Quishing: How to Protect Yourself from QR Code Scams
QR codes have become part of everyday life as simple, immediate tools for accessing menus, making payments, downloading apps, viewing documents or quickly reaching a web page. Their widespread use, however, has also attracted the attention of cybercriminals, who can exploit them to direct people to fraudulent websites and steal credentials, personal data or financial information.
This technique is known as quishing, a term formed by combining “QR Code” and “phishing”. The mechanism is typical of social engineering: the victim is induced to voluntarily perform an apparently legitimate action, while the destination hidden behind the code is controlled by the attacker.
The phenomenon is becoming increasingly significant. According to Microsoft Threat Intelligence, in the first quarter of 2026 the volume of QR-code phishing attacks rose from 7.6 million in January to 18.7 million in March, an increase of 146%. One reason for their effectiveness is that the malicious link can be embedded in an image, making it harder for some traditional email-analysis systems to detect.
Understanding how these scams work is therefore important not only for users but also for companies. In increasingly digitalized and interconnected organizations, cybersecurity depends on the integration of protection technologies, threat monitoring and informed human behavior.
What Is Quishing?
Quishing is a form of phishing in which a QR code is used to direct the victim to a digital resource controlled by a cybercriminal. Once the code is scanned with a smartphone or another device, the user may be taken to a website designed to imitate a legitimate service, an authentication page, a corporate portal or a payment system.
The objective may be to obtain:
- usernames and passwords,
- banking details,
- credit-card numbers,
- personal information,
- codes needed to access digital services.
In other cases, the link may lead to the download of malicious software or to procedures that induce the user to install untrusted applications.
Quishing therefore belongs to the broader family of social-engineering attacks. CERT-AGID defines phishing as a form of cyber fraud aimed at acquiring confidential information or inducing the victim to carry out certain actions, mainly by exploiting human interaction.
A distinctive feature of a QR code is that the destination address is not normally readable at a glance. In a traditional email, it is often possible to see the text of a link directly or inspect the URL before opening it. With a graphical code, by contrast, the destination is decoded only through the device used for scanning.
This step can reduce the user’s level of attention. Familiarity with QR codes and the speed with which they are normally used may lead people to regard them as automatically trustworthy, especially when they appear in an apparently credible context.
The risk can also arise outside email. The National Cyber Security Centre notes that QR codes are increasingly used in phishing campaigns and recommends particular caution when a code is received through unexpected messages or communications. Physical contexts can also be exploited: a code printed on a sheet, sticker or sign can become the entry point to an online scam.
How Does a QR Code Scam Work?
A QR-code scam generally begins by creating a credible context. The attacker tries to convince the victim that scanning is necessary to perform a normal or urgent action, such as:
- verifying an account,
- viewing a document,
- making a payment,
- confirming an identity,
- accessing a service,
- resolving an alleged security issue.
The code may be included in a phishing email, an attachment, an SMS, a printed communication or physically placed over a legitimate QR code. In all these cases, the principle is the same: shift the user’s attention away from the actual link and toward the apparently harmless act of scanning.
Once the code is framed by the camera, the device interprets the encoded information and proposes opening a web page. If the user proceeds, they may be presented with a screen that closely resembles that of a familiar organization.
In Italy, CERT-AGID has documented phishing campaigns in which fake communications about alleged PagoPA fines contained a QR code to be scanned with a mobile phone instead of the traditional link in the message body. This is a concrete example of how trust associated with a familiar service can be redirected toward a fraudulent destination.
The malicious page may then ask for login credentials, payment-card details or other sensitive information. Once submitted, this information can be collected by the criminal and used to access accounts, carry out fraudulent transactions or build further attacks.
In other scenarios, the page may try to convince the user to download a file or install an application. It is therefore important to distinguish two steps: simply scanning a QR code does not necessarily mean the device has been infected; the risk increases when the proposed destination is opened and, above all, when data is entered, permissions are granted or software from unverified sources is installed.
What Is a Fake QR Code and How Can You Recognize It?
A fake QR code is a code created or modified to lead the user to a destination different from the one they expect. It may be entirely fraudulent or may physically replace a legitimate QR code.
For example, it may be a sticker placed over the original code on:
- a sign,
- a vending machine,
- a parking meter,
- a charging station,
- an information display.
