A QR code is a compact link, not proof that the destination is trustworthy. In a quishing attack, the code moves a victim from an email, poster, invoice or parking notice to a fake login or payment page. The image can also evade filters that normally inspect clickable links.
Pause before moving to the phone
An unexpected code that claims an account will close, a parcel is delayed or a payment failed is a reason to verify independently. Do not scan it merely to “see where it goes” on a device that holds banking apps and signed-in accounts.
Safer verification
- Open the organization's official app or type its known address.
- For a physical code, check whether a sticker covers the original sign.
- Preview the decoded URL and read the full domain before opening.
- Do not install an app, profile or certificate from the resulting page.
- Report suspicious workplace codes to the security team.
If you entered information
Change the affected password through the official service, end active sessions and review MFA methods. Contact the payment provider immediately if money or card details were submitted. Preserve the message or photograph as evidence.
A familiar logo beside a QR code is easy to reproduce. Trust should come from an independently reached service and a domain you have checked, not from the printed square itself.
A workplace example
An invoice arrives with a QR code labelled “view secure document.” The accounts employee should locate the supplier in the approved vendor system and call the stored number, not the number printed on the invoice. If the supplier confirms no request, the image and message can be reported without ever opening the destination.
What a safe code should provide
Organizations using QR codes should display the human-readable domain and offer a normal typed or clickable alternative. A code that is the only route to an urgent payment deserves extra scrutiny.
Use the destination, not the artwork, as evidence
A branded QR code can be printed, copied or covered with a sticker in seconds. Before opening it, use the camera preview to read the complete host name. For a restaurant, parking meter or payment counter, compare the code with the organization's official app or printed web address and ask staff if anything looks altered.
Payment codes require an extra check
Confirm the merchant name and amount inside the payment app before authorizing. A code that opens an ordinary web form asking for full card details is not equivalent to a verified in-app payment request. On a work device, avoid scanning a code from an unsolicited document because it moves the attack outside the company's email controls.
Security teams should preserve the image and decode it in an isolated analysis process. Publishing a sensitive reset or document-sharing URL to a public scanner may expose the very resource being investigated.
Verify the action before scanning
A QR code is only an encoding of data. The logo, colour and placement around it provide no proof of ownership. Before scanning a payment, parking or sign-in code, ask what action should happen and find an independent way to confirm the organization. A sticker placed over a legitimate code can redirect a phone without changing anything else on the sign.
Use the camera preview to inspect the complete destination. Read the registered domain, not the familiar words placed before it. For payment codes, check the merchant name and amount inside the banking application before authorizing. A web form asking for full card details is different from a verified in-app payment request.
Handle workplace QR codes as links
Email controls may inspect an ordinary link but fail to decode an image. Attackers use this gap to move the sign-in attempt to a personal phone that has fewer protections. Organizations should decode codes in a controlled scanner, preserve the original message and train users to report the request before opening it.
If credentials were entered, use the legitimate service to change them, revoke sessions and inspect MFA activity. If payment information was supplied, contact the issuer promptly. Deleting the image or browser history does not invalidate information already submitted.