Quishing Is the New Phishing: QR Code Scams Are Rising Worldwide

Once upon a pre-pandemic time, QR codes were the clunkiest of tech conveniences – awkward, rarely used, and mostly reserved for warehouse logistics. Fast-forward to now and they’re everywhere: restaurant menus, parking meters, concert posters, even email inboxes. Which is exactly why cybercriminals have fallen in love with them.

Welcome to the era of quishing – QR code phishing – a rapidly growing cyber threat that blends old-school scams with modern frictionless design. And according to cybersecurity experts and government agencies, it’s only accelerating.

At the start of January, the Federal Bureau of Investigation (FBI) issued a warning about cybercriminals using fake QR codes to trick users into handing over personal and financial information. While the alert focused on the US, experts stress this is very much a global problem – including here in the UK.

What exactly is quishing?

Quishing works much like traditional phishing, but instead of clicking a suspicious link, you scan a code. That scan can redirect you to a fake website designed to look legitimate – a parking payment page, a restaurant checkout, a Google login – where criminals harvest your details.

The most unsettling part? These codes often appear in places we instinctively trust. Parking machines. Café tables. Public signage. Criminals simply stick a fake QR code over a real one and wait.

A smartphone scanning a QR code on a café table next to a latte, illustrating how everyday QR code use can expose users to quishing scams and online fraud.

Once a pandemic convenience, now a cybersecurity risk. QR codes are everywhere – café tables included – and cybercriminals know it. As quishing scams rise, that innocent scan could lead somewhere far less chic.
Credit: Ahmed / Unsplash

Several UK government bodies have already raised alarms. Fake QR stickers have been found on parking meters, sending drivers to cloned payment pages.

“Bogus QR code stickers have been found in council car parks, sending users to a fraudulent cloned website that requests credit card details and other personal data. Users are advised not to scan any QR codes or barcodes they see on parking machines or signage,” explained the official Walsall Council website in January 2025.

Across the Atlantic, the US Federal Trade Commission has issued similar warnings about unexpected packages containing QR codes that lead to phishing sites.

When QR codes go geopolitical

This isn’t just low-level fraud. The FBI has also linked quishing to state-sponsored cybercrime. In a series of targeted attacks, a North Korean group known as Kimsuky embedded malicious QR codes in emails sent to think tanks and advisory firms.

“Quishing (QR Code Phishing) is a phishing technique in which adversaries embed malicious URLs inside QR codes to force victims to pivot from their corporate endpoint to a mobile device, bypassing traditional email security controls,” the FBI explained.

In one case, recipients were invited to a non-existent conference; the QR code led to a fake Google login page designed to steal credentials. It’s a chilling reminder that QR scams aren’t just opportunistic – they’re strategic.

Why QR scams work so well

According to cybersecurity experts at Planet VPN, the psychology behind quishing is simple: QR codes lower our guard.

“Quishing is phishing–just in a different wrapper,” says Konstantin Levinzon, co-founder of Planet VPN. “A QR code can lower people’s guard because this technology became ubiquitous only during the pandemic, and the threat still isn’t as widely recognized. It also shifts the ‘risky click’ from a visible link to a quick scan, making the danger easier to miss.”

There’s also a technical advantage for attackers. QR codes are images, meaning they often bypass traditional email security filters that analyse text and links. Even when detection tools improve, criminals adapt – changing colours, formats, and designs to stay one step ahead.

Cybersecurity researchers at Proofpoint estimate that in just the first half of last year there were 4.2 million QR-code-related threats. Levinzon believes the real figure is likely far higher, as many scams go undetected.

How to protect yourself (without becoming paranoid)

The goal isn’t to swear off QR codes entirely – they’re too embedded in modern life for that. Instead, experts advise slowing down and being intentional.

If a QR code redirects you to a site asking for payment or login details, pause. If it arrives via email from an unknown sender, don’t scan first and think later. Verify the sender directly.

“We recommend applying the same logic everywhere: stay skeptical whether you receive a message from a coworker or on your personal social media account,” Levinzon says. “However, vigilance is only part of the story.”

Basic digital hygiene still matters: keep your devices updated, use strong passwords, enable multi-factor authentication, and be cautious on public Wi-Fi. Tools like VPNs can also add a layer of protection, particularly when you’re on the move.

The bigger picture

QR codes promised convenience – and they delivered. But as with most frictionless tech, ease has come at a cost. Quishing is a reminder that design trends don’t exist in a vacuum; they reshape behaviour, trust, and risk.

So the next time you’re hovering your phone camera over a neat little square, remember: convenience is powerful, but skepticism is chic.

Some of the products and services featured in this article may be from our affiliate partners, which means we may earn a small commission if you make a purchase through these links — at no extra cost to you. Our editorial team only spotlights what we genuinely love and think you will, too.

Leave a Comment