⚠ FBI WARNING First issued January 2022

Quishing:
QR Code Phishing
Explained

How attackers exploit QR codes to steal credentials and money — and how consumers and businesses can protect themselves.

+587% increase in attacks (2023) Updated 2026

Trusted by Leading Organizations

Join thousands of businesses using QRTRAC for their QR code needs

Definition

What is Quishing?

Quishing (QR + phishing) is a cyberattack that uses QR codes to direct victims to malicious websites. Unlike traditional phishing — where a suspicious link is visible in an email — QR codes hide the destination URL, making the attack harder to spot before scanning.

Attackers use quishing because: QR codes bypass most email security filters (they appear as images, not links), most users can't see the URL before scanning, and mainstream QR adoption means victims are habituated to scanning without scrutiny.

FBI Warning (January 2022)

The FBI's IC3 warned that "cybercriminals are tampering with both digital and physical QR codes to replace legitimate codes with malicious codes" — specifically targeting parking meters, cryptocurrency ATMs, and restaurant payment kiosks. Victims were directed to phishing sites designed to steal financial credentials.

How a Quishing Attack Works

1

The attacker creates a malicious QR code

They encode a URL pointing to a phishing site — often a near-perfect replica of a bank, government portal, parking payment system, or restaurant ordering page.

2

The code replaces or supplements a legitimate one

Common methods: a printed sticker placed over a legitimate QR code (restaurant menus, parking meters), a malicious code emailed as a document that bypasses email filters, or fake QR codes in phishing emails posing as package delivery or invoice notifications.

3

Victim scans the code

The phone camera shows the URL briefly — but most users tap without reading. Mobile browsers also show shorter URL previews than desktop, making domain spoofing easier to miss (e.g., "paypa1.com" instead of "paypal.com").

4

Victim enters credentials or payment details

The phishing site looks legitimate. Victims enter login credentials, payment card numbers, or personal data. Some sophisticated attacks also attempt to install malware via browser exploits.

5

Data is harvested — victim usually doesn't notice immediately

Unlike a scam phone call, the victim receives a normal-looking "error" or redirect. The theft happens silently. Detection often occurs only when the financial fraud or account takeover appears later.

Common Quishing Scenarios

🅿️

Parking Meter Fraud

Fake QR stickers over legitimate parking payment codes. Victims pay "parking fees" to attacker-controlled crypto wallets or fake payment pages.

📧

Email QR Phishing

Emails posing as HR, IT, or package delivery include QR codes instead of links — bypassing corporate email filters that scan URLs but not image content.

🍽️

Restaurant Menu Swap

Attacker places QR code sticker over a restaurant's legitimate menu QR. Victim scans and reaches a fake "order here" page collecting payment details.

🏦

Crypto ATM Scams

Fraudsters place QR codes near legitimate cryptocurrency ATMs directing victims to wallets the attacker controls.

📦

Fake Package Notifications

SMS or email claims a package needs action. QR code leads to a credential-harvesting page mimicking FedEx, UPS, or USPS.

🏥

Healthcare Check-in Fraud

Fake QR codes in waiting rooms posing as patient check-in portals — capturing insurance information, Social Security numbers, and personal data.

How to Protect Yourself & Your Customers

For Consumers: Staying Safe

  • Read the URL preview before tapping — look for misspellings or unfamiliar domains
  • Check for stickers over QR codes at physical locations (a common tampering sign)
  • Be suspicious of QR codes in unexpected emails — especially from "HR", "IT", or delivery services
  • Only scan QR codes at trusted locations; when in doubt, type the URL manually
  • Keep your phone OS and browser updated to protect against drive-by exploits
  • Use HTTPS-only — refuse to enter information on any HTTP destination after a scan
  • Enable your browser's safe-browsing warnings for phishing and malware

For Businesses: Protecting Your Customers

  • Use a QR management platform with a consistent custom domain — customers can recognize your domain after scanning
  • Monitor scan analytics for anomalies — sudden geographic spikes or unusual device patterns can indicate code tampering
  • Use branded QR codes — your logo and colors make tampered sticker replacements obvious to observant customers
  • Educate customers: "Our QR codes always go to [yourdomain.com]"
  • Regularly audit QR code placements in physical locations for signs of tampering
  • Use dynamic QR codes — if a code is compromised, deactivate it instantly from your dashboard
  • Consider laminated or etched QR codes for permanent fixtures to prevent sticker placement

QRTRAC's Security Approach

Custom Domain Routing

All your QR codes route through your verified domain. Customers learn to recognize your URL — making spoofed codes immediately suspicious.

Instant Deactivation

If a code is compromised, disable it in one click. The physical code becomes inert without any reprinting.

Anomaly Detection via Analytics

Unusual scan patterns (location, volume, timing) surface immediately in your QRTRAC dashboard — a first signal of potential tampering.

GDPR & CCPA Compliant

Scan data is handled in compliance with global privacy regulations — no personal data is collected without consent.

Quishing & QR Code Security: FAQs

Answers to the most important questions about QR code phishing and how to stay protected.

Q What is quishing?

Quishing (QR code phishing) is a cyberattack where criminals embed malicious URLs in QR codes to direct victims to phishing sites designed to steal credentials, financial information, or install malware. The term blends 'QR' and 'phishing'. It's grown significantly since 2022 as QR code scanning became mainstream and attackers exploited the fact that most people can't preview a QR URL before scanning.

Q Why is quishing harder to detect than email phishing?

Traditional email phishing links are visible as text — trained users can hover to see the URL before clicking. QR codes are opaque: you can't see the encoded URL without scanning. Most phone cameras show the URL briefly after scanning but before the user taps to open — this is the only preview window. Additionally, QR codes bypass many email security filters because they appear as images, not links.

