Quishing is a phishing attack that uses a QR code, rather than a typed link, to send victims to a malicious website, fake login page, or fraudulent payment form. The name blends "QR" and "phishing," and it describes the newest major variant in a family of social engineering attacks that already includes email phishing, SMS smishing, and voice vishing.

QR codes went from novelty to infrastructure in just a few years. Restaurant menus, parking payments, event tickets, package labels, and login flows all moved behind those black-and-white squares. Attackers followed, because a QR code has one property that makes it ideal for fraud: a human cannot read it. You cannot glance at a QR code and notice a misspelled domain the way you can with a written link. You find out where it goes only after you are already there.

This glossary article defines quishing precisely, walks through how real QR code scams work (including the parking meter sticker scam), summarizes what the FTC and FBI advise, and gives practical scanning habits for individuals and organizations.

Quishing Definition

Quishing (QR code phishing): a social engineering attack in which a fraudster distributes a QR code, physically or digitally, that resolves to a malicious destination designed to steal credentials, payment details, or personal information, or to trigger a malware download.

The attack has three parts:

  1. A trusted context. The QR code appears somewhere scanning feels natural and safe: a parking meter, a menu, an email that looks like a security notice, a flyer, a shipping label.
  2. An unreadable pointer. The code encodes a URL the victim cannot inspect visually. Attackers often add a redirect chain or a lookalike domain so even the post-scan preview looks plausible.
  3. A malicious destination. Usually a fake payment or login page. Sometimes a prompt to download an app or file.

Quishing is most usefully understood as a delivery mechanism rather than a wholly new scam. The destination pages are the same ones used in email and text phishing. If you want the full taxonomy of these attacks and how they differ, our comparison of smishing vs. phishing vs. vishing lays out the whole family side by side.

Real-World Example: The Parking Meter QR Sticker Scam

The clearest illustration of quishing is the parking meter sticker scam, which police departments in multiple U.S. cities have warned drivers about.

It works like this. Fraudsters print adhesive stickers bearing their own QR code and stick them onto parking meters, pay stations, or nearby signage, sometimes directly over a legitimate code. A driver parks, sees the code, scans it, and lands on a professional-looking "pay for parking" page that harvests their card number. The driver believes they paid for parking. In reality they handed their card to a criminal and may get a parking ticket on top of it.

The scam thrives because every element of the context screams legitimacy: you are standing at real city infrastructure performing a routine payment. Cities that have issued warnings generally advise drivers to pay through the city's official parking app or the meter's own payment hardware, and to be suspicious of any QR sticker that looks added on, misaligned, or layered over another label.

The same physical technique shows up on restaurant tables, EV chargers, utility bills posted in shared spaces, and event posters. Anywhere a code can be stickered over, it eventually is.

Where Quishing Attacks Show Up

ChannelTypical lureWhat the attacker wants
Physical stickersParking meters, EV chargers, posters, table tentsCard numbers via fake payment pages
Email"Your account will be locked, scan to verify" security alertsLogin credentials; QR codes also slip past filters that scan text links
Text messagesPackage delivery or account alerts with a QR image or link to oneCredentials and payment data
Mail and packagesUnexpected parcels or letters with a QR code to "verify" or "register"Personal information and card data
Fake documentsBogus invoices, permits, or tickets bearing a codePayment to fraudulent accounts

The email variant deserves special note. Attackers embed QR codes in messages precisely because email security tools historically inspected written URLs more thoroughly than images. The code also forces a device switch: you read the email on a laptop but scan with your phone, which may sit outside your organization's protections. The FBI's Internet Crime Complaint Center (IC3) and the FTC have both published consumer guidance on QR code scams, and the FTC's advice centers on one behavior: inspect the URL after scanning and before tapping, and never enter sensitive information on a page you reached through an unexpected code.

