You've probably heard of phishing.
Quishing is essentially phishing that uses QR codes.
Instead of clicking a suspicious link, you're encouraged to scan a code. That code can take you to a fraudulent website designed to look legitimate — often a fake login, payment or verification page.
This explainer covers what quishing means, how it works, where it appears, how it differs from classic phishing, and how to protect yourself. For the wider topic, see QR Code Scams: How They Work, Warning Signs & What to Do.
Quishing in plain language
Phishing tries to trick people into trusting a fake message or destination.
Quishing uses the same idea with a different entry point:
- Classic phishing: “Click this link”
- Quishing: “Scan this QR code”
Once the destination opens, the rest can look familiar: urgent language, trusted logos, and forms asking for passwords, personal details or payments.
How quishing works
A typical quishing attempt follows a pattern:
- A lure appears — an email, text, letter, poster, parking sign or parcel notice.
- A QR code is offered as the quick next step.
- The code opens a deceptive destination, often a lookalike website.
- The page asks for action — sign in, confirm identity, pay a fee, download an app or enter a code.
- The scammer benefits from the information, access or money obtained.
Quishing vs phishing
| Phishing | Quishing | |
|---|---|---|
| Entry point | Link, attachment or message prompt | QR code |
| Common channels | Email, SMS, messaging apps | Those channels plus physical signs and print |
| User action | Click / tap | Scan |
| Goal | Steal data, access or money | Same goals |
They are related. Quishing is best understood as phishing adapted to scanning behaviour.
Where quishing occurs
Quishing can appear in:
- Emails
- Text messages
- Letters
- Posters
- Parking areas
- Packages and delivery notices
- Payment or “scan to pay” stickers
- Other physical locations where scanning feels normal
Because QR codes are already common in those places, a fraudulent code can blend into everyday routines.
Examples of quishing scenarios
These are illustrative patterns, not reports of specific live incidents:
- An email claims your account will be locked unless you scan to verify
- A parcel notice says a delivery fee is due and points to a QR payment page
- A parking sign sticker leads to a lookalike payment site
- A message pretending to be from a bank asks you to scan and confirm a transaction
- A workplace-looking poster asks staff to scan for “mandatory security updates”
In each case, the pressure to act quickly is part of the tactic.
Warning signs of quishing
Many signs overlap with general fake QR code warning signs:
- Unexpected request to scan
- Urgency, threats or countdown language
- Codes that look stuck on over genuine print
- Destination addresses that look odd or unfamiliar
- Requests for passwords, one-time codes or card details after a surprise scan
- Branding that is almost right, but not quite
- A story that falls apart when you pause
How to protect yourself from quishing
Quishing protection checklist
What to do after scanning a quishing code
If you think you scanned a quishing QR code:
- Stop interacting with the destination
- Identify what happened next (opened page, entered details, paid, downloaded)
- Follow the matching steps in I Scanned a Scam QR Code — What Should I Do?
If passwords or payments were involved, prioritise securing accounts and contacting your bank or provider through trusted channels.
Why quishing can feel convincing
Quishing works when three things combine:
- Familiarity — people already scan QR codes for real tasks
- Authority cues — logos, official-sounding language, uniforms or branded print
- Urgency — fear of fines, missed deliveries, locked accounts or lost access
A short pause breaks that combination. That is the heart of Stop. Look. Verify.
Key takeaway
Quishing is QR-code phishing. It is not proof that every QR code is unsafe. It is a reminder that scanning deserves the same caution as clicking.
For the complete overview of techniques, warning signs and recovery steps, return to the QR Code Scams guide.
Frequently asked questions
What does quishing mean?
Quishing is phishing that uses QR codes. Instead of asking you to click a suspicious link, scammers encourage you to scan a code that leads to a fraudulent destination.
Is quishing different from a normal QR code scam?
Quishing is one common form of QR code scam, focused on phishing-style deception such as fake logins and urgent verification pages. Broader QR scams can also involve payments, downloads or physical tampering.
Can quishing happen in person as well as online?
Yes. Quishing can appear in emails and texts, and also on posters, parking signs, parcels, letters and other physical materials.
Related guides
QR Code Scams: How They Work, Warning Signs & What to Do
Learn how QR code scams work, the warning signs to look for, how quishing works and what to do if you've scanned a suspicious QR code.
I Scanned a Scam QR Code — What Should I Do?
Scanned a suspicious QR code? Learn what to do if you entered a password, shared payment details, downloaded something or made a payment.
How to Spot a Fake QR Code: 10 Warning Signs
Learn the 10 warning signs of a fake QR code, from suspicious URLs and unexpected payments to physical QR-code tampering.
QRaware provides educational information about QR-code scams and online fraud. It is not a substitute for professional cybersecurity, financial or legal advice.