Quishing: QR Code Phishing
Definition: Quishing is a phishing attack that delivers a malicious link inside a QR code, so the victim scans a square instead of clicking a suspicious URL.
The technique works because a QR code hides the destination and shifts the click to a personal phone, which is usually outside corporate email filtering and endpoint protection. Common patterns include fake parking and EV-charger stickers placed over legitimate codes, fake invoice or MFA-reset emails containing an image-only code, and counterfeit payment codes in restaurants. Defence is split: businesses should protect their physical codes with tamper-evident stickers, branded short domains, and staff checks, while scanners should preview the URL before opening, refuse to enter credentials or card details after a scan, and distrust any code stuck over another.
Key points
- Codes hide the destination, which is exactly what attackers exploit
- Image-only codes routinely bypass email link scanning
- Stickers placed over legitimate codes are the most common physical attack
- A branded short domain makes tampering easier to notice
- Never enter credentials or payment details on a page reached by scanning a public code
Frequently asked questions
How can I tell if a QR code is malicious?
Preview the URL before opening, check for a sticker layered over the original, and look for a domain that matches the business you expect.
Can a QR code install malware directly?
No. The code only carries data; harm requires you to open the link and then act on the page it loads.
How do businesses protect their codes?
Print codes into the artwork rather than applying stickers, use a branded domain, and inspect public-facing codes regularly.
Related terms
liveqr.codes is a free QR code generator. Static codes are free and unlimited with no signup; a one-time $1.99 lifetime upgrade adds unlimited dynamic codes with editable destinations and scan analytics. Download every code as a high-resolution PNG or vector SVG.