What is quishing
We show the full address first, with the domain highlighted. Nothing opens automatically.
How the attack works
The mechanics are almost always the same. The attacker places a code where paying or logging in feels perfectly normal — a parking meter, an EV charger, a restaurant table, a delivery notice. You scan. The page that opens imitates a service you recognise, closely enough that you do not stop to look at the address. You enter card details or a password, and they go straight to the attacker.
What makes it effective is not technical sophistication but borrowed authority. A sticker on a machine looks like part of the machine. Nothing on the code itself reveals who made it.
Where you meet it
- Parking meters and chargers — the most common physical case. A sticker over the operator's own payment code.
- Fake delivery notices — a card in your letterbox saying a parcel awaits a small customs fee.
- Emails with a code in an image — used precisely because a code slips past filters that would catch a suspicious link.
- Restaurant tables — a code stuck over the menu code, leading to a fake ordering page.
- Posters for prizes or discounts — an offer good enough to stop you checking.
The signs, physical and digital
On the object: a sticker over another sticker, a lifted edge, print quality that does not match the rest of the design, a code placed awkwardly relative to the layout. On a parking meter, a code that looks added rather than part of the machine's own graphics is reason enough to pay another way.
In the address: read the domain — the part immediately before the first single slash. Attackers rely on lookalikes: an extra word, a hyphen, a different ending, a character that resembles a letter. Treat link shorteners with suspicion (they hide the destination), along with http without the s, numeric IP addresses instead of a domain name, and credentials appearing before the domain.
Three habits that protect you
- Never pay from a scanned code. For parking, fines or deliveries, open the official app or type the address yourself. It costs twenty seconds.
- Read the address before acting. Use a scanner that shows it to you instead of opening it. Ours highlights the domain and warns about the patterns above.
- When in doubt, look from a distance. Our optional safety check opens the page in an isolated environment and returns a screenshot, the redirect chain and a verdict — so your device never touches the site.
Check a code before you trust it
- The full address, with the domain highlighted, before anything opens
- Warnings for shorteners, http, numeric IPs and lookalike domains
- Optional isolated check with a screenshot and the full redirect chain
- Decoding is 100% local — the image never leaves your browser
Frequently asked questions
- What exactly is quishing?
- Quishing is phishing delivered through a QR code. Instead of a link in an email, the attacker gives you a code — printed on a sticker, in a letter or in an attachment. Scanning it takes you to a page that imitates a bank, a courier or a parking operator and asks for card details or login credentials.
- Why do QR codes work so well for fraud?
- Because a QR code is opaque. You cannot read it, so you cannot judge the destination before you act — the entire habit of “check the link before clicking” stops working. On top of that, a code printed on a sticker carries the authority of the place it is stuck on: a parking meter, a restaurant table, a delivery locker.
- Where do quishing attacks show up most often?
- On parking meters and EV chargers (a sticker over the legitimate payment code), on restaurant tables, on fake parcel-delivery notices, in emails pretending to come from a bank or an employer, and on posters for competitions or discounts. The common thread: a moment when paying or logging in feels normal.
- How can I tell if a QR code has been tampered with?
- Look at it physically first. A sticker over another sticker, a slightly raised edge, a code that does not match the surrounding print quality, or one placed oddly relative to the rest of the design are all warning signs. On parking meters especially, if the code looks added rather than printed with the machine's own graphics, do not use it.
- What should I do before opening a scanned link?
- Read the full address, with attention to the domain — that is, the part right before the first single slash. Attackers use lookalikes such as an extra word, a hyphen or a different ending. Be suspicious of link shorteners, of http without the s, of numeric IP addresses, and of domains using unusual characters. Our scanner highlights the domain and warns about all of these.
- I scanned a suspicious code. What now?
- If you only scanned it and did not open anything, nothing happened — decoding is harmless. If you opened the page and entered card details or a password, contact your bank immediately, change the password everywhere you reused it, and enable two-factor authentication. Then report the sticker to the owner of the place it was stuck on.
- Does an antivirus protect me against quishing?
- Only partially. Quishing does not usually rely on a virus, but on convincing you to type your own data into a fake form. The real protection is the habit of reading the address before acting — and, when in doubt, checking the page from a safe distance rather than on your own phone.