QR-code "quishing" scams: why you can’t see where a code leads
Scammers hide harmful links inside QR codes — on stickers, in texts, and on unexpected packages. Here’s how quishing works, the tells, and the free move that defeats it.
A QR code is convenient precisely because you don’t have to read a long web address — you just point your camera and go. That’s also what makes it a great hiding place for a scam. With “quishing” (QR-code phishing), the harmful link is tucked inside the code, so nothing looks wrong until you’ve already landed on a fake page.
How the scam works
- The placement. Scammers stick their own QR code over a real one (on a parking meter or a poster), text or email you a code with a made-up reason to scan, or even mail an unsolicited package containing a code.
- The spoofed page. Scanning opens a site dressed up to look real. If you log in or enter card details, the scammer captures them.
- The payload. Some codes push you to a page that tries to install malware or harvest personal information like card or Social Security numbers.
- The cover. Because the destination is hidden behind the code, a look-alike address (a small misspelling, an odd domain) is much easier to miss than it would be in a normal link.
The core problem in one line: you can’t see where a QR code goes before you commit to it. That single blind spot is what the whole scam rents.
How to spot it
The tells are in the box below. The simplest rule: a QR code in an unexpected place, pushing you to act fast, is guilty until proven innocent. Inspect the URL before you act, and if it asks you to log in or pay, stop.
What to do instead
You don’t need an app to beat this — the free move comes first (see the defense box). The habit that defeats it is Go Direct: instead of scanning a code you can’t verify, open the official app or type the real website yourself. For payments especially, reach the company on a channel you already trust. See the other named defense moves, or sharpen your eye on the 60-second quiz.
- A QR code turns up somewhere unexpected — a sticker over a real one, a random text, or an unsolicited package.
- Scanning it opens a page that asks you to log in or hand over card or personal details.
- The web address is a look-alike — a small misspelling or an unfamiliar domain you can’t verify.
- Don’t scan QR codes you weren’t expecting — especially ones urging you to act immediately.
- Before you open a code’s link, preview the URL and check it for misspellings or switched letters.
- To pay or log in, go to the official app or website yourself rather than through a scanned code.
- If you entered details after scanning, change that password, turn on two-factor authentication, and watch your accounts.
A QR code is just a link you can’t read — that’s the whole trick. We’ve all been trained to scan without thinking at restaurants and parking meters, and scammers are renting that reflex. When a code shows up somewhere it shouldn’t, the safe move is boring: ignore it and go to the source yourself.
Sources
Frequently asked
What is "quishing"?
Quishing is phishing that uses a QR code instead of a visible link. Because the destination is hidden inside the code, you can’t see where it leads until you’ve already scanned it — which is exactly why scammers like it.
Is it dangerous just to scan a QR code?
Scanning usually just opens a link, so the real risk is what you do next — logging in or entering details on a spoofed page. Preview the URL first, and don’t enter anything if the address looks off.
I got a package I didn’t order with a QR code inside. What should I do?
The FBI warns these can be a fraud setup. Don’t scan the code. Treat the unexpected package and its code as suspicious, and report it.