How quishing works
In a quishing attack, a QR code replaces the suspicious link found in ordinary phishing. The code may arrive in an email, text message, letter or flyer, or be stuck over a real code in a public place. Because people cannot read a QR code by eye, they often do not see the destination until the page has opened.
The fake page usually imitates something familiar, such as a bank, a delivery company, a parking payment site or a workplace login. It then asks for a password, card number or other details, or pushes a payment.
What authorities have warned about
In January 2022, the FBI’s Internet Crime Complaint Center warned that criminals were tampering with QR codes to redirect victims to malicious sites and steal funds. In December 2023, the US Federal Trade Commission warned consumers that scammers hide harmful links in QR codes, including codes on parking meters and in unexpected emails and texts. Fake stickers on parking pay stations have been reported in several cities.
- Emails with a QR code asking you to verify an account or fix a delivery
- Stickers placed over real codes on parking meters and signs
- Texts or letters claiming an unpaid bill or fine
- Codes urging immediate action to avoid a penalty
How to protect yourself
The best defense is to read the link preview before opening a scanned code, and to treat unexpected codes with the same suspicion as unexpected links. Do not pay or log in through a code that arrived in an unsolicited email or text. When in doubt, go to the organization’s website or app directly rather than through the code.