Skip to content
QRaware

What Is Quishing? QR Code Phishing Explained

What is quishing? Learn how QR-code phishing works, where scammers use it and how to recognise and avoid QR-code phishing attacks.

You've probably heard of phishing.

Quishing is essentially phishing that uses QR codes.

Instead of clicking a suspicious link, you're encouraged to scan a code. That code can take you to a fraudulent website designed to look legitimate — often a fake login, payment or verification page.

This explainer covers what quishing means, how it works, where it appears, how it differs from classic phishing, and how to protect yourself. For the wider topic, see QR Code Scams: How They Work, Warning Signs & What to Do.

Quishing in plain language

Phishing tries to trick people into trusting a fake message or destination.

Quishing uses the same idea with a different entry point:

  • Classic phishing: “Click this link”
  • Quishing: “Scan this QR code”

Once the destination opens, the rest can look familiar: urgent language, trusted logos, and forms asking for passwords, personal details or payments.

How quishing works

A typical quishing attempt follows a pattern:

  1. A lure appears — an email, text, letter, poster, parking sign or parcel notice.
  2. A QR code is offered as the quick next step.
  3. The code opens a deceptive destination, often a lookalike website.
  4. The page asks for action — sign in, confirm identity, pay a fee, download an app or enter a code.
  5. The scammer benefits from the information, access or money obtained.

Quishing vs phishing

PhishingQuishing
Entry pointLink, attachment or message promptQR code
Common channelsEmail, SMS, messaging appsThose channels plus physical signs and print
User actionClick / tapScan
GoalSteal data, access or moneySame goals

They are related. Quishing is best understood as phishing adapted to scanning behaviour.

Where quishing occurs

Quishing can appear in:

  • Emails
  • Text messages
  • Letters
  • Posters
  • Parking areas
  • Packages and delivery notices
  • Payment or “scan to pay” stickers
  • Other physical locations where scanning feels normal

Because QR codes are already common in those places, a fraudulent code can blend into everyday routines.

Examples of quishing scenarios

These are illustrative patterns, not reports of specific live incidents:

  • An email claims your account will be locked unless you scan to verify
  • A parcel notice says a delivery fee is due and points to a QR payment page
  • A parking sign sticker leads to a lookalike payment site
  • A message pretending to be from a bank asks you to scan and confirm a transaction
  • A workplace-looking poster asks staff to scan for “mandatory security updates”

In each case, the pressure to act quickly is part of the tactic.

Warning signs of quishing

Many signs overlap with general fake QR code warning signs:

  • Unexpected request to scan
  • Urgency, threats or countdown language
  • Codes that look stuck on over genuine print
  • Destination addresses that look odd or unfamiliar
  • Requests for passwords, one-time codes or card details after a surprise scan
  • Branding that is almost right, but not quite
  • A story that falls apart when you pause

How to protect yourself from quishing

Quishing protection checklist

What to do after scanning a quishing code

If you think you scanned a quishing QR code:

  1. Stop interacting with the destination
  2. Identify what happened next (opened page, entered details, paid, downloaded)
  3. Follow the matching steps in I Scanned a Scam QR Code — What Should I Do?

If passwords or payments were involved, prioritise securing accounts and contacting your bank or provider through trusted channels.

Why quishing can feel convincing

Quishing works when three things combine:

  • Familiarity — people already scan QR codes for real tasks
  • Authority cues — logos, official-sounding language, uniforms or branded print
  • Urgency — fear of fines, missed deliveries, locked accounts or lost access

A short pause breaks that combination. That is the heart of Stop. Look. Verify.

Key takeaway

Quishing is QR-code phishing. It is not proof that every QR code is unsafe. It is a reminder that scanning deserves the same caution as clicking.

For the complete overview of techniques, warning signs and recovery steps, return to the QR Code Scams guide.

Frequently asked questions

What does quishing mean?

Quishing is phishing that uses QR codes. Instead of asking you to click a suspicious link, scammers encourage you to scan a code that leads to a fraudulent destination.

Is quishing different from a normal QR code scam?

Quishing is one common form of QR code scam, focused on phishing-style deception such as fake logins and urgent verification pages. Broader QR scams can also involve payments, downloads or physical tampering.

Can quishing happen in person as well as online?

Yes. Quishing can appear in emails and texts, and also on posters, parking signs, parcels, letters and other physical materials.

Related guides

QRaware provides educational information about QR-code scams and online fraud. It is not a substitute for professional cybersecurity, financial or legal advice.