code take you somewhere before you know where that is. A few habits go a long way:
- Use your phone's built-in preview (both iOS and Android show the destination URL before opening it) as a first, quick check.
- Be suspicious of any QR code that arrived unexpectedly by email or text — legitimate services generally send clickable links, not images to scan.
- Look for physical signs of tampering on codes in public places — see our guide to spotting a fake QR sticker.
- Run an actual safety check on the destination link before visiting it, especially if it asks for a password or payment. That's what CheckThisQR does — decode the code and check where it leads before you go there.
See real examples of how these attacks have actually played out in our QR code scam examples guide, or jump straight to how to check a QR code before scanning it.