How QR code phishing (quishing) scams work
QR code phishing, often called quishing, is a scam that hides a malicious web link inside a QR code so you cannot read the address before you scan it.
How the scam works
A QR code is just a picture that stores a web address. Your phone camera turns that picture back into a link and offers to open it. That is convenient, and scammers know it. When the link is printed as a square of dots, you cannot see where it goes until you have already scanned it. By then your phone may be halfway to opening the page.
A quishing attack replaces a trusted QR code, or invents a new one, that points to a fake website. The fake page usually copies a brand you know: a bank, a parcel service, a parking app, or a workplace sign-in screen. It asks you to log in, confirm a payment, or enter card details. Whatever you type goes straight to the attacker.
The scam works for two reasons. First, people trust QR codes because they feel modern and official. Second, the dangerous part is hidden. A written link like paypa1-secure.com looks wrong at a glance. The same link inside a QR code looks like every other QR code on earth.
Where quishing shows up
Attackers put fake QR codes wherever people already expect to scan one. Common places include:
- Emails that ask you to scan a code to reset a password, view a document, or confirm a delivery. Email filters often read links in text, but a QR code is an image, so it can slip past them.
- Stickers placed over the real QR code on a parking meter, an electric vehicle charger, or a restaurant menu.
- Printed letters and flyers that look like they come from a bank, a tax office, or a utility company.
- Posters and signs in public spaces, sometimes with a small fake code pasted in a corner.
Because the codes travel from a screen or a page to your phone, they cross from one device to another. That gap is exactly where a lot of protection does not reach. A scam poster does not have to beat your email filter, because it never touches your inbox.
What happens after you scan
Most quishing links lead to a fake sign-in page. The address might read something like login-microsoft.secure-check.ru or amaz0n-billing.support-desk.net. The page looks right, so people type their username and password. Some pages then ask for a one-time code from a text message or an authenticator app, which lets the attacker step past two-factor protection in real time.
Other quishing links start a download, ask you to install an app from outside the official store, or push you toward a payment. A common version claims a small parcel fee is unpaid and asks for card details to release the package. The fee is fake. The card details are the prize.
How to protect yourself
You do not need to stop using QR codes. You need one habit: check the link before you trust the page it opens.
- When your phone shows the link preview after a scan, read it slowly. Look at the main part of the address, the word just before the .com or .net. That is the real owner of the site. Everything else can be faked.
- Be careful with codes that arrive by surprise, especially ones that create urgency, mention money, or ask you to sign in.
- Look at physical codes up close. A sticker sitting on top of another code, or a code that looks glued on, is a warning sign.
- Do not install apps from a link inside a QR code. Go to the official app store yourself.
- If a code claims to come from your bank or your employer, do not scan it. Open the app or website you already know and check there.
This is where Fish Catcher helps. It can read a QR code on your screen and check the link inside before you trust it, so the address is examined against its checks first instead of after you have already opened the page. If the link points to a known scam site or a lookalike brand address, you get a plain warning with a risk color, and you still decide what to do next.
Common questions
Can a QR code itself infect my phone?
No. A QR code only stores text, usually a web address. The risk is not the code, it is the website or file the link leads to, and what you do once you get there. That is why checking the link before you act matters so much.
Is it safe to scan a QR code in a restaurant or on a parking meter?
Usually, but look first. Check that the code is printed as part of the sign, not a sticker placed over something else. After scanning, read the link preview. A restaurant menu should lead to that restaurant, not to a login page or a payment form.
How can I tell if the link after a scan is fake?
Read the part of the address right before the ending, such as .com. A real Microsoft page ends in microsoft.com, not secure-check.ru. Extra words, misspellings, and swapped characters like a zero for the letter o are signs of a fake. If anything looks off, do not sign in.