Home
Blog
QR Code Scams (Quishing): Why That Code on the Table Could Be a Trap

QR Code Scams (Quishing): Why That Code on the Table Could Be a Trap

Reviewed by
Table of Contents

Key Takeaways

You're seated at a restaurant, your server hasn't stopped by yet, and there's a small square code on the table inviting you to "scan to view our menu." You point your phone camera at it without a second thought. That's exactly what cybercriminals are counting on.

Welcome to the world of quishing, QR code phishing, one of the fastest-growing threats targeting everyday people and businesses alike. It's sneaky, it's spreading, and the worst part is that most people don't even know it's happening until it's too late.

What is quishing?

Quishing is a form of phishing that uses QR (Quick Response) codes to disguise malicious links. Instead of sending you a suspicious email with a clickable URL, scammers encode a harmful web address directly into a QR code image. When you scan it, your phone quietly opens the link, often before you've had any chance to recognize the danger.

The name is a mashup: QR + phishing = quishing. And it's deceptively effective.

Here's why: traditional phishing defenses are built to scan text-based links. A QR code hides that link inside a visual pattern, a jumble of black and white squares. Most email filters, corporate firewalls, and even trained human eyes can't read a QR code the way they'd read a suspicious URL. The malicious destination is invisible until your phone reveals it.

The numbers don't lie: quishing is exploding

This isn't a niche threat. The statistics are stark:

  • A 587% increase in quishing incidents was recorded in 2023 alone, making it one of the year's fastest-rising phishing attack vectors. (Keepnet Labs)
  • 12% of all phishing emails contained a QR code in 2025, up from just 0.8% in 2021. (Keepnet Labs)
  • Over 4.2 million QR code phishing threats were identified in early 2025. (Keepnet Labs)
  • 68% of quishing attacks specifically targeted mobile users in 2025, exploiting the fact that phones are typically less protected than corporate computers. (Keepnet Labs)
  • Only 36% of QR code phishing attacks were accurately identified and reported by the people who received them, meaning nearly two-thirds slipped by undetected. (Keepnet Labs)
  • 11% of all phishing emails in the first half of 2026 contained malicious QR codes, according to the ESET Threat Report H1 2026.

The energy, manufacturing, insurance, technology, and financial services sectors are the most frequently targeted, but physical-world quishing attacks mean anyone is fair game.

How does quishing actually work?

The digital route: emails and documents

In the corporate world, quishing typically arrives in your inbox. The email looks legitimate, perhaps a DocuSign signature request, a payroll update from HR, or a Microsoft account alert. Instead of a clickable link, there's a QR code and an instruction to "scan with your phone."

Palo Alto Networks' Unit 42 researchers have documented a particularly sophisticated evolution: attackers are now using Cloudflare Turnstile (a human-verification tool) to block security crawlers from inspecting the phishing page. They also route victims through legitimate website redirect mechanisms to hide the true destination. Some attacks even conduct pre-attack reconnaissance on specific targets before deploying personalized phishing lures.

Once you scan the code on your phone, you're moved from a relatively protected corporate environment to a personal device that almost certainly has fewer security controls. That's the trap: the QR code doesn't just deliver malicious content, it changes the battleground.

The physical route: QR codes in the real world

This is where quishing gets particularly unsettling. Scammers don't just operate online, they operate in your neighborhood.

Common physical quishing locations include:

  • Restaurant tables, fake "scan for our menu" codes placed over or beside legitimate ones
  • Parking meters and kiosks, fraudulent stickers placed over the official payment QR code, redirecting your payment to a scammer's account
  • Electric vehicle charging stations, a documented attack pattern flagged by ESET and security researchers, where payment QR codes are swapped out
  • Public flyers and posters, fake notices with QR codes promising deals, event registration, or prize claims
  • Package delivery notifications, fake "track your parcel" codes on stickers left on doors or packages

The Better Business Bureau has issued specific warnings about fake QR codes being placed over real ones on parking meters, public transit areas, and packages. The Pinellas County Sheriff's Office has issued similar warnings, with deputies noting that scammers are hoping you'll scan their QR code that will take you to a site designed to steal your information.

