QR Code Scams Are Everywhere: How 'Quishing' Works in 2026
Fake QR codes on parking meters, menus and emails can hijack payments and steal logins. The mechanics of QR phishing — and how to verify any code in seconds.
Toolverse Editorial
Practical writing on privacy, browsers & getting things done

The scan-by-default habit
QR codes trained us perfectly: point, scan, tap. Restaurants replaced menus with them, parking meters replaced keypads, event tickets live in them. That convenience created an attack surface with a name security researchers now use routinely — quishing, QR phishing — because a QR code is just a link, and humans have been trained to open links without reading them.
The classic attacks are refreshingly low-tech. A sticker with a fraudulent payment code is slapped over the real one on a parking meter. A 'restaurant menu' poster on a wall actually opens a crypto-wallet drain page. An emailed HR document contains a QR code precisely because mail scanners are much worse at reading images than text links.
Why the code itself tells you nothing
A QR code carries no identity, no signature and no brand. Any pixel pattern that decodes to a URL looks exactly as legitimate as any other. Attack sites are trivially good at imitating payment pages, and the small phone screen hides the one detail that would give them away — the full domain in the address bar.
That is the entire game: get the scan, hide the URL, rush the tap. Defense is therefore not about spotting visual fakes — it is about inspecting what the code actually decodes to before opening it.
Verify before you tap — in seconds
The safe habit takes less time than unlocking your phone again: decode the QR with a scanner that shows you the raw destination first, instead of auto-opening it. Read the domain the way an email security expert would — the part just before the first single slash, exactly, character by character. 'paytm-secure.com' and 'paytm.com' are different organizations; only one of them is the real one.
For codes you generate yourself — payments, Wi-Fi, contact cards — the same rule applies in reverse: generate locally, verify by decoding your own output, and only then print or share. A typo in a payment QR is a payment to the wrong account.
The rules worth memorizing
Never scan codes that promise urgency ('account suspended, scan now'). Prefer typing a known domain over scanning a code you found in the physical world when money is involved. Treat email QR codes with the same suspicion as email links. And on any payment screen, confirm the payee name after the page opens — the last line of defense takes one second.
QR codes are genuinely great technology. Like all great technology, they deserve one second of inspection at the moment that matters.
Frequently Asked Questions
Can a QR code contain a virus?
The code itself is just data — usually a URL. The danger is the website it opens, which may attempt phishing or exploit a vulnerable device. Keeping your phone updated removes most technical risk; reading the destination handles the rest.
How do I check where a QR code leads without opening it?
Use a scanner that displays the decoded URL as text before opening anything. The raw destination tells you everything — legitimate services rarely mind being inspected.
Are QR payments safe?
When the code comes from the payee directly and you verify the payee name after opening, yes. Sticker-swap fraud on physical codes is the main real-world attack.
Tools Used in This Guide
Toolverse Editorial
We write practical, no-fluff guides on privacy, browser technology and getting things done faster — everything we publish is free to read, and every tool we build runs entirely in your browser.
More from the blogarrow_forward

