Quishing (QR-code phishing)
Quishing is phishing that hides a malicious link inside a QR code. Since a QR code keeps its destination out of sight until you scan it, attackers plant fake codes on posters, parking meters, emails, or stickers pasted over real ones, routing you to a counterfeit login or payment page. The ease of scanning gets past the habit of checking a link before you click.
How we check this: Written and reviewed by the Hunch team; recognition signs reflect how the FTC/FBI describe this scam. · Last reviewed: 2026-08
Check a suspicious message now
Example
A sticker on a parking meter shows a QR code to 'pay here.' Scanning it opens a page that mimics the city's payment portal but simply harvests your card details, while your parking is never actually paid.
How to recognize it
- A QR code in an unexpected email or on a sticker that could cover the original
- A scanned code that leads to a login or payment page you didn't expect
- The destination domain not matching the business the code claims to serve
- Pressure to scan and pay quickly to avoid a fine or fee
How Hunch flags it
After a scan resolves to a web address, Hunch applies the same signal categories as any link, lookalike or mismatched domain, a credential or payment ask, and urgency, to the page the QR code opens.
FAQ
What is quishing?
QR-code phishing, hiding a phishing link inside a QR code so that scanning it sends you to a fraudulent website.
How can I scan QR codes more safely?
Preview the link your camera shows before opening it, and be wary of codes on stickers, unsolicited emails, or anywhere a real one could be covered over.
Are QR codes on official mail always safe?
Not necessarily. Scammers mail convincing fake notices too, so treat any QR code that leads to a login or payment page with the same caution as an unknown link.