Q How do I know if a QR code is safe to scan?

Before scanning: check the physical code hasn't been covered by a sticker (a common attack vector in restaurants and parking meters). After scanning: read the URL preview carefully before tapping — look for misspellings, unfamiliar domains, or HTTP (not HTTPS). Use a QR scanner app with URL preview (not just your camera app) if you're scanning unknown codes. In public: be suspicious of QR codes in unexpected locations.

Q Has the FBI warned about QR code scams?

Yes. The FBI's Internet Crime Complaint Center (IC3) issued a public service announcement in January 2022 warning consumers about cybercriminals tampering with QR codes at physical locations. The alert specifically warned about tampered parking meters, cryptocurrency kiosks, and restaurant payment QR codes being replaced with malicious alternatives.

Q How can businesses protect customers from quishing using their QR codes?

Use a QR management platform (like QRTRAC) so all your codes redirect through your verified domain — if a scammer replaces your QR code with a malicious one, the new code will redirect to a different domain, making it obvious something is wrong. Monitor scan analytics: a sudden spike or location anomaly in scan data can indicate a hijacked code. Use custom-branded QR codes so customers recognize legitimate codes from your business.

Q Can QR codes contain viruses or malware directly?

No. A QR code itself cannot contain executable code or malware. QR codes encode data (typically a URL) — the danger is the URL they point to, which can lead to phishing sites or sites that attempt to exploit browser vulnerabilities. Keep your device's OS and browser updated to protect against drive-by download attempts that can occur after scanning a malicious URL.

Plans and Pricing

QRTRAC Pricing Plans - Custom Domain QR Code Solutions
Choose from our flexible pricing plans starting at $5/mo. Featuring custom domain QR codes, real-time analytics, and transparent branding options. Start with a 7-day free trial.

Agency & Enterprise Plans

Scale your organization with white-label solutions, SSO, and custom data residency.

View Advanced Plans
Largest Scale

Agency Plan

$250 / month

Everything you need to manage multiple brands or clients with full white-label control.

White label application with full branding control
Custom QR codes, scans, and domains
Custom user seats and teams
Advanced security & API access
Dedicated support with priority response
Everything in Legendary plan included
Custom Solutions

Enterprise Plus

$5,000+ / year

Global data residency, SSO, and white-glove onboarding for large organizations.

Everything in Agency included
SSO support for secure enterprise access
DPA and custom data residency options
Bulk creation and custom integrations
White-glove onboarding & dedicated support
Compliance ready: GDPR, CCPA, SOC 2

Plans and Feature Comparison

Everything you need to know about our 6 specialized plans.

Compare Plans
Kickoff

Individuals with limited needs

Startup

Freelancers & creators going fully branded

Business Plus Most Popular

Growing businesses wanting more power

Legendary

Businesses with high-volume usage

Agency

Agencies managing multiple clients

Enterprise Plus

Large organizations with custom needs

Plan Volumes
Dynamic QR Codes
?
Upto 5
Upto 25
Upto 250
Upto 500
Custom
Custom
Static QR Codes
?
Upto 25
Upto 125
Upto 1,250
Upto 2,500
Custom
Custom
QR Code Scans
?
Unlimited
Unlimited
Unlimited
Unlimited
Unlimited
Unlimited
Short Link Clicks
?
Unlimited
Unlimited
Unlimited
Unlimited
Unlimited
Unlimited
Custom Domains
?
Add-on
Add-on
1 Included
1 Included
Custom
Custom
Mini-sites
?
Add-on
Add-on
Add-on
Add-on
Add-on
Add-on
User Seats
?
1
1
3
Up to 10
Custom
Custom
Teams / Workspaces
?
1
1
2
3
Custom
Custom
Add-ons
Additional Domains
?
Custom
Additional Seats
?
Custom
Mini-sites Hosting
?
Custom
Additional Teams
?
Custom
Additional QR Codes
?
Custom
QR Migration Service
?
$3 one-time/QR · Min 100 QR codes
$3 one-time/QR · Min 100 QR codes
Included free
Included free
Core Features
Bulk Generation
?
Up to 50
Up to 500
Custom
Custom
Smart Scheduling
?
High-Res Download Plans
?
AI QR Designer
?
Multi-direction Scanning
?
Ultra-fast Scanning
?
Ultra-fast Redirects
?
Domain Management
Remove QRTRAC Branding
?
SSL certificate
?
Supported
Supported
1 included
1 included
Custom
Custom
Branded links
?
Supported
Supported
Custom URL slugs / Back-halves
?
Data & Analytics
Real-time link analytics
?
Detailed performance metrics
?
Geo-location Data (City/Country/Zip)
?
Scans by GPS location
?
Device & OS tracking
?
Device language tracking
?
Campaign URL Builder (UTM)
?
Google Analytics 4 Integration
?
Private/public reports
?
Aggregated reports
?
Date range selector
?
Configure report time zone
?
Data Downloading (CSV, XLS)
?
Tag management
?
Custom
Custom
Export link traffic details
?
Custom
Custom
Your logo in reports
?
Custom
Custom
Collaboration & Teams
Multi-level access management
?
Shared team account dashboard
?
Ownership transfer
?
Mobile Landing Pages
Link List Page (Linktree style)
?
Lead Forms
?
Video QR Pages
?
Form Attribution
?
A/B Testing
?
Age Restrictions
?
Multi-Language Support
?
Security & Compliance
GDPR & CCPA Compliant
?
SSO (Single Sign-On)
?
Data Residency Options
?
Dedicated Support
?
Standard
Standard
Priority
Priority
Priority
Dedicated

Run QR codes your customers can trust

Managed QR codes with security built in

Custom domain, instant deactivation, anomaly analytics. Free 7-day trial.