Skip to content

Quishing (fraudulent QR code)

In plain terms

A QR code doesn't show where it leads. A sticker placed on a parking meter or a terminal is enough to send people to a fake payment page.

Definition

Quishing is the use of a QR code to direct people to a fraudulent site: the code hides the destination address, which is therefore not readable before it's opened.

How it works

A QR code is just an address encoded as a graphic. Nothing about its appearance indicates where it leads: two visually similar codes can point to unrelated destinations. The attacker places a fraudulent code where the process seems ordinary — a sticker placed over a parking meter or terminal, a letter imitating an administration, a poster in a public place — and the destination mimics a payment service or a login page. The scan is most often done on a phone, where the address is shown truncated and where people pay less attention than at a desk.

Warning signs

  • Sticker placed over an original QR code, or a code that's visibly been added
  • Address displayed after the scan unrelated to the expected organization
  • Request for immediate payment or credentials after a simple scan
  • QR code received by mail or message for an unsolicited procedure
  • Successive redirects between the scan and the final page

How to verify

Before opening it, read the address your phone shows in the preview and check the domain name. For a payment or an administrative procedure, ignore the code and reach the official service on your own: a QR code is never the only path available.

What to do

Don't open the page if the domain doesn't match the expected organization. On a physical support, check that no sticker covers the original code.

If it already happened

If banking details were entered, block your card immediately. If credentials were entered, change the affected password and enable two-factor authentication. Report the incident to the relevant authority.

Frequently asked questions

Is simply scanning a QR code dangerous?
Scanning only displays an address. The risk starts when the page opens, and above all when information is entered. Get into the habit of reading the address preview before opening it.
How do I spot a fraudulent QR code on a physical support?
Run your finger over it: a sticker placed over the original code can be felt by touch, and that's the most reliable signal on a terminal or parking meter.

Official sources

This article is part of the Website and browser attacks family. Last updated: 2026-08-31.