Why is quishing so hard to detect?

Quishing is particularly dangerous for several compounding reasons.

1. The link is invisible to the human eye.

Unlike a suspicious URL (think: secure-micros0ft-login.xyz), a QR code is just a pattern of squares. You can't visually inspect it and sense danger.

2. It moves you to your phone, fast.

Security controls on corporate laptops and email systems are much stronger than on personal smartphones. Quishing deliberately exploits this gap.

3. It bypasses traditional security filters.

Email scanners look for malicious text links and attachments. A QR code is an image, and historically, many scanners couldn't decode images to extract and inspect the URL inside.

4. It exploits habit and trust.

The pandemic normalized scanning QR codes everywhere. We do it reflexively now. Scammers didn't create the habit, they just weaponized it.

5. Nearly 90% of attacks are aimed at stealing credentials.

Login details, passwords, session tokens, even multi-factor authentication (MFA) codes. Some attackers use what's called an adversary-in-the-middle technique to harvest your MFA token in real time, meaning even turning on two-factor authentication isn't always enough protection on its own.

6. State-sponsored actors are in the game.

In January 2026, the FBI issued a warning that North Korea's Kimsuky hacking group was using QR codes in spearphishing emails targeting think tanks, academic institutions, and US government entities. If nation-state actors consider this method effective, that tells you something about its reach.

What can happen if you fall for a quishing attack?

The consequences of a successful quishing attack can be severe:

  • Credential theft: Your usernames and passwords land in a scammer's hands, opening access to bank accounts, email, work systems, and more.
  • Financial loss: Between April 2024 and April 2025, 784 quishing incidents resulted in approximately £3.5 million in losses in the UK alone. (Action Fraud)
  • Malware installation: Some QR codes bypass app store security to install malicious apps directly onto your phone.
  • Account takeover: Attackers can use QR codes that link directly to legitimate apps (like payment platforms) with pre-filled scammer account details.
  • Identity theft: The personal data harvested from a phishing page can be sold, used for fraud, or used for follow-on attacks.

How to protect yourself from quishing

The good news: awareness is your strongest defense. Here's what to do.

Before you scan

  • Inspect the physical code first. Is there a sticker placed over another code? Peel it back slightly. Look for signs of tampering.
  • Ask yourself: did I expect this? Unsolicited QR codes in emails, on flyers, or on packages should immediately raise your guard.
  • Verify the source independently. If you get an email with a QR code from your bank or employer, log in through the official app to confirm before scanning.

When you scan

  • Preview the URL before opening it. Most modern phones show you the destination link before your browser opens it. Look at it critically. Does the domain match the organization it claims to be from?
  • Watch for urgency. "Scan now or lose access" and "Act immediately" are classic pressure tactics. Pause instead of rushing.
  • Use a QR scanner app that shows the full URL before redirecting you.

Broader habits

  • Keep your phone's operating system and apps updated. Security patches matter, especially on mobile.
  • Never enter your login credentials on a page you reached via QR code without verifying the URL and the site's legitimacy first.
  • Enable strong MFA, and stay alert to the fact that some quishing attacks are specifically built to harvest MFA tokens in real time.
  • Report suspicious codes. Whether in an email or a physical location, reporting helps protect others.

For an extra layer of protection, Guardio monitors and blocks malicious URLs in real time, including those reached through QR code scans on your phone or computer. When a scam page loads, Guardio detects it before you have a chance to type a single character.

The bottom line

QR codes are genuinely useful, and that's exactly why scammers love exploiting them. The trust we've built around scanning codes in restaurants, parking lots, and emails is the vulnerability being weaponized. Quishing works because it's frictionless, familiar, and almost entirely invisible until it's too late.

