QR Code Phishing (Quishing)

QR code phishing, also called quishing, is a scam where a fake code is stuck over a real one so your phone opens a fake payment page.

Also known as quishing QR scam fake QR code

Definition

A QR code is only a picture of a web address, so your phone reads it and opens whatever page it points at. You cannot see where it goes until you are already there, and that gap is the whole attack. QR code phishing, often called quishing, simply means putting a bad code where people expect a good one.

The sticker is the trick, so someone prints a code on cheap vinyl and lays it over the real one. It can go on a parking meter, a restaurant table, a charging point or a printed invoice, and the page that opens looks like the payment screen you expected. The driver pays for an hour of parking and hands over a full card number at the same time. Nothing about the meter has changed, which is why nobody notices for weeks.

A phone hides the one thing that would save you, because the address bar is short, the page fills the screen and a long address is cut in the middle. A name like pay-parking-city.co is easy to accept when it is the only part you can read. Many people would have paused over it on a laptop, but on a phone there is nothing to pause over.

Two checks take five seconds, and the first is running your thumb over the sign before you scan. A sticker laid on top of another sticker has an edge your nail will catch, so you feel the fake before you open it. The second is to read the address your phone shows and look only at the last two words before the first slash, because that part says who owns the page. Everything in front of it can be typed by anyone.

Businesses make it worse without meaning to, because a code pointing at a random payment link teaches their own customers to scan and pay without thinking. Print the plain web address under the code instead, on your own domain, and never put a code on paper that asks for money. That is why payment pages stay on the main domain whenever Linkysoft builds a site in a website design project.

If someone has already scanned a code and typed card details, treat it as a stolen card rather than a mistake. Call the bank and cancel it, then read the statement for a small test charge of one or two pounds. Printed codes now come up far more often than passwords when people ask Linkysoft's cybersecurity team for help.

Questions about QR Code Phishing (Quishing)

Is it safe to scan a QR code on a restaurant table?
Usually, but check the sticker first. If it peels at the corner or sits on top of another one, do not scan it. Ask the staff for the printed address instead.
How can I see where a QR code leads before I open it?
Most phone cameras show the address in a small bar before you tap. Read it, and if it is cut short or full of odd words, close it. Nothing is lost by typing the address yourself.
Should my business print QR codes on invoices?
Not for payment. Print the plain web address on your own domain instead, and let the customer type it or log in as usual. A code on a bill is the easiest thing to replace.
I scanned a fake code and typed my card details. What now?
Call your bank at once and cancel the card. Then look through the statement for a small charge you do not recognise, because thieves test a stolen card with a tiny amount first.

Still not sure how this applies to your project?

Tell us what you are building and we will answer in plain language.