# QR Code Phishing: How to Check a “Quishing” Message

> QR codes hide their destination until scanned. Learn how quishing messages steal logins and how to inspect a request without trusting it.

- Canonical article: [https://www.metacyber.guru/articles/qr-code-phishing-quishing](https://www.metacyber.guru/articles/qr-code-phishing-quishing)
- Category: Scam Defence
- Author: Muhammad Azhar
- Published: August 14, 2026
- Last reviewed: 2026-08-14

A QR code is a compact link, not proof that the destination is trustworthy. In a quishing attack, the code moves a victim from an email, poster, invoice or parking notice to a fake login or payment page. The image can also evade filters that normally inspect clickable links.

## Pause before moving to the phone

An unexpected code that claims an account will close, a parcel is delayed or a payment failed is a reason to verify independently. Do not scan it merely to “see where it goes” on a device that holds banking apps and signed-in accounts.

## Safer verification

1. Open the organization's official app or type its known address.
2. For a physical code, check whether a sticker covers the original sign.
3. Preview the decoded URL and read the full domain before opening.
4. Do not install an app, profile or certificate from the resulting page.
5. Report suspicious workplace codes to the security team.

## If you entered information

Change the affected password through the official service, end active sessions and review MFA methods. Contact the payment provider immediately if money or card details were submitted. Preserve the message or photograph as evidence.

A familiar logo beside a QR code is easy to reproduce. Trust should come from an independently reached service and a domain you have checked, not from the printed square itself.

## A workplace example

An invoice arrives with a QR code labelled “view secure document.” The accounts employee should locate the supplier in the approved vendor system and call the stored number, not the number printed on the invoice. If the supplier confirms no request, the image and message can be reported without ever opening the destination.

## What a safe code should provide

Organizations using QR codes should display the human-readable domain and offer a normal typed or clickable alternative. A code that is the only route to an urgent payment deserves extra scrutiny.

## Use the destination, not the artwork, as evidence

A branded QR code can be printed, copied or covered with a sticker in seconds. Before opening it, use the camera preview to read the complete host name. For a restaurant, parking meter or payment counter, compare the code with the organization's official app or printed web address and ask staff if anything looks altered.

## Payment codes require an extra check

Confirm the merchant name and amount inside the payment app before authorizing. A code that opens an ordinary web form asking for full card details is not equivalent to a verified in-app payment request. On a work device, avoid scanning a code from an unsolicited document because it moves the attack outside the company's email controls.

Security teams should preserve the image and decode it in an isolated analysis process. Publishing a sensitive reset or document-sharing URL to a public scanner may expose the very resource being investigated.

## Sources and further reading

- [Google Safety Blog: 2026 fraud and scams advisory](https://blog.google/innovation-and-ai/technology/safety-security/fraud-scams-advisory-june-2026/)
- [FTC: How to recognize and avoid phishing scams](https://consumer.ftc.gov/articles/how-recognize-and-avoid-phishing-scams)

---

This Markdown edition is provided for language-model retrieval. The canonical human-readable page is the HTML article linked above.
