QR Code Scams ("Quishing"): How They Work and How to Spot One
Scammers are hiding phishing links inside QR codes on parking meters, mailers, and even emails to dodge the red flags people have learned to spot. Here's how quishing works and how to check a code before you scan it.
What "Quishing" Means and Why It Works
Quishing is QR-code phishing: a scammer embeds a malicious link inside a QR code instead of a text link, betting that you'll scan it with your phone camera without reading the URL first the way you might scrutinize a suspicious link in an email. QR codes exploded in everyday use after 2020 for restaurant menus, parking payments, and event check-ins, and that familiarity is exactly what scammers exploit — people scan first and think second. Because the destination URL is hidden inside the code itself until you scan it, quishing skips the usual visual red flags people have learned to spot in a phishing email, like a misspelled sender address or a suspicious link preview.
Where Malicious QR Codes Actually Show Up
The most common real-world version is a sticker placed directly over a legitimate QR code — on a parking meter, a restaurant table tent, an EV charging station, or a public flyer — redirecting the scan to a fake payment page that captures your card details. Scammers also mail fake letters designed to look like they're from a bank, the IRS, or a delivery company, with a QR code replacing the usual link because email spam filters and link-scanning tools generally can't inspect what's encoded inside an image. A newer variant shows up in phishing emails themselves: a QR code embedded in the email body rather than a clickable link, specifically to dodge corporate email security scanners that check text links but don't decode images.
What Happens After You Scan
| Scam Outcome | What It's After |
|---|---|
| Fake payment page | Card number, expiry, CVV |
| Fake login page | Email/bank/social account credentials |
| App install prompt | Malware or a fake app with broad device permissions |
| "Verify your identity" page | Social Security number, ID photos |
How to Check a QR Code Before You Scan
- Look for a sticker over a sticker — on parking meters and table tents, check whether the QR code appears layered on top of the original panel rather than printed as part of it.
- Preview the URL before opening it — most phone cameras show a link preview banner after scanning, before actually opening the page. Read the full domain, not just the first few characters.
- Never enter a password after scanning a public QR code — if a scan leads to a login page for your bank, email, or social account, close it and navigate to the site directly instead.
- Be suspicious of QR codes in unsolicited mail or email — legitimate businesses rarely ask you to scan a code instead of clicking a normal link.
Quishing at Parking Meters and EV Chargers Specifically
Parking and EV-charging scams have become common enough that several cities have issued public warnings after residents reported fraudulent charges following a QR scan at a meter. The fake page usually looks identical to the real parking app's payment screen, asks for a card number directly (real apps typically use a saved payment method or a known app redirect, not a fresh card-entry form), and either overcharges the card or captures it for later fraudulent use. If a meter or charger only offers payment via a QR code with no app name or attendant number listed, it's worth using the official app or a phone-based payment line instead.
What to Do If You Already Scanned a Malicious Code
If you entered a password on a page you reached through a QR code and now suspect it was fake, change that password immediately — and change it everywhere else you reused it, which is exactly the scenario a password manager is built to prevent by keeping every account's password unique. If you entered payment card details, contact your card issuer to flag the transaction and consider requesting a new card number. If the scan triggered an app install, uninstall it and run a security scan on the device. Our phishing guide covers the same account-recovery steps in more depth, since quishing is ultimately phishing delivered through a different format.
Building QR Awareness Into Everyday Habits
The best defense isn't avoiding QR codes entirely — they're genuinely convenient and not going away — it's treating a scan the same way you'd treat a link in a text message from an unknown number: pause, check the destination, and don't enter sensitive information unless you're confident where you landed. Turning on two-factor authentication across your important accounts means that even if a quishing page does capture a password, the attacker still can't get in without the second factor. Our 2FA guide walks through setup across the major apps, and a password manager that autofills only on the real, saved URL for a site — never on a lookalike page — adds a second layer of protection, since it simply won't offer to fill credentials on a fraudulent domain.
Frequently Asked Questions
Are QR codes themselves dangerous, or just what they link to? The code itself is harmless — it's just a shortcut to a URL. The risk is entirely in where that URL leads, which is invisible until you scan.
Can my phone warn me about a malicious QR code automatically? Most modern phone cameras show a link preview before opening the page, and some antivirus apps flag known malicious domains, but neither is foolproof against a brand-new fake site.
Is it safe to scan restaurant menu QR codes? Generally yes for well-established restaurants, but always check the preview URL matches the restaurant's actual domain, and never enter payment details on a menu-scan page — legitimate menus don't need your card number.
Recommended Tools
Quishing succeeds when a fake page captures a password or payment detail you'd normally protect more carefully. A password manager like NordPass only autofills on the real, saved domain for a site, so it won't offer credentials on a lookalike page reached through a malicious QR code. NordProtect adds identity monitoring in case a scan does result in exposed personal data. See our full recommended tools guide for the complete lineup.
Recommended next step
Compare password manager options
If you are choosing between Bitwarden, NordPass, 1Password, or browser autofill, start with the comparison cluster instead of a generic tools page.
Compare password manager options →Keep Improving Your Account Security
- Browse the password managers hub for the complete set of related guides.
- AI Voice Cloning Scams: How to Protect Yourself and Your Family
- Email Security Best Practices 2026: Protect Your Inbox from Hackers and Phishing
- How to Spot Fake Websites: A Practical Guide to Avoiding Phishing and Scam Sites
- What Is Phishing and How to Avoid It: A Practical Guide