9 min read

What Is Quishing? QR Code Phishing Explained

Quishing is QR code phishing - a scam that hides a malicious link inside a QR code you can't preview. Learn how it works and how to stay safe.

P

Pavel Demidovich

Developer and Founder of Email Scam Checker

Quishing - short for "QR phishing" or "QR code phishing" - is a phishing attack that hides a link's real destination inside a QR code, so neither you nor a URL filter that only reads visible links can see where it leads until the code is scanned. The QR code itself is just data; the danger is the website or login page waiting on the other side.

  • Quishing is "QR code phishing" - a malicious link stored inside a QR code instead of clickable text.
  • The trick is invisibility: a URL filter that only reads the visible link can miss a destination encoded in an image, so it stays hidden until you scan it.
  • Quishing shows up both digitally - in emails and texts - and physically, as a sticker swapped over a real QR code.
  • Scanning a malicious QR code can lead to a fake login page, a malware download, or a payment form that sends money to the attacker.
  • You can't hover over a QR code to preview its link, which is why decoding it before you scan is the key protection.

Quishing definition and meaning

The quishing definition is straightforward - "quishing" blends "QR code" and "phishing" - and the quishing meaning is a phishing attack that hides a malicious destination inside a QR code instead of printing it as a clickable link. It is the type of phishing that uses QR codes rather than a link you can click or hover over. A QR code is a two-dimensional barcode that encodes text, most often a web address, so the real destination stays sealed inside that image until you scan it.

Because the link is stored as an image rather than visible text, it can slip past link scanners and spam filters that only inspect the visible words and URLs, not the image itself. Wikipedia's entry on phishing groups QR-code phishing with email, text, and phone variants - the same social-engineering deception, delivered through a different channel.

Why quishing works

Quishing works because it removes the one thing most people are trained to check: the link. With a normal phishing email you can hover over a link or read the URL before you click. With a QR code there is nothing to hover over - the destination is sealed inside a black-and-white image until your phone's camera decodes it.

The other half is borrowed trust. People treat QR codes as a shortcut to something legitimate - a menu, a parking payment, a package-tracking page - so the "scan to continue" prompt rarely gets the scrutiny a URL does. The FBI warned that criminals tamper with QR codes to redirect victims, swapping a real code for a malicious one on signs and payment stickers.

How a QR code scam works

Every quishing scam works the same way: the attacker creates a malicious destination, hides it in a QR code, and gets that code in front of you. Here is what happens once you scan it.

  1. You scan the code. Your phone reads it and shows a preview of the URL - or sometimes opens it immediately, depending on the app.
  2. You land on a lookalike page. The destination is a fake login, payment, or "track your package" page built to match the real brand.
  3. You hand something over. You enter credentials, card details, or approve a payment - and the attacker takes whatever you gave them.

The same code can also trigger a malware download instead of opening a page, but credential theft and payment fraud are the most common outcomes.

Common quishing scams

How can QR codes be used in phishing scams? The codes ride on everyday moments where scanning feels routine, so they rarely look out of place - and rarely get the scrutiny a visible link would.

Parking and payment stickers are the classic example: a scammer places a fake QR code over the one on a parking meter or a restaurant table, so the payment you think goes to the operator goes to the attacker instead. The FTC's guidance on scammers hiding harmful links in QR codes points to this sticker-swap tactic, plus fake delivery notices and unpaid-invoice messages that arrive by email or text.

A newer variation uses unsolicited packages. A box you never ordered arrives with a note telling you to scan a QR code to find out who sent it or how to return it - a spin on "brushing" scams that the FBI flagged in a public service announcement about QR codes on unsolicited packages. Scanning it leads to a page built to harvest your details or install malware, and there is no legitimate sender behind the package at all.

Quishing vs other phishing types

What sets quishing apart from the rest of the phishing family is where the link is hidden. Email and text phishing still leave the destination as readable text you can hover over or inspect; quishing is the one channel where it is sealed inside an image you cannot preview. For the full family of attacks, our guide to what phishing is breaks down each type.

Attack type Delivery channel Where the link hides Primary risk The tell
Quishing QR code - email, text, or sticker Sealed inside an image you can't preview Silent redirect to a fake login or payment page No URL to inspect before scanning
Email phishing Email, mass-sent Fake display text over a real link Credentials or card details entered on a fake page Hover to reveal the real destination
Smishing Text message Shortened or masked link Credentials or payment taken through a fraudulent link Unknown sender plus an urgent claim
Vishing Phone call No link at all - voice pressure Payment or credentials handed over on the call Caller demands immediate payment or details
Spear phishing Email, individually researched Convincing domain plus personal details Targeted credential theft or a fraudulent transfer An unusual request from someone you know

How to spot a quishing attack

You can't hover over a QR code, but you can still check what surrounds it before you scan. The same sender, link, and language instincts apply - they just apply to the message around the code rather than the code itself. Our guide to spotting a phishing email walks through each red flag in detail.

  • Check the source. Who is asking you to scan, and through what channel? An unexpected email, text, or package note is the first warning sign.
  • Preview the URL. Most modern phone cameras and QR scanners show the decoded URL before opening it - read it for misspellings or an unfamiliar domain, and don't proceed if it looks off.
  • Treat urgency as a red flag. "Scan now to avoid a late fee" or "your package is on hold" is pressure, not information.
  • Look for tampering. On a physical code, check whether a sticker has been placed over the original.

