Quishing - short for "QR phishing" or "QR code phishing" - is a phishing attack that hides a link's real destination inside a QR code, so neither you nor a URL filter that only reads visible links can see where it leads until the code is scanned. The QR code itself is just data; the danger is the website or login page waiting on the other side.
- Quishing is "QR code phishing" - a malicious link stored inside a QR code instead of clickable text.
- The trick is invisibility: a URL filter that only reads the visible link can miss a destination encoded in an image, so it stays hidden until you scan it.
- Quishing shows up both digitally - in emails and texts - and physically, as a sticker swapped over a real QR code.
- Scanning a malicious QR code can lead to a fake login page, a malware download, or a payment form that sends money to the attacker.
- You can't hover over a QR code to preview its link, which is why decoding it before you scan is the key protection.
Quishing definition and meaning
The quishing definition is straightforward - "quishing" blends "QR code" and "phishing" - and the quishing meaning is a phishing attack that hides a malicious destination inside a QR code instead of printing it as a clickable link. It is the type of phishing that uses QR codes rather than a link you can click or hover over. A QR code is a two-dimensional barcode that encodes text, most often a web address, so the real destination stays sealed inside that image until you scan it.
Because the link is stored as an image rather than visible text, it can slip past link scanners and spam filters that only inspect the visible words and URLs, not the image itself. Wikipedia's entry on phishing groups QR-code phishing with email, text, and phone variants - the same social-engineering deception, delivered through a different channel.
Why quishing works
Quishing works because it removes the one thing most people are trained to check: the link. With a normal phishing email you can hover over a link or read the URL before you click. With a QR code there is nothing to hover over - the destination is sealed inside a black-and-white image until your phone's camera decodes it.
The other half is borrowed trust. People treat QR codes as a shortcut to something legitimate - a menu, a parking payment, a package-tracking page - so the "scan to continue" prompt rarely gets the scrutiny a URL does. The FBI warned that criminals tamper with QR codes to redirect victims, swapping a real code for a malicious one on signs and payment stickers.
How a QR code scam works
Every quishing scam works the same way: the attacker creates a malicious destination, hides it in a QR code, and gets that code in front of you. Here is what happens once you scan it.
- You scan the code. Your phone reads it and shows a preview of the URL - or sometimes opens it immediately, depending on the app.
- You land on a lookalike page. The destination is a fake login, payment, or "track your package" page built to match the real brand.
- You hand something over. You enter credentials, card details, or approve a payment - and the attacker takes whatever you gave them.
The same code can also trigger a malware download instead of opening a page, but credential theft and payment fraud are the most common outcomes.
Common quishing scams
How can QR codes be used in phishing scams? The codes ride on everyday moments where scanning feels routine, so they rarely look out of place - and rarely get the scrutiny a visible link would.
Parking and payment stickers are the classic example: a scammer places a fake QR code over the one on a parking meter or a restaurant table, so the payment you think goes to the operator goes to the attacker instead. The FTC's guidance on scammers hiding harmful links in QR codes points to this sticker-swap tactic, plus fake delivery notices and unpaid-invoice messages that arrive by email or text.
A newer variation uses unsolicited packages. A box you never ordered arrives with a note telling you to scan a QR code to find out who sent it or how to return it - a spin on "brushing" scams that the FBI flagged in a public service announcement about QR codes on unsolicited packages. Scanning it leads to a page built to harvest your details or install malware, and there is no legitimate sender behind the package at all.
Quishing vs other phishing types
What sets quishing apart from the rest of the phishing family is where the link is hidden. Email and text phishing still leave the destination as readable text you can hover over or inspect; quishing is the one channel where it is sealed inside an image you cannot preview. For the full family of attacks, our guide to what phishing is breaks down each type.
