QR code phishing (quishing): the scan-and-steal scam
Quishing — QR code phishing — exploits a simple fact: a QR code hides where it goes until you scan it. That removes the one habit that protects people from bad links, inspecting the URL, and lands them on a phone where checking is hardest. It is phishing with the address bar switched off.
Why QR codes are a perfect disguise
- Opaque by design — you can't read a QR code with your eyes, so you can't vet the destination first.
- Scanner-evading — an image of a code in an email or PDF sails past link filters.
- Mobile-first — scanning pushes you onto a phone, where lookalike domains and cloaking thrive.
- Trusted context — codes feel official on posters, invoices and payment notices.
Common quishing tactics
Attackers email a QR code claiming you must "re-authenticate" an account; stick fake codes over real ones on parking meters or restaurant tables; or print them on convincing notices. In each case the scan leads to a fake login or payment page — often cloaked so it looks clean to any automated check.
A QR code is just a link you can't see. Treat the page it opens with the same suspicion as any link in a message — and be especially careful when it asks you to log in or pay.
What brands can do
- Limit sensitive QR flows — avoid asking customers to log in or pay via a raw scanned code where you can.
- Use clear, branded landing pages so a fake destination is easier to tell apart.
- Monitor and take down the lookalike domains and cloned pages quishing campaigns rely on.
Phish Plug detects and removes the cloaked pages and lookalike domains that QR campaigns point to — cutting off quishing at the destination.
The takeaway
Quishing wins by hiding the link inside a code and moving you to a phone. The code itself is harmless; the page it opens is the threat. Be cautious with scans that ask you to log in or pay, and — as a brand — remove the pages those codes lead to.
Keep reading
Related articles
Pharming: when the right address sends you to a fake site
Pharming poisons the path between a correct address and the real server. How DNS-based redirection works, why it is hard to spot, and how to reduce the risk.
Read article Threats · 7 minMalvertising: fake ads that impersonate your brand
Attackers buy ads on your own brand terms to outrank you and send customers to clones. How malvertising works and how to detect and take it down.
Read article Email security · 7 minHow to spot a phishing email: the red flags that matter
The reliable signals of a phishing email — and the ones that no longer hold. A practical guide for people, plus why brands can't rely on it alone.
Read articleRemove the clones targeting your brand
Run a free clone check on one domain — Phish Plug proves the cloaking and files the takedown.