Quishing (QR-code phishing)

Quishing is phishing that hides a malicious link inside a QR code. Since a QR code keeps its destination out of sight until you scan it, attackers plant fake codes on posters, parking meters, emails, or stickers pasted over real ones, routing you to a counterfeit login or payment page. The ease of scanning gets past the habit of checking a link before you click.

Check a suspicious message now

The check runs in your browser. What you paste stays on your device. It is not sent to our servers or anyone else, and nothing is stored.

The image is read on your device. It is never sent or stored.

Please don't paste other people's personal data.

Or try a real one:

Get it free

Or check it on Telegram

Example

A sticker on a parking meter shows a QR code to 'pay here.' Scanning it opens a page that mimics the city's payment portal but simply harvests your card details, while your parking is never actually paid.

How to recognize it

  • A QR code in an unexpected email or on a sticker that could cover the original
  • A scanned code that leads to a login or payment page you didn't expect
  • The destination domain not matching the business the code claims to serve
  • Pressure to scan and pay quickly to avoid a fine or fee

How Hunch flags it

After a scan resolves to a web address, Hunch applies the same signal categories as any link, lookalike or mismatched domain, a credential or payment ask, and urgency, to the page the QR code opens.

FAQ

What is quishing?

QR-code phishing, hiding a phishing link inside a QR code so that scanning it sends you to a fraudulent website.

How can I scan QR codes more safely?

Preview the link your camera shows before opening it, and be wary of codes on stickers, unsolicited emails, or anywhere a real one could be covered over.

Are QR codes on official mail always safe?

Not necessarily. Scammers mail convincing fake notices too, so treat any QR code that leads to a login or payment page with the same caution as an unknown link.

Related