How QR code phishing (quishing) scams work

Updated View source
Stay safe

QR code phishing, often called quishing, is a scam that hides a malicious web link inside a QR code so you cannot read the address before you scan it.

How the scam works

A QR code is just a picture that stores a web address. Your phone camera turns that picture back into a link and offers to open it. That is convenient, and scammers know it. When the link is printed as a square of dots, you cannot see where it goes until you have already scanned it. By then your phone may be halfway to opening the page.

A quishing attack replaces a trusted QR code, or invents a new one, that points to a fake website. The fake page usually copies a brand you know: a bank, a parcel service, a parking app, or a workplace sign-in screen. It asks you to log in, confirm a payment, or enter card details. Whatever you type goes straight to the attacker.

The scam works for two reasons. First, people trust QR codes because they feel modern and official. Second, the dangerous part is hidden. A written link like paypa1-secure.com looks wrong at a glance. The same link inside a QR code looks like every other QR code on earth.

Where quishing shows up

Attackers put fake QR codes wherever people already expect to scan one. Common places include:

Because the codes travel from a screen or a page to your phone, they cross from one device to another. That gap is exactly where a lot of protection does not reach. A scam poster does not have to beat your email filter, because it never touches your inbox.

What happens after you scan

Most quishing links lead to a fake sign-in page. The address might read something like login-microsoft.secure-check.ru or amaz0n-billing.support-desk.net. The page looks right, so people type their username and password. Some pages then ask for a one-time code from a text message or an authenticator app, which lets the attacker step past two-factor protection in real time.

Other quishing links start a download, ask you to install an app from outside the official store, or push you toward a payment. A common version claims a small parcel fee is unpaid and asks for card details to release the package. The fee is fake. The card details are the prize.

How to protect yourself

You do not need to stop using QR codes. You need one habit: check the link before you trust the page it opens.

This is where Fish Catcher helps. It can read a QR code on your screen and check the link inside before you trust it, so the address is examined against its checks first instead of after you have already opened the page. If the link points to a known scam site or a lookalike brand address, you get a plain warning with a risk color, and you still decide what to do next.

Common questions

Can a QR code itself infect my phone?

No. A QR code only stores text, usually a web address. The risk is not the code, it is the website or file the link leads to, and what you do once you get there. That is why checking the link before you act matters so much.

Is it safe to scan a QR code in a restaurant or on a parking meter?

Usually, but look first. Check that the code is printed as part of the sign, not a sticker placed over something else. After scanning, read the link preview. A restaurant menu should lead to that restaurant, not to a login page or a payment form.

How can I tell if the link after a scan is fake?

Read the part of the address right before the ending, such as .com. A real Microsoft page ends in microsoft.com, not secure-check.ru. Extra words, misspellings, and swapped characters like a zero for the letter o are signs of a fake. If anything looks off, do not sign in.