The next time you see a QR code on a table, at a meter, or in an email, take one extra second. Inspect it. Question it. Preview the URL. That brief pause could be the difference between a quick menu check and handing over your credentials to a cybercriminal thousands of miles away.

Think before you scan. Every time.

Conclusion

QR codes work because they're convenient, and that convenience is exactly what scammers are banking on. The trust built up around scanning a code at a restaurant, a parking meter, or in an email is the exact weakness quishing exploits, since there's nothing to visually inspect before you scan. Building in one extra second before scanning (checking for a sticker placed over another code, previewing the URL, questioning anything unsolicited) closes most of that gap. It's a small habit that can be the difference between checking a menu and handing your credentials to a scammer on the other side of the world.

Get a free security scan with Guardio today and stay protected from phishing scams and malicious links.

CMS-based CTA:
Add Guardio to BrowserTake Security Quiz
Default CTA:
Smart protection, built for how you live online
Stay ahead of threats with real-time insights and proactive protection.
Add Guardio to BrowserTake Security Quiz
CMS-based "Did you know?" block
Did you know?
Default "Did you know?" block
Did you know?

Make sure you have a personal safety plan in place. If you believe someone is stalking you online and may be putting you at risk of harm, don’t remove suspicious apps or confront the stalker without a plan. The Coalition Against Stalkerware provides a list of resources for anyone dealing with online stalking, monitoring, and harassment.

Guardio Security Team
Guardio’s Security Team researches and exposes cyber threats, keeping millions of users safe online. Their findings have been featured by Fox News, The Washington Post, Bleeping Computer, and The Hacker News, making the web safer — one threat at a time.
Tips from the expert

Related articles

FAQs

What is quishing?

Quishing is a type of phishing attack that hides a malicious URL inside a QR code. When you scan the code, your phone opens the link and takes you to a fake website built to steal your login credentials, personal information, or payment details. Unlike standard phishing, the link is invisible to the eye, which makes it far harder to spot.

How do I know if a QR code is a scam?

You can't tell from the code's appearance alone, but there are warning signs. Check whether the code is a sticker placed over another one, especially on parking meters or restaurant tables. When you scan, preview the URL your phone displays before opening it, and look for mismatched domains or odd redirects. Any QR code that arrives unexpectedly in an email or on a public surface deserves extra scrutiny.

Can a QR code install malware on my phone?

Yes, in some cases. Some malicious QR codes link to sites that attempt to download malicious apps or exploit vulnerabilities in your phone's browser. Keeping your phone's operating system updated and using a browser with real-time protection significantly reduces this risk.

Are QR code scams common?

QR code scams have surged in recent years. Keepnet Labs reports a 587% increase in quishing incidents in 2023, and ESET's Threat Report H1 2026 found that 11% of all phishing emails in the first half of 2026 contained malicious QR codes. They appear in emails, on restaurant tables, parking meters, EV charging stations, and package delivery notices.

What should I do if I accidentally scanned a malicious QR code?

Close the browser tab or app immediately without entering any information. Change the passwords for any accounts you may have accessed recently from that device. Run a security scan on your phone, and if you entered financial details, contact your bank. Report the incident to the FTC at ReportFraud.ftc.gov and alert the business or location where you found the code.

Can QR code scams steal my two-factor authentication codes?

Yes. Some advanced quishing attacks use an adversary-in-the-middle technique, sitting between you and a legitimate site so they can capture your MFA token in real time as you enter it. This means two-factor authentication, while still valuable, isn't a complete shield against sophisticated quishing attacks. Verifying the URL before entering any credentials remains essential.

Table of Contents
Can You Spot a Scam Text Message?
Test your skills and learn how to protect yourself from online scams.
Take the quiz now
Can You Spot a Scam Text Message?
Test your skills and learn how to protect yourself from online scams.
Take the quiz now