Security

Quishing

Phishing through a QR code. A tampered or unsolicited code leads to a fake page. Read the address your phone shows before opening it and avoid codes from unexpected places.

How it works

Quishing is phishing that uses a QR code to lead someone to a deceptive destination. The code encodes information such as a web address; its presence does not authenticate the page or the person who placed it. The scam usually depends on what happens after scanning.

A practical example

Imagine a QR sticker added over a legitimate payment notice. It could lead to a lookalike payment page requesting card information. An unexpected parcel could also include a code that claims to explain the delivery. Neither a printed label nor a familiar logo proves that the destination is trustworthy.

What to check

Inspect the surrounding context and preview the destination address before opening it when your scanner provides that option. If a payment or account action is involved, use the organization’s known app or independently obtained website instead. Confirm the intended transaction and do not supply passwords or codes to an unverified page.

Limits and safe use

A QR code is not inherently dangerous, and scanning is not the same as submitting data or granting permissions. Assess what actually occurred. If sensitive information was entered, secure the relevant account and contact the provider through a trusted channel. Removing a fraudulent sticker does not reverse information already submitted or a payment already made.

Technical sources

← All glossary terms