Skip to content
All guides

Phishing Protection

QR Code Scams: How Quishing Works and How to Avoid It

QR code scams, often called quishing, hide a phishing destination behind a code you cannot read at a glance. Treat unexpected codes like suspicious links. Verify the real website before entering logins, card numbers, or personal information.

By the 4safer teamUpdated August 29, 20266 minutes read

What quishing means

Quishing is phishing delivered through a QR code. The code may appear on a fake parking notice, restaurant flyer, package insert, email attachment, or sticker placed over a real code.

The risk is not the code itself. The risk is the page it opens and what that page asks you to enter.

  • Fake payment page
  • Credential capture
  • Package QR code
  • Sticker over real code

When to avoid scanning

Avoid unexpected QR codes that create urgency, ask for payment, promise a refund, or claim you must verify an account. Be especially cautious when the code appears on a package you did not order.

  • Unexpected package
  • Urgent payment
  • Account verification
  • Refund promise

What to inspect after scanning

Before entering anything, read the full domain in the browser. If it does not match the official service, close the page. Do not install apps or profiles from a QR code prompt.

Use official apps and typed addresses

For parking, tolls, banking, shipping, or government services, use the official app or type the address yourself instead of trusting a random code.

  • Use official app.
  • Type the address.
  • Avoid shortened links.

Do not enter sensitive data

Never enter a current password, one-time code, full card number, bank detail, SSN, or identity document into a page opened from an unexpected QR code.

  • Protect passwords.
  • Protect payment details.
  • Protect identity documents.

If you entered information

Change affected passwords on the real site, contact your card issuer if payment details were entered, and report suspicious charges or messages.

  • Change credentials.
  • Contact card issuer.
  • Monitor accounts.

Use 4safer for follow-up context

If the QR code came after spam or suspicious messages, checking your own email may help explain targeting. A negative result does not guarantee safety.

Frequently asked questions

Is every QR code dangerous?

No. The concern is unexpected codes that send you to pages asking for sensitive information.

Can a QR code install malware?

A code can lead to a page that tries to push downloads or unsafe profiles. Do not install anything from an unexpected scan.

Should I scan package QR codes?

Avoid QR codes included with unsolicited packages or suspicious notices.

Sources

This guide is reviewed against official guidance. External pages may be updated by their respective owners.