How QR code phishing (quishing) scams work

Updated View source
Stay safe

QR code phishing, often called quishing, hides a malicious web link inside a QR code so you cannot read the address before you scan it.

How the scam works

A QR code is a picture that stores a web address. Your phone turns it back into a link and offers to open it. Printed as dots, the link cannot be read until you have scanned it.

A QR code versus a written link QR code ? where it goes is hidden until you scan Written link https:// paypa1-secure.com /login the owner is readable before you tap
Same scam link. One hides the owner until it is too late, the other shows it first.

A quishing attack swaps in a QR code that points to a fake page copying a brand you know: a bank, a parcel service, a parking app. It asks you to log in, confirm a payment, or enter card details.

Where quishing shows up

What happens after you scan

Most links lead to a fake sign-in page at an address like login-microsoft.secure-check.ru. Others start a download or ask for card details to release a parcel for a small fee. The fee is fake, the card details are the prize.

How to protect yourself

You do not need to stop using QR codes, only to look before you trust.

Fish Catcher can read a QR code on your screen and check the link before you open it, and warns you in plain language if it looks like a scam. It never blocks the page.

Common questions

Can a QR code itself infect my phone?

No. A QR code only stores text. The risk is the website or file it leads to.

Is it safe to scan a QR code in a restaurant or on a parking meter?

Usually, but check that the code is printed as part of the sign, not a sticker over it, and read the link preview before you tap.

How can I tell if the link after a scan is fake?

Read the part before the ending. A real Microsoft page ends in microsoft.com, not secure-check.ru. Extra words and swapped characters are signs of a fake.