| Attack type | Delivery channel | Where the link hides | Primary risk | The tell |
|---|---|---|---|---|
| Quishing | QR code - email, text, or sticker | Sealed inside an image you can't preview | Silent redirect to a fake login or payment page | No URL to inspect before scanning |
| Email phishing | Email, mass-sent | Fake display text over a real link | Credentials or card details entered on a fake page | Hover to reveal the real destination |
| Smishing | Text message | Shortened or masked link | Credentials or payment taken through a fraudulent link | Unknown sender plus an urgent claim |
| Vishing | Phone call | No link at all - voice pressure | Payment or credentials handed over on the call | Caller demands immediate payment or details |
| Spear phishing | Email, individually researched | Convincing domain plus personal details | Targeted credential theft or a fraudulent transfer | An unusual request from someone you know |
How to spot a quishing attack
You can't hover over a QR code, but you can still check what surrounds it before you scan. The same sender, link, and language instincts apply - they just apply to the message around the code rather than the code itself. Our guide to spotting a phishing email walks through each red flag in detail.
- Check the source. Who is asking you to scan, and through what channel? An unexpected email, text, or package note is the first warning sign.
- Preview the URL. Most modern phone cameras and QR scanners show the decoded URL before opening it - read it for misspellings or an unfamiliar domain, and don't proceed if it looks off.
- Treat urgency as a red flag. "Scan now to avoid a late fee" or "your package is on hold" is pressure, not information.
- Look for tampering. On a physical code, check whether a sticker has been placed over the original.
How Email Scam Checker protects against quishing
We treat a QR code in an email as a link that happens to be hiding - and we decode it before you ever point a phone at it.
One of our heuristic checks finds QR codes inside an email, decodes any web address they contain, and runs that address through the same link checks as a visible link - suspicious domains, redirect shorteners, homoglyphs, and the rest. If the code sits inside an attached PDF rather than the message body, we open the PDF and decode it the same way on Gmail, Outlook, Yahoo Mail, and Zoho Mail. On Proton Mail and iCloud Mail, where attachments are end-to-end encrypted or served through a cross-origin token API, we can't read the PDF directly, so we flag it with a low-severity "attachment may hide a link" caution instead.
We also flag the presence of a QR code itself as a low-severity caution, because a link delivered as a picture is worth a second look even when its destination looks clean. Attachments we can't read - office files or images, or a PDF whose code we couldn't decode - still get a low-severity caution, since an attachment with no visible link is the classic shape of a message hiding its real destination. And if a decoded QR code points to a domain registered in the last 30 days, our fresh-domain lookup flags it as a supporting risk signal - a recent registration is worth scrutiny, though it is not proof of phishing on its own.
One honest caveat: for QR codes rendered as images, we read the ones we can access directly. A QR embedded straight into the email is caught reliably; one that your mail provider loads from a remote server may not be visible to us on every provider, so treat an unexpected QR code with the same caution you would an unexpected link.
All of this runs automatically the moment you open a message in Gmail, Outlook, Yahoo Mail, Proton Mail, iCloud Mail, or Zoho Mail. Our more than two dozen heuristic checks score each email from 0 to 100, and our optional on-device AI Deep Scan adds a second opinion that runs entirely offline. For services that support them, anti-phishing codes give one more layer of verification for emails that claim to come from Coinbase, Gate, Binance, or Proton Mail.
How to prevent quishing
Preventing quishing is mostly about refusing to scan on impulse - and letting software do the checking you can't.
- Don't scan QR codes from unexpected emails, texts, or packages.
- Preview the URL before opening it, and back out if the domain looks unfamiliar or misspelled.
- Type a company's address directly instead of scanning a payment or login code.
- Inspect physical codes for a sticker placed over the original.
- Let automated detection decode and check the QR codes in your inbox before you do.
Government guidance lands on the same point: CISA's phishing guidance says to stop and verify before responding, and the FTC repeats the same "think before you scan" advice. Browser protections like Google Safe Browsing catch many known-malicious destinations once you tap through - but a brand-new page behind a code may not be classified yet. If you're weighing detection tools, our best phishing protection comparison lines up the options side by side.
Final verdict - quishing
Quishing is phishing that hides its destination inside a QR code, and it works because you cannot inspect an image the way you can inspect a link. The defense is the same instinct you use for any phishing attempt - slow down, verify the source, and never hand over credentials or payment on impulse - backed by software that reads the code before you do. Treat an email with a QR code the way you treat an email with an unknown link, because that is exactly what it is.