LIVE: New phishing campaigns targeting mobile users —View latest threats →

Back to Threats
High🎣 PhishingNEW

QR Code Phishing (Quishing)

Quishing attacks swap real QR codes with malicious ones in emails and public spaces, redirecting victims to phishing sites that bypass email security tools.

Published: 18 January 2026Last updated: 10 March 2026

What Is This Threat?

Quishing (QR + phishing) is a rapidly growing attack that exploits the public's trust in QR codes. Because QR codes are opaque — you cannot see the URL before scanning — they are ideal for hiding malicious links. Security email filters also struggle to scan them, making quishing highly effective.

How It Works

  • Physical attack: Criminals place sticker QR codes over legitimate ones on parking meters, restaurant menus, bike-sharing stations, and public posters.
  • Email attack: Phishing emails replace clickable links with QR codes, telling you to scan with your phone — which has weaker security controls than a corporate laptop.
  • You scan the code and are taken to a convincing fake login page (Microsoft, PayPal, bank, etc.) on your phone.
  • You enter credentials on your mobile device where corporate security tools aren't active.
  • Your credentials or payment details are stolen.
  • Real 2025–2026 Cases

  • Fake parking payment QR codes reported across Germany, Austria, and Switzerland on parking meters — victims paid criminals instead of the city.
  • Quishing emails bypassing Microsoft Defender by embedding the phishing URL inside an image-based QR code.
  • Fake parcel delivery QR codes on paper slips left at doors.
  • Red Flags

  • QR code sticker placed over an original printed code (look for bubbles or misalignment).
  • Email instructs you to scan a QR code rather than click a link.
  • After scanning, the URL in your browser does not match the expected service.
  • The site asks for login credentials or payment details immediately after scanning.
  • How to Protect Yourself

    • Before scanning a QR code in public, inspect it physically — check for stickers placed over the original
    • After scanning, always check the URL in your browser before entering any data
    • Use a QR scanner app that previews the URL before opening it
    • Never scan QR codes from unsolicited emails — go to the service directly instead
    • Pay for parking via the official app or pay machine, not via QR stickers

    What to Do If Affected

    1. 1.If you scanned a suspicious code but entered no data, you are likely safe — clear your browser cache
    2. 2.If you entered credentials, change your password immediately and enable 2FA
    3. 3.If you made a payment to a fraudulent site, contact your bank to dispute the charge
    4. 4.Report fake QR codes on public infrastructure to your local municipality or police
    5. 5.Report quishing emails to your IT security team or national cybersecurity authority
    #QR code#quishing#phishing#parking#email#2026