Scam Defence

QR Code Phishing: How to Check a “Quishing” Message

QR codes hide their destination until scanned. Learn how quishing messages steal logins and how to inspect a request without trusting it.

Muhammad Azhar August 14, 2026 Reviewed August 14, 2026 3 min read

A QR code is a compact link, not proof that the destination is trustworthy. In a quishing attack, the code moves a victim from an email, poster, invoice or parking notice to a fake login or payment page. The image can also evade filters that normally inspect clickable links.

Pause before moving to the phone

An unexpected code that claims an account will close, a parcel is delayed or a payment failed is a reason to verify independently. Do not scan it merely to “see where it goes” on a device that holds banking apps and signed-in accounts.

Safer verification

  1. Open the organization's official app or type its known address.
  2. For a physical code, check whether a sticker covers the original sign.
  3. Preview the decoded URL and read the full domain before opening.
  4. Do not install an app, profile or certificate from the resulting page.
  5. Report suspicious workplace codes to the security team.

If you entered information

Change the affected password through the official service, end active sessions and review MFA methods. Contact the payment provider immediately if money or card details were submitted. Preserve the message or photograph as evidence.

A familiar logo beside a QR code is easy to reproduce. Trust should come from an independently reached service and a domain you have checked, not from the printed square itself.

A workplace example

An invoice arrives with a QR code labelled “view secure document.” The accounts employee should locate the supplier in the approved vendor system and call the stored number, not the number printed on the invoice. If the supplier confirms no request, the image and message can be reported without ever opening the destination.

What a safe code should provide

Organizations using QR codes should display the human-readable domain and offer a normal typed or clickable alternative. A code that is the only route to an urgent payment deserves extra scrutiny.

Use the destination, not the artwork, as evidence

A branded QR code can be printed, copied or covered with a sticker in seconds. Before opening it, use the camera preview to read the complete host name. For a restaurant, parking meter or payment counter, compare the code with the organization's official app or printed web address and ask staff if anything looks altered.

Payment codes require an extra check

Confirm the merchant name and amount inside the payment app before authorizing. A code that opens an ordinary web form asking for full card details is not equivalent to a verified in-app payment request. On a work device, avoid scanning a code from an unsolicited document because it moves the attack outside the company's email controls.

Security teams should preserve the image and decode it in an isolated analysis process. Publishing a sensitive reset or document-sharing URL to a public scanner may expose the very resource being investigated.

Sources and further reading

Use the right privacy tool for the task

A browser proxy changes the network path for one session. Review the Privacy Policy and use a trusted direct connection for sensitive accounts.