Fake QR Codes and Quishing: How QR Code Phishing Works
A fake QR code hides a malicious link behind a familiar square image, sending the person who scans it to a phishing page, fraudulent payment screen, or malware download.
A fake QR code hides a malicious link behind a familiar square image, sending the person who scans it to a phishing page, fraudulent payment screen, or malware download. This form of QR code phishing is often called quishing. It works because the destination is harder to inspect than a normal link and the scan usually moves the attack from a protected work computer to a phone.
For a small business, one successful scan can expose Microsoft 365 credentials, payment details, customer data, or an employee device. The practical defense is not to ban QR codes. It is to teach people how to verify them, reduce the value of stolen passwords, and give staff a fast way to report a suspicious scan.
What is quishing?
Quishing combines “QR code” and “phishing.” The attacker places a malicious destination inside a QR code, then uses urgency or trust to persuade someone to scan it. The Federal Trade Commission warns that these codes can lead to convincing fake sites or malware and may appear in unexpected emails, texts, packages, or physical locations.
The QR image is only the delivery mechanism. The actual attack usually aims to steal a password, capture card information, redirect a payment, install software, or persuade the victim to call a fraudulent support number.
How does a fake QR code attack work?
Most attacks follow the same sequence:
- The attacker creates a QR code that points to a domain they control.
- They place it in a message, invoice, package insert, sign, parking meter, or document that looks legitimate.
- The message creates urgency: verify an account, review a secure document, pay a fee, reset a password, or fix a delivery problem.
- The employee scans with a phone and sees a page designed to resemble Microsoft, a bank, a delivery company, or another trusted service.
- The attacker captures the information entered or convinces the person to install an app, approve a login, or send money.
Where do businesses encounter malicious QR codes?
Email and text messages
A QR image can avoid the obvious clickable link employees have been trained to distrust. Common lures include shared documents, payroll notices, voicemail alerts, password-expiration warnings, and delivery failures.
Printed signs and stickers
Attackers can place a sticker over a legitimate payment or information code. Parking, event, restaurant, visitor check-in, and equipment-service codes deserve a quick physical inspection before use.
Unexpected packages and invoices
The FTC has also documented unexpected-package scams involving QR codes. In a business setting, the same tactic can appear on a fake invoice, shipping notice, vendor update, or benefits document.
How can you spot a fake QR code?
- Treat urgency, secrecy, payment demands, and unexpected login requests as warning signs.
- Preview the destination on the phone before opening it. Look for misspellings, extra words, shortened links, and domains that do not match the claimed sender.
- Inspect physical codes for stickers, altered labels, or placement that does not match the surrounding sign.
- Open the known website or app yourself instead of using a code in an unexpected message.
- Verify unusual vendor, payroll, or payment requests through a trusted phone number or a separate conversation.
What should you do after scanning a suspicious QR code?
Scanning alone does not always mean the account or phone is compromised. The response depends on what happened next. Close the page, do not download anything, and report the incident immediately. If credentials were entered, change the password from a known-clean device, revoke active sessions, review sign-in activity, and confirm that MFA methods and forwarding rules were not changed. If payment or identity information was entered, contact the relevant provider through a verified channel and follow its fraud process.
How should a small business prevent quishing?
Start with recurring security awareness training that includes QR examples, then give employees one obvious reporting channel. Layer email security with mobile-device management, DNS or web filtering, and strong multi-factor authentication. For privileged and high-risk accounts, use phishing-resistant authentication where the platform supports it.
Frequently asked questions
- What is quishing?
- Quishing is phishing delivered through a QR code. The code sends the person who scans it to a fake login page, fraudulent payment screen, malicious download, or other attacker-controlled destination.
- Can scanning a QR code infect a phone?
- A scan usually opens a web address, so scanning alone does not guarantee infection. Risk increases if the person downloads an app or file, grants permissions, enters credentials, or follows instructions on the malicious page.
- How can employees check a QR code safely?
- Preview the destination before opening it, inspect the domain carefully, and avoid codes in unexpected messages. For account, payment, or delivery requests, open the known app or website directly instead.
- What should we do if an employee entered a password after scanning?
- Change the password from a known-clean device, revoke active sessions, review recent sign-ins, check MFA methods and mailbox rules, and report the event to IT immediately so the account can be contained.
- Does email security stop QR code phishing?
- It can detect and block many suspicious messages, but no filter catches every image or social-engineering lure. Email security works best with awareness training, mobile controls, web filtering, MFA, and a fast reporting process.
Want a straight answer for your business?
Book a first appointment with a bdManagedIT strategist. No sales script, no obligation.
Book your first appointment