Quishing (QR code phishing) is a cyberattack using malicious QR codes to trick people into
visiting fake websites, downloading malware, or revealing sensitive data like passwords and
financial info, blending the convenience of QR codes with the deception of phishing, often
bypassing email filters by embedding codes in emails, posters, or menus to redirect users to
harmful sites.
Why Quishing Works
- Hidden links: Unlike clickable hyperlinks, QR code destinations are concealed until after
scanning. This stealthy nature allows malicious codes to bypass traditional email filters. - Ubiquitous trust: With QR codes everywhere—from menus to parking meters—many
users scan without verifying. A NordVPN study found that 73% of Americans scan QR
codes without checking their legitimacy. - Ease of deployment: Criminals simply overlay fake QR stickers onto legitimate ones in
public places like parking meters or flyers, relying on urgency to minimize scrutiny.
Common Quishing Scenarios
- Parking meter scams: Fake codes posted on meters redirect users to fraud sites
requesting payment or credit card information. - Restaurant menu overlays: Attackers stick malicious QR codes over legitimate
restaurant menus. Scans lead to fake menus asking for payment or installing malware. - Workplace spear-phishing: Groups like North Korea’s Kimsuky embed QR codes in
emails, directing victims to spoofed login portals — bypassing corporate email defenses
and stealing credentials or tokens.
Alarming Stats
- Nearly 26 million Americans were redirected to malicious sites via quishing.
- Quishing attacks surged from 0.8% in 2021 to about 11% of phishing attacks by
mid2024. - KeepNet reported that 26% of all malicious links in phishing campaigns in 2025 used QR
codes.
How Quishing Works (in steps)
- Create malicious QR — embedding a deceptive URL.
- Distribute — pasted on public materials (menus, flyers), embedded in emails or texts.
- Scan — victim unknowingly visits a spoofed site or downloads malware.
- Exploit — data or credentials are stolen, malware deployed, and sometimes MFA tokens
bypassed. Protection: Stay Safe from Quishing
1. Think Before You Scan
- Pause and verify the source before scanning QR codes on public surfaces or in emails.
- Avoid unfamiliar QR codes, especially in high-stakes places like parking or payment
kiosks.
2. Preview Links
Use default camera QR scanners that preview URLs. Watch for suspicious domains or shortened
links.
3. Reinforce Security
- Keep devices updated and have anti-malware protection.
- Use MultiFactor Authentication (MFA) and monitor for strange login attempts.
4. Physical Awareness
Inspect codes visually—look for overlays, mismatched placement, or sticker signs. Avoid
scanning anything that seems tampered with.
5. Educate & Report
- Organizations should educate staff and run quishing simulations to build awareness.
- Report suspicious QR codes to authorities or site owners—especially public spaces like
parking areas. - Quishing represents a clear intersection of convenience and danger in our increasingly
mobile world. By understanding the threat, scrutinizing before scanning, securing our
devices, and raising awareness, individuals and businesses can significantly reduce the
risk of falling victim to QR code scams. Scan smart—not blindly.