How to Protect Yourself from QR Code Scams

  • Preview before you tap. Modern phone cameras display the destination URL when they detect a code. Read it. If the domain is a jumble, a shortener, or a near-miss of the brand you expect, stop.
  • Prefer the official app or typed address. For parking, banking, and account logins, skip the code and go directly to the app or website you already know. A QR code should be a convenience, never the only path you trust.
  • Physically inspect codes in public. A sticker sitting on top of printed signage, misaligned with the design around it, is the classic tampering sign.
  • Distrust urgency. "Scan within 24 hours to avoid account suspension" is the same pressure script used in every phishing channel. Real organizations do not conduct emergency business through QR codes.
  • Never download apps from a scanned link. Get apps only from official app stores.
  • Keep your phone updated. Current operating systems include protections against known malicious sites; updates keep those protections current.
  • Report what you find. Report QR scams to the FTC at ReportFraud.ftc.gov and, if you lost money or data, file a complaint at ic3.gov. Physical sticker scams are also worth reporting to the city or business being impersonated. Scam texts containing QR codes can be forwarded to 7726 (SPAM).

If you scanned a bad code and entered information, act on what you shared: dispute card charges with your bank, change the compromised password everywhere you reuse it, and visit IdentityTheft.gov if you provided identity data.

What Quishing Means for Organizations That Message the Public

Nonprofits, healthcare providers, schools, and government agencies increasingly pair QR codes with their outreach: donation pages, patient portals, event check-ins, benefit applications. Quishing does not mean abandoning the tool. It means deploying it in ways recipients can authenticate:

  • Put codes only in expected, controlled contexts. A QR code inside a consented text or a printed statement you mailed is verifiable. A code on an unattended public surface invites sticker-over attacks, so audit those placements regularly.
  • Use your own domain, visibly. Print the destination URL next to the code so people can compare or type it manually, and never route through generic shorteners that hide the destination.
  • Send from recognizable, registered channels. A code arriving in a text from your organization's registered, consistent number inherits that channel's trust. One arriving from a random number inherits nothing. This is the same trust logic covered in our smishing explainer: the sender's authenticity is half the battle.
  • Give people a way to verify. When a supporter or patient can reply to your text and ask "did you send this," and an AI Powered Helper answers immediately with the official link, you have converted suspicion into confidence instead of losing the interaction.

Organizations that build their outreach on consented, two-way SMS with registered senders make quishing dramatically harder to execute against their audience, because their community knows exactly what legitimate messages look like and where they come from.

Frequently Asked Questions

What does quishing mean?

Quishing is QR code phishing: a scam that uses a QR code to route victims to a malicious website or payment page instead of delivering the link as visible text. The term combines "QR" and "phishing," and the FTC and FBI have both issued public guidance about it.

Can scanning a QR code by itself hack my phone?

For an up-to-date phone, simply scanning and viewing the destination URL is generally low risk. The danger comes from what happens next: tapping through to a malicious site, entering credentials or card details, or downloading a file or app the page offers. Preview the URL, and stop there if anything looks off.

How can I tell if a QR code is fake?

You usually cannot tell from the code itself, which is the core problem. Judge the context instead: Is the code a sticker layered over other signage? Did it arrive in an unexpected email or text? Does the previewed URL match the organization's real domain? When in doubt, skip the code and navigate to the organization directly.

What should I do if I scanned a scam QR code?

If you only scanned, close the page and do nothing else. If you entered payment details, contact your bank or card issuer to dispute charges. If you entered a password, change it immediately on that account and any account sharing it. Report the scam to ReportFraud.ftc.gov and ic3.gov, and report identity exposure at IdentityTheft.gov.

What is the difference between quishing and smishing?

Both are phishing variants; the difference is the delivery vehicle. Smishing delivers a malicious link through a text message, while quishing delivers it through a QR code, which can appear in texts, emails, mail, or on physical surfaces. The destination scams are largely identical.

Build Outreach Your Community Can Verify with FRANSiS

FRANSiS helps nonprofits, healthcare organizations, schools, and agencies send consented, two-way SMS from registered numbers, with an AI Powered Helper that lets recipients verify any message or link instantly. To make your outreach the kind scammers cannot convincingly imitate, contact the FRANSiS team.