Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

QR Code Scams (Quishing) Explained: The Hidden Risk in a Square of Dots

In short

Quishing is phishing that uses a QR code instead of a link. Because a QR code hides its true destination and is scanned on a personal phone, it slips past email filters and out of your control. Learn where fake codes appear, the warning signs, and one simple habit: always check the web address before you tap.

QR codes are everywhere now — on menus, posters, parking meters, packaging and business cards. They are genuinely useful, which is precisely why criminals have started abusing them. The scam even has a name: quishing, short for “QR code phishing.”

The idea is simple. A QR code is just a web address stored as a pattern of dots. When you scan it, your phone opens that address — but you cannot read where it leads before you go there. That hidden destination is the whole point. A phishing email shows you a link you could inspect; a QR code shows you a square of noise and asks you to trust it.

Why criminals love QR codes

Quishing has become popular for reasons that should worry any business owner:

  • It hides the destination. You cannot hover over a QR code to check the link the way you might on a computer. The address is invisible until you have already scanned it.
  • It slips past email filters. Many security tools scan the words and links in an email. A QR code is an image, so there is nothing for the filter to read. A malicious code sails straight into the inbox.
  • It jumps onto a personal phone. People scan codes with their own mobiles, which sit outside your business’s security. The moment the attack moves to a personal device, your company protections no longer apply.
  • It borrows trust from the physical world. A code printed on an official-looking poster or a letter feels legitimate in a way a random email does not.

A QR code shows you a square of noise and asks you to trust it — the hidden destination is the whole point.

Where fake QR codes turn up

Quishing appears in both the digital and physical world. The cases affecting UK businesses most often include:

  • Car park payment machines. Fraudsters stick their own QR code over the real one. Drivers scan it, land on a convincing fake payment page, and hand over their card details. The genuine parking is never paid, so a fine follows too.
  • Fake invoices and statements. A code in a PDF invoice promises a quick way to “view” or “pay” a bill, sending the victim to a fake portal. This dovetails neatly with business email compromise, where criminals impersonate a real supplier.
  • Emails pretending to be Microsoft or your IT team. “Your password expires today — scan this code to keep your account.” The code leads to a fake Microsoft 365 login that harvests your username and password.
  • Posters, flyers and stickers in public places, offering free Wi-Fi, a prize, or a discount — with a sticker anyone could have placed.
  • Delivery and parcel notes left at reception, echoing the fake-delivery texts used in smishing.

The warning signs

Quishing relies on you scanning first and thinking later. Slow down when you notice:

  • An unexpected code in an email, especially one about passwords, payments or account security.
  • A code that leads straight to a login or payment page. A genuine link rarely demands your credentials the instant you arrive.
  • A web address that does not match the organisation — a lookalike domain, a random string, or a shortened link that hides the real destination.
  • A sticker over a sticker on a machine or poster — a classic sign of tampering in the physical world.
  • Pressure and urgency — the same trick as every scam: act now, or lose access.

How to stay safe

You do not need to ban QR codes. You need one steady habit and a few sensible rules.

Read the address before you tap. Almost every modern phone camera shows a preview of the web address when it detects a QR code. Pause and read it. Does the domain genuinely belong to the organisation you expect? If it looks off, close it.

Go direct instead. If a code claims to be from your bank, a supplier, a car park or Microsoft, do not scan it — open the official app or type the known website address yourself. This single habit defeats the vast majority of quishing.

Never enter passwords or card details from a scanned code. If a page reached by QR code asks you to log in or pay, treat that as a red flag and stop.

Check physical codes for tampering. On payment machines and posters, look for stickers placed over the original. When in doubt, pay at the machine, by app, or by card instead.

Keep MFA switched on. If a quishing page does capture a password, multi-factor authentication gives you a second lock — as long as nobody hands over the one-time code as well.

Tell your team. Most staff have never heard the word “quishing” and assume QR codes are automatically safe. A two-minute explanation at a team meeting is often all it takes to change that.

Building it into how you work

Quishing is a good example of why cyber-security is never just software. The malicious code arrives as an image, gets scanned on a personal phone, and asks for details on a page that looks perfectly ordinary — every step designed to sidestep the tools you already own. Defending against it is mostly about awareness and a couple of steady habits, backed by sensible technical controls like MFA and a filtered, well-configured email setup.

That blend of practical staff guidance and quiet technical protection is what we set up for businesses across Leeds and Yorkshire. If you would like your team to recognise scams like this before they cause harm, take a look at our cyber-security services or simply get in touch for a straightforward, jargon-free chat.

Frequently asked questions

What is quishing?

Quishing is 'QR code phishing' — a scam that uses a QR code in place of a clickable link. When you scan it, you are sent to a fake website designed to steal your login details or card information, or to a page that tries to install something on your phone. The trick works because a QR code hides where it actually leads.

Are QR codes safe to scan at all?

QR codes themselves are not dangerous — they are just a way of storing a web address. The risk is where they send you. A code from a trusted, tamper-proof source (like a printed menu you were handed) is generally fine. Treat any unexpected code, or one on a sticker that could have been placed by anyone, with caution.

How can I check a QR code before trusting it?

Most phone cameras show a preview of the web address before opening it — pause and read it. Check the domain looks right and genuinely belongs to the organisation you expect, not a lookalike or a random shortened link. If the address looks odd, or the page immediately asks you to log in or pay, close it and go to the official website directly instead.

Why do quishing attacks get past our email security?

Many email filters scan for dangerous links in the text of a message. A QR code is an image, so there is no link for the filter to read. Worse, the victim usually scans it with a personal mobile phone, which sits outside your business's security controls entirely. That combination is exactly why criminals like it.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.