QR Code Scams (Quishing): The Newest Phishing Variant

QR codes were once a curiosity; the pandemic made them a habit. Restaurants put menus on them. Parking meters use them. Bills include them. Even ads on the back of bathroom doors invite a scan. That habit is the entire opening for “quishing” (QR phishing) — the fastest-growing phishing variant the FBI has flagged in the last two years.

The danger isn’t the QR code itself. It’s that scanning one is identical to tapping a link, except you can’t hover over a QR code to preview the destination, and your phone is much more trusting of links opened from the camera than from email.

How a QR Scam Works

  1. A scammer prints a sticker with their malicious QR code and pastes it over a legitimate one — on a parking meter, an EV charger, a restaurant table, a public flyer.
  2. Or they email a QR code “to access a document” (working around email filters that block link text).
  3. You scan with your phone camera.
  4. The link opens a convincing lookalike page (your bank, a payment portal, a city parking site).
  5. You enter credentials, card number, or pay a “fee.” They drain the account, charge the card, or install browser-based malware.
Safe QR scanning in 4 steps: hover, preview URL, verify domain, open or close

Where Quishing Shows Up Most

Parking Meters and EV Chargers

Cities and charger networks use QR codes for payment. Scammers print stickers with their codes and slap them over the originals. You scan, enter card info, get a real-looking parking confirmation, and never actually pay the city — you get a ticket plus a fraudulent card charge. Reported in Austin, San Antonio, Atlanta, multiple California cities, and many more.

Restaurant Menus and Tabletop Codes

Less common but documented: stickers placed over the restaurant’s code that redirect to fake payment portals or surveys harvesting personal info.

Email Attachments and PDFs

A “secure document” email contains a QR code instead of a link — the QR routes around the email security filter that would have flagged a malicious URL. Common impersonation: Microsoft 365 password reset, DocuSign signature requests, Adobe Acrobat shared files.

Public Flyers and Billboards

“Scan to claim your prize / get the menu / vote / apply.” In high-traffic areas, scammers stick QR codes on top of real ones, or post their own flyers that look semi-official.

Crypto Wallet Stickers

At bitcoin ATMs and in crypto-related communications, scammers replace the recipient wallet QR with their own. Anyone who scans and sends sends to the scammer instead.

How to Scan Safely

  • Look at the URL preview before opening. Modern iPhone and Android cameras show the URL at the bottom of the screen before you tap. Don’t tap unless the domain matches the legitimate organization exactly.
  • Be very wary of physical-world QR codes that ask for payment — parking meters, EV chargers. Use the official app or pay at a kiosk instead. Check that the QR code isn’t a sticker placed over another one.
  • Type known URLs by hand. If a QR claims to take you to your bank’s login, close it and type the address yourself.
  • Never enter passwords from a QR-launched page unless you scanned it from your own bank’s physical statement or letter.
  • Don’t scan QR codes in unexpected emails. If a coworker sends you a QR for a document, confirm by another channel first.
  • Watch for tampering. Stickers over codes. Codes that look freshly printed in an old setting. Two codes near each other.

If You’ve Already Scanned and Entered Info

  1. Close the browser tab immediately.
  2. If you entered card info: call the issuer and freeze the card.
  3. If you entered a password: change it everywhere you use it.
  4. Run a security check on your phone: iOS — Settings > Safari > Clear History and Website Data. Android — check installed apps for anything you don’t recognize and remove.
  5. Report: the FTC (reportfraud.ftc.gov), and if it was a physical sticker, the city or property owner so they can remove it.

Further Reading

Educational only. Scam tactics evolve constantly. If you believe you’ve been targeted or have lost money, report to: the Federal Trade Commission at reportfraud.ftc.gov, the FBI’s Internet Crime Complaint Center at ic3.gov, your state attorney general, and your local police. For lost funds, contact your bank, credit-card issuer, or payment-app support immediately — speed of reporting often determines whether funds can be recovered. This article is not a substitute for legal or financial advice.