📷 QR Code Phishing (Quishing): Why Scanning That Code Could Cost You
QR Code Phishing (Quishing): Why Scanning That Code Could Cost You
QR code phishing — known as quishing — grew 320% in 2026 according to the QRLJacking Threat Report, making it one of the fastest-growing attack vectors in cybersecurity. Attackers place malicious QR codes in physical locations such as parking meters, restaurant tables, and public notice boards, as well as in digital channels including email attachments, PDF documents, and social media posts. When scanned, these codes redirect victims to credential harvesting pages that look indistinguishable from legitimate services.
The real danger of quishing lies in how it bypasses our existing security instincts. Most people would hesitate before clicking an unfamiliar link in an email, but the same person will happily scan a QR code on a parking meter or restaurant table without a second thought. Attackers are exploiting this blind spot at massive scale.
How QR Code Phishing Works Technically
A QR code is simply a two-dimensional barcode that encodes data — typically a URL. The vulnerability is not in the QR code technology itself, but in the human trust placed in it. There are three primary methods attackers use to deliver malicious QR codes:
Sticker overlay attacks: The attacker prints their own QR code on a sticker and places it directly over a legitimate QR code. The victim assumes they are scanning the authentic code. This is common on parking meters, EV charging stations, and public vending machines where codes are exposed outdoors and easily tampered with.
Digital distribution: Attackers embed malicious QR codes in PDF attachments, email signatures, or social media posts. Because the QR code appears within a seemingly legitimate document, victims scan without considering that the code could lead anywhere. This method has been used to target corporate finance teams with fake invoice PDFs.
Physical replacement: The attacker removes or covers the legitimate QR code display and places their own nearby. Restaurant table tent cards, event registration boards, and hotel check-in kiosks are all vulnerable to this approach.
The Most Common Quishing Attacks in 2026
Fake Parking Payment Codes
Parking meter quishing is the fastest-growing subtype, driven by the proliferation of QR-code-based parking payment systems in major cities worldwide. Attackers place their own QR code sticker on top of the legitimate meter's QR code. Motorists scan the code and are taken to a convincing payment page that captures credit card details, registration information, and in some cases, the vehicle's location — enabling follow-up theft or cloning attacks on the same vehicle.
Major cities including London, New York, Sydney, and Toronto have all reported parking quishing incidents in 2026. In a particularly brazen case in Chicago, attackers placed stickers on over 200 parking meters across the downtown area in a single weekend, capturing payment data from an estimated 1,500 motorists before the scam was detected. The fake payment page was so well designed that it even showed the correct parking rate for each meter zone.
Fake Restaurant Menu Codes
Diners have grown accustomed to scanning QR codes to view digital menus — a habit that became universal during the pandemic. Attackers replace legitimate restaurant QR code tent cards with their own version. When a diner scans to view the menu, they are redirected to a page that requests their phone number, email, and payment details to "confirm the reservation" or "secure a table."
The attack exploits social context brilliantly. Dining out creates a relaxed, trusting environment where security awareness is lowest. You are in a public place, surrounded by people, and the restaurant has already earned your trust. Asking for a phone number or email to view a menu does not seem unreasonable — but that data is immediately harvested and sold or used in follow-up attacks. Some variants also install tracking profiles on the phone for targeted advertising or credential theft.
Fake Package Delivery Codes
Sent via email or text: "Your parcel is ready for delivery. Scan the QR code below to confirm your delivery window." This combines the proven delivery notification hook from smishing with the technical novelty of QR codes. The victim, expecting a package, scans the code on their phone where the smaller screen makes URL inspection significantly harder.
The landing page typically requests personal information to "verify your identity for delivery" — name, address, phone number, and sometimes a date of birth or partial payment card number. This information is then used for identity theft or sold on dark web marketplaces. Amazon-themed quishing campaigns saw a 450% increase in Q1 2026 alone, according to security researchers at Abnormal Security.
Fake EV Charging Station Codes
As electric vehicle adoption accelerates, attackers have begun targeting EV charging stations. The attacker places a malicious QR code sticker over the legitimate charging payment code. Drivers, often in a hurry and unfamiliar with the specific charging station interface, scan the code and enter payment details into a fake charging app or website. This emerging variant is expected to grow significantly through 2027 as EV infrastructure expands.
How to Scan QR Codes Safely
Protecting yourself from quishing requires building new security habits around QR code scanning. Here is what security experts recommend:
- Use built-in camera apps — iOS and Android camera apps show the full URL as a preview before navigating. Third-party QR scanners may navigate directly without warning you. On iOS 18 and Android 15, the URL preview appears automatically when a QR code is detected.
- Always preview the URL before tapping — look for typosquatted domains (arnazon.com instead of amazon.com, paypa1.com instead of paypal.com). If the URL looks unfamiliar, misspelled, or uses a URL shortener, do not proceed.
- Never download apps from QR codes — always use the official App Store or Google Play Store to download applications. QR codes that prompt you to install an app are almost certainly malicious, especially if they bypass the app store.
- Check for physical tampering — if a QR code looks like a sticker placed over another code, is misaligned, or has bubbles or wrinkles that suggest it was applied recently, do not scan it. Report it to the venue or facility management.
- Use a security-enhanced QR scanner — apps like Kaspersky QR Scanner and Avast QR Scan check URLs against known threat databases before opening them, providing an additional layer of protection.
- Use official apps directly — for parking payments, use the official parking app rather than scanning the meter code. For restaurant menus, ask the staff for a physical menu or type the restaurant's known website URL directly.
What to Do If You Have Scanned a Malicious QR Code
If you suspect you have scanned a quishing code, take the following steps immediately:
- Do not enter any information — close the browser page immediately if you have not submitted anything.
- Change your passwords — if you entered credentials on the fake page, change the password for that account immediately from a different, trusted device.
- Contact your bank — if you entered payment card details, call your bank's fraud department and request a card replacement and transaction monitoring.
- Enable multi-factor authentication — if you have not already, enable MFA on all accounts that support it. This provides a critical safety net if credentials are compromised.
- Report the QR code — notify the venue or facility where the code was found so they can remove it, and report the phishing URL to Google Safe Browsing or similar services.
Quishing is not going away. As QR codes become embedded in more aspects of daily life — payments, transit, healthcare check-in, event access — the attack surface only expands. Building a healthy scepticism around every QR code you encounter is the most important habit you can develop.