How Email Scam Checker protects against quishing

We treat a QR code in an email as a link that happens to be hiding - and we decode it before you ever point a phone at it.

One of our heuristic checks finds QR codes inside an email, decodes any web address they contain, and runs that address through the same link checks as a visible link - suspicious domains, redirect shorteners, homoglyphs, and the rest. If the code sits inside an attached PDF rather than the message body, we open the PDF and decode it the same way on Gmail, Outlook, Yahoo Mail, and Zoho Mail. On Proton Mail and iCloud Mail, where attachments are end-to-end encrypted or served through a cross-origin token API, we can't read the PDF directly, so we flag it with a low-severity "attachment may hide a link" caution instead.

We also flag the presence of a QR code itself as a low-severity caution, because a link delivered as a picture is worth a second look even when its destination looks clean. Attachments we can't read - office files or images, or a PDF whose code we couldn't decode - still get a low-severity caution, since an attachment with no visible link is the classic shape of a message hiding its real destination. And if a decoded QR code points to a domain registered in the last 30 days, our fresh-domain lookup flags it as a supporting risk signal - a recent registration is worth scrutiny, though it is not proof of phishing on its own.

One honest caveat: for QR codes rendered as images, we read the ones we can access directly. A QR embedded straight into the email is caught reliably; one that your mail provider loads from a remote server may not be visible to us on every provider, so treat an unexpected QR code with the same caution you would an unexpected link.

All of this runs automatically the moment you open a message in Gmail, Outlook, Yahoo Mail, Proton Mail, iCloud Mail, or Zoho Mail. Our more than two dozen heuristic checks score each email from 0 to 100, and our optional on-device AI Deep Scan adds a second opinion that runs entirely offline. For services that support them, anti-phishing codes give one more layer of verification for emails that claim to come from Coinbase, Gate, Binance, or Proton Mail.

How to prevent quishing

Preventing quishing is mostly about refusing to scan on impulse - and letting software do the checking you can't.

  • Don't scan QR codes from unexpected emails, texts, or packages.
  • Preview the URL before opening it, and back out if the domain looks unfamiliar or misspelled.
  • Type a company's address directly instead of scanning a payment or login code.
  • Inspect physical codes for a sticker placed over the original.
  • Let automated detection decode and check the QR codes in your inbox before you do.

Government guidance lands on the same point: CISA's phishing guidance says to stop and verify before responding, and the FTC repeats the same "think before you scan" advice. Browser protections like Google Safe Browsing catch many known-malicious destinations once you tap through - but a brand-new page behind a code may not be classified yet. If you're weighing detection tools, our best phishing protection comparison lines up the options side by side.

Final verdict - quishing

Quishing is phishing that hides its destination inside a QR code, and it works because you cannot inspect an image the way you can inspect a link. The defense is the same instinct you use for any phishing attempt - slow down, verify the source, and never hand over credentials or payment on impulse - backed by software that reads the code before you do. Treat an email with a QR code the way you treat an email with an unknown link, because that is exactly what it is.

Frequently asked questions

What is quishing?

Quishing - short for "QR code phishing" - is a phishing attack that hides a malicious link inside a QR code, so the destination stays hidden until you scan it. A scammer puts the code in an email, a text, or over a real code on a sign, and the scan leads to a fake login or payment page.

Can you get scammed by scanning a QR code?

Yes. A QR code can open a fake login page, trigger a malware download, or send you to a payment form that sends money to the attacker instead of the business. The code itself is not dangerous - the destination it encodes is, which is why you should preview the URL and verify the source before scanning anything unexpected.

Is scanning a QR code itself dangerous?

Scanning a QR code is usually safe - it only decodes the text stored in the image. The danger starts with what you do next: tapping the decoded link, entering credentials, or approving a payment. A scan alone does not compromise your device, which is why you should preview the decoded URL and stop before opening it or handing anything over.

How do QR code scams work?

An attacker creates a malicious page or payment form, encodes its address in a QR code, and gets the code in front of you - in a phishing email, a fake delivery text, or a sticker placed over a real code on a parking meter. When you scan it, you are redirected to a lookalike page that asks for credentials, card details, or a payment.

What happens if you scan a scam QR code?

Usually one of three things: you land on a phishing page that harvests credentials or card details, a payment you authorize goes to the scammer, or a download starts that installs malware. If you scanned one and entered anything, change that account's password immediately and report the message to your provider.

Are QR codes safe?

QR codes themselves are safe - they are just a way to store text, usually a web address. The risk is who controls the destination. A code from a trusted business on its own printed material is low risk; a code in an unexpected email, text, or stuck over another code on a sign is worth refusing until you can verify where it leads.

Can QR codes be used in phishing emails?

Yes. A quishing email hides its malicious link inside a QR code instead of a clickable link, so it slips past URL filters that read text rather than images. Email Scam Checker decodes QR codes in emails - including ones inside attached PDFs - and runs the decoded address through the same link checks as a normal link.

How do you prevent QR code phishing?

Don't scan QR codes from unexpected messages or packages, preview the URL before opening it, type a company's address directly instead of scanning a payment code, and check physical codes for a sticker placed over the original. Automated detection helps too, since it can decode and check a QR code in your inbox before you ever scan it.

More from the blog