Cybersecurity & QR
QR phishing (quishing): how attackers hijack trust
People learned to distrust odd links in email. A QR code hides the address behind a square — and that is why quishing works: scanning feels harmless, yet it is the same click on a URL.
What quishing is — and how it differs from classic phishing
Quishing is phishing delivered through a QR code. The goal is familiar: push someone onto a malicious page, harvest a login, confirm a payment, or trigger a download. The difference is the delivery channel. Instead of a blue “click here”, the attacker shows a code that the phone camera opens instantly.
The usual moment of doubt disappears: there is no visible domain until the page is already loading. If the phone opens the link blindly, URL checks happen too late — sometimes after credentials are typed.
Why QR codes bypass caution
- Speed. A scan takes a second — the brain does not “read” risk.
- Trusted context. A code on a café menu, parking meter, or “official” letter looks legitimate.
- Hidden address. You see a square, not
evil-pay.example.
Rule of thumb: a QR is not a safe format — it is only a compact way to carry the same URL, Wi-Fi string, or other payload.
Typical attack scenarios
Fake “bank / delivery / tax” messages with a QR “for quick login”. The victim lands on a clone site and types a password.
Parking and payments. A sticker over the real payment code sends money to the attacker.
Restaurants and hotels. A “menu” or “Wi-Fi” code leads to a form that asks for card details “for tips”.
Offices and events. Badge or handout codes get swapped to harvest corporate credentials.
Red flags: do not open immediately
- The code pushes urgent “sign in”, “confirm payment”, or “update details”.
- The sticker looks fresh over an older one, wrinkled, or printed differently.
- The domain after decoding does not match the brand (extra hyphens, wrong TLD).
- The page asks for a password, CVV, or an APK/EXE download right away.
- A stranger in a messenger says “just scan this”.
How to check a QR before you open it
If the context feels even slightly off, do not let the phone camera open the destination blindly. Decode first and inspect where it points — without visiting the page.
QRcode Global offers a scanner with a malicious-content check: it shows the decoded payload and helps you judge risk before the browser loads the link.