Best Practices5 min readJuly 19, 2026

QR Code Scams ("Quishing"): How They Work and How to Spot One

Scammers are hiding phishing links inside QR codes on parking meters, mailers, and even emails to dodge the red flags people have learned to spot. Here's how quishing works and how to check a code before you scan it.

What "Quishing" Means and Why It Works

Quishing is QR-code phishing: a scammer embeds a malicious link inside a QR code instead of a text link, betting that you'll scan it with your phone camera without reading the URL first the way you might scrutinize a suspicious link in an email. QR codes exploded in everyday use after 2020 for restaurant menus, parking payments, and event check-ins, and that familiarity is exactly what scammers exploit — people scan first and think second. Because the destination URL is hidden inside the code itself until you scan it, quishing skips the usual visual red flags people have learned to spot in a phishing email, like a misspelled sender address or a suspicious link preview.

Where Malicious QR Codes Actually Show Up

The most common real-world version is a sticker placed directly over a legitimate QR code — on a parking meter, a restaurant table tent, an EV charging station, or a public flyer — redirecting the scan to a fake payment page that captures your card details. Scammers also mail fake letters designed to look like they're from a bank, the IRS, or a delivery company, with a QR code replacing the usual link because email spam filters and link-scanning tools generally can't inspect what's encoded inside an image. A newer variant shows up in phishing emails themselves: a QR code embedded in the email body rather than a clickable link, specifically to dodge corporate email security scanners that check text links but don't decode images.

What Happens After You Scan

Scam OutcomeWhat It's After
Fake payment pageCard number, expiry, CVV
Fake login pageEmail/bank/social account credentials
App install promptMalware or a fake app with broad device permissions
"Verify your identity" pageSocial Security number, ID photos

How to Check a QR Code Before You Scan

  • Look for a sticker over a sticker — on parking meters and table tents, check whether the QR code appears layered on top of the original panel rather than printed as part of it.
  • Preview the URL before opening it — most phone cameras show a link preview banner after scanning, before actually opening the page. Read the full domain, not just the first few characters.
  • Never enter a password after scanning a public QR code — if a scan leads to a login page for your bank, email, or social account, close it and navigate to the site directly instead.
  • Be suspicious of QR codes in unsolicited mail or email — legitimate businesses rarely ask you to scan a code instead of clicking a normal link.

Quishing at Parking Meters and EV Chargers Specifically

Parking and EV-charging scams have become common enough that several cities have issued public warnings after residents reported fraudulent charges following a QR scan at a meter. The fake page usually looks identical to the real parking app's payment screen, asks for a card number directly (real apps typically use a saved payment method or a known app redirect, not a fresh card-entry form), and either overcharges the card or captures it for later fraudulent use. If a meter or charger only offers payment via a QR code with no app name or attendant number listed, it's worth using the official app or a phone-based payment line instead.

What to Do If You Already Scanned a Malicious Code

If you entered a password on a page you reached through a QR code and now suspect it was fake, change that password immediately — and change it everywhere else you reused it, which is exactly the scenario a password manager is built to prevent by keeping every account's password unique. If you entered payment card details, contact your card issuer to flag the transaction and consider requesting a new card number. If the scan triggered an app install, uninstall it and run a security scan on the device. Our phishing guide covers the same account-recovery steps in more depth, since quishing is ultimately phishing delivered through a different format.

Building QR Awareness Into Everyday Habits

The best defense isn't avoiding QR codes entirely — they're genuinely convenient and not going away — it's treating a scan the same way you'd treat a link in a text message from an unknown number: pause, check the destination, and don't enter sensitive information unless you're confident where you landed. Turning on two-factor authentication across your important accounts means that even if a quishing page does capture a password, the attacker still can't get in without the second factor. Our 2FA guide walks through setup across the major apps, and a password manager that autofills only on the real, saved URL for a site — never on a lookalike page — adds a second layer of protection, since it simply won't offer to fill credentials on a fraudulent domain.

Frequently Asked Questions

Are QR codes themselves dangerous, or just what they link to? The code itself is harmless — it's just a shortcut to a URL. The risk is entirely in where that URL leads, which is invisible until you scan.

Can my phone warn me about a malicious QR code automatically? Most modern phone cameras show a link preview before opening the page, and some antivirus apps flag known malicious domains, but neither is foolproof against a brand-new fake site.

Is it safe to scan restaurant menu QR codes? Generally yes for well-established restaurants, but always check the preview URL matches the restaurant's actual domain, and never enter payment details on a menu-scan page — legitimate menus don't need your card number.

Recommended Tools

Quishing succeeds when a fake page captures a password or payment detail you'd normally protect more carefully. A password manager like NordPass only autofills on the real, saved domain for a site, so it won't offer credentials on a lookalike page reached through a malicious QR code. NordProtect adds identity monitoring in case a scan does result in exposed personal data. See our full recommended tools guide for the complete lineup.

Recommended next step

Compare password manager options

If you are choosing between Bitwarden, NordPass, 1Password, or browser autofill, start with the comparison cluster instead of a generic tools page.

Compare password manager options

Keep Improving Your Account Security

#quishing#qr code scam#phishing#parking scam#nordpass#nordprotect

🔒 Generate a Strong Password Now

Use our free tool to create cryptographically secure passwords for all your accounts.

Try the Password Generator →
Best value

Simple, fast, and secure. Made by the team behind NordVPN.

Try NordPass
Most secure

Open-source password manager trusted by millions. Free forever.

Get Bitwarden Free