Scams & fraud
Quishing
Quishing is phishing delivered through a QR code — a quick scan that can send you to a fake login, payment page, or malware download.
What it is
Quishing combines “QR” and “phishing.” Instead of a suspicious link in an email alone, the attacker puts a QR code on a poster, flyer, parking ticket, restaurant table tent, package label, or inside a message. When you scan it, your phone opens a URL the scammer controls.
The goal is the same as classic phishing: steal passwords, one-time codes, payment details, or personal data — or push you into installing something harmful. Quishing works well because people trust QR codes in everyday places and often scan without checking the destination.
How it works
- Bait — A QR code appears somewhere you might expect a real one (billing notice, delivery update, Wi‑Fi signup, “verify your account,” parking payment).
- Scan — Your camera or QR app opens a link. On many phones you only see a short preview of the domain — easy to miss if it’s a lookalike.
- Trap — A page mimics a bank, delivery service, employer portal, or crypto wallet and asks you to sign in, pay, or “confirm” identity.
- Payoff — Stolen credentials, card data, or remote access; sometimes a follow-up call or text (vishing/smishing) to finish the scam.
Attackers also sticker over legitimate codes (for example on parking meters or restaurant menus) so a trusted place leads to a malicious URL.
Red flags
- A QR code in an unexpected place, or one that looks freshly stuck over another code
- Urgency: “Pay now,” “Account locked,” “Package held — scan to release”
- After scanning, the URL doesn’t match the brand you expected (misspellings, odd domains, extra words)
- A login or payment page that asks for more than the situation needs (SSN, seed phrase, full card + CVV + “verify by text”)
- Requests to install an app from outside the official App Store / Google Play
- A code sent in a cold email or text from someone you don’t do business with
What to do if you’re targeted
- Don’t enter credentials or pay on a page you reached from a surprise QR code. Close the tab.
- Check the URL before typing anything. When in doubt, open the real site or app yourself (bookmark or official store listing) — don’t reuse the scanned link.
- If you already entered a password: change it on the real site, enable multifactor authentication, and review recent account activity.
- If you shared payment info: contact your bank or card issuer and watch statements.
- Report phishing to the platform or brand involved, and consider reporting to the FTC at ReportFraud.ftc.gov (U.S.).
- For a broader check-in: run a free identity scan or start monitoring if you’re worried your personal data may already be exposed elsewhere.
Related terms
Related reading
Next steps
Free identity scan
Curious whether your info may be exposed? Start with a free identity scan.
Free identity scanProtect your identity
Monitoring for dark web and social risks, plus identity theft insurance up to $1M (subject to policy terms).
Protect your identity