At first glance, the code may look perfectly normal: for this reason, the appearance of the QR code alone is not enough to establish whether it is genuine.
To help assess the situation, it is useful to look for recurring warning signs. The following table summarizes clues that should be checked before scanning the code or opening the link.
| Warning sign | Why it may be suspicious | Recommended action |
| Sticker or overlaid code | It may hide the original QR code and redirect to a fraudulent website. | Do not scan it and, if possible, verify the code through the official channel. |
| Unexpected or urgent request | Urgency is often used to reduce the time available for verification. | Stop the operation and check the communication with the organization concerned. |
| Unusual or misspelled domain | An address similar to the official one may imitate a familiar brand. | Read the URL preview and carefully check the domain name. |
| Request for passwords or banking details | Phishing pages often aim to steal credentials and financial information. | Do not enter data; reach the service through the official website or app. |
| Download or installation requested | The link may attempt to distribute malicious software or untrusted applications. | Do not install files or apps from an unverified destination. |
A first warning sign is the physical context. If the QR code appears to have been added as a sticker, has raised edges, covers another graphical element or seems to have been applied later, it is prudent not to use it.
The digital context also provides important clues. A QR code received through an unexpected communication, accompanied by urgent requests or threats such as immediate suspension of a service, deserves additional verification. Urgency is in fact a recurring social-engineering technique.
The most important check, however, concerns the link destination. Many smartphones display a preview of the address before opening it. At this stage, it is useful to examine the domain carefully, looking for spelling mistakes, added characters, names that imitate those of familiar organizations or domains that are completely unrelated to the service you intend to use.
The presence of HTTPS alone does not guarantee that a website is authentic. The main checks should concern the domain and whether the proposed destination is consistent with the organization that is supposed to provide the service.
The same principle applies to logos, colors and graphics. A visually convincing page is not necessarily safe. Criminals can reproduce the appearance of existing services very accurately, so the site’s identity should be verified through its address and, where possible, by reaching the service through the official website or an already installed app rather than through the QR code received.
How to Protect Yourself
The first step in protecting yourself from quishing is to adopt more conscious behavior when using QR codes. Their convenience should not lead to automatic scanning: before opening a link, it is important to ask who provided the code, why you are being asked to use it and what destination it should open.
A few simple rules can significantly reduce the risk:
- read the decoded URL before proceeding: if the domain clearly does not match the expected service, contains anomalies or uses a shortened address that hides the destination, the safest choice is not to open it;
- access the service through the official channel: if the QR code is supposed to lead to the website of a bank, public body, company or other known service, it is preferable to type the official address directly into the browser or use the already installed app, removing the need to trust the link embedded in the code;
- do not enter data after unexpected requests: if, after scanning, you are asked to enter passwords, banking details, authentication codes or personal information, stop the operation and verify the communication through an independent official channel;
- enable multi-factor authentication, which adds another layer of account protection, although it is not sufficient on its own: some advanced forms of phishing also attempt to capture authentication information, so checking the destination and recognizing unusual requests remain essential;
- keep smartphones and applications up to date: updated operating systems, browsers and security tools reduce exposure to known vulnerabilities, while applications should only be installed from trusted stores and sources.
In a business context, however, protection requires a broader approach. The National Cyber Security Centre recommends a multilayered strategy against phishing, in which technological and organizational measures reduce both the likelihood that the message reaches the user and the consequences of any mistake.
Training therefore plays a central role. Employees must be able to recognize unusual communications and know how to report them quickly, without placing the entire burden of security on each individual’s ability to detect every attempted scam.
Alongside awareness activities, companies can adopt:
- threat-monitoring systems,
- advanced email protections,
- tools for detecting anomalous access,
- structured incident-management processes.
This combination becomes even more important in organizations that manage essential services and digitalized infrastructure, where protection of information assets must accompany technological evolution.
In this context, quishing is a concrete example of how digital security does not depend on technology alone. The more connected processes, services and infrastructure become, the greater the need to combine defensive tools with a widespread security culture. Being able to recognize a suspicious QR code, check its destination and stop when faced with an unexpected request are simple behaviors, but they help build preventive capacity that, together with monitoring, intelligence and technological protection, makes the entire digital ecosystem more resilient.