How QR code phishing (quishing) scams work
QR code phishing, often called quishing, hides a malicious web link inside a QR code so you cannot read the address before you scan it.
How the scam works
A QR code is a picture that stores a web address. Your phone turns it back into a link and offers to open it. Printed as dots, the link cannot be read until you have scanned it.
A quishing attack swaps in a QR code that points to a fake page copying a brand you know: a bank, a parcel service, a parking app. It asks you to log in, confirm a payment, or enter card details.
Where quishing shows up
- Emails asking you to scan a code to reset a password. Filters read links in text, but a QR code is an image, so it slips past.
- Stickers over the real code on a parking meter, an EV charger, or a menu.
- Letters, flyers, and posters posing as a bank or a tax office.
What happens after you scan
Most links lead to a fake sign-in page at an address like login-microsoft.secure-check.ru. Others start a download or ask for card details to release a parcel for a small fee. The fee is fake, the card details are the prize.
How to protect yourself
You do not need to stop using QR codes, only to look before you trust.
- After a scan, read the link preview. The word before the .com or .net is the real owner.
- Be careful with codes that arrive by surprise, especially ones that push urgency.
- Look at physical codes up close. A sticker on top of another code is a warning sign.
- If a code claims to come from your bank or employer, open the app or site you already know instead.
Fish Catcher can read a QR code on your screen and check the link before you open it, and warns you in plain language if it looks like a scam. It never blocks the page.
Common questions
Can a QR code itself infect my phone?
No. A QR code only stores text. The risk is the website or file it leads to.
Is it safe to scan a QR code in a restaurant or on a parking meter?
Usually, but check that the code is printed as part of the sign, not a sticker over it, and read the link preview before you tap.
How can I tell if the link after a scan is fake?
Read the part before the ending. A real Microsoft page ends in microsoft.com, not secure-check.ru. Extra words and swapped characters are signs of a fake.