Skip to content
VixQR

By the VixQR team · published on · 9 min read

Are QR Codes Safe? What Quishing Is and How to Spot a Fake Code

The FBI warned about quishing in January 2026. How QR phishing works, the six scams that keep succeeding, and how to check a code before you scan.

A QR code sticker being peeled back to reveal a second, fraudulent code underneath

A QR code is a link you can't read. That's the entire security problem in one sentence.

When someone sends you a suspicious URL, you can hover over it and see where it goes. A QR code strips that away: a black-and-white square gives you nothing to inspect. You point your camera, and by the time you know the destination, you're already there.

Attackers noticed. The technique has a name now — quishing — and in January 2026 the FBI issued a formal alert about it.

What the FBI actually warned about

The Bureau's alert described North Korean state-sponsored group Kimsuky embedding malicious QR codes in spearphishing emails aimed at think tanks, universities, and government-adjacent organisations. The technique is tracked in the MITRE ATT&CK framework as T1660.

The mechanics are worth understanding, because they explain why this works when ordinary phishing increasingly doesn't:

  1. The code arrives as an image, attached to or embedded in an email. Corporate email security scans URLs — it doesn't decode pixels. The malicious link sails straight through URL rewriting, inspection, and sandboxing.
  2. Scanning forces a device switch. The victim moves from a managed corporate laptop to a personal phone. That phone sits outside endpoint detection, outside network inspection, outside every control the security team built.
  3. The destination fingerprints the device — operating system, IP, screen size, locale — and serves a mobile-optimised fake login page impersonating Microsoft 365, Okta, or a VPN portal.
  4. The payoff is session token theft. Steal the token rather than the password and you replay the session directly, bypassing multi-factor authentication without ever triggering a failed-MFA alert.

That last point is why the FBI classifies quishing as an "MFA-resilient identity intrusion vector." The usual advice — turn on MFA — does not close this hole by itself.

The six scams that keep working on ordinary people

Nation-state campaigns make headlines, but the everyday versions are simpler and far more common.

Sticker-over-sticker on parking meters. A fraudulent QR code printed on adhesive paper, applied over the city's legitimate one. You scan, land on a convincing payment page, and hand over card details. This is the single most reported physical QR scam, and it costs the attacker about ten cents per sticker.

Swapped restaurant menu codes. Same trick, different venue. The fake page asks you to "sign in" or "confirm your details" before showing the menu — something a real menu would never do.

Missed delivery notices. A card on your door or a flyer claiming a parcel needs rescheduling. Vague delivery details plus time pressure is the tell.

Account security warnings. A code claiming your bank or email needs urgent verification. Legitimate institutions do not route account security through a printed square.

Discount and refund traps. Codes promising a rebate that quietly enrol you in a recurring charge, with the terms buried or absent.

Charity and crisis appeals. Codes on flyers, collection tins and street stands after a disaster, routing donations to the attacker. These spike predictably in the days after a major news event, when giving quickly feels more important than checking.

The pattern across all six: the code appears in a place you already trust. That's the mechanism. It isn't carelessness — it's routine being turned against you.

And notice what none of them require. No malware, no exploit, no technical sophistication. The most successful physical QR scam in the world costs about ten cents and a steady hand.

How to check a code before you scan

Look at the physical code first. Is it a sticker sitting on top of something else? Peel-able at the corner? Scratched, misaligned, or a slightly different paper stock than the sign it's printed on? Legitimate codes are usually printed as part of the artwork, not applied afterwards. A sticker on a parking meter or a laminated table card deserves suspicion by default.

Read the URL preview. Every modern phone camera shows the destination before opening it. Read it. Check the domain carefully — not just that it contains the brand name, but that the brand name is the actual domain. starbucks.payments-secure.co is not Starbucks.

Distrust urgency. "Verify within 24 hours or your account will be suspended" is a social-engineering script, not a security policy.

Never enter credentials after scanning. This is the single rule that neutralises nearly every quishing attack. If a scan leads to a login page, close it and navigate to the service yourself, by typing the address or using your existing app. A QR code is fine for reading a menu, joining WiFi, or saving a contact. It is not an acceptable path to a password field.

If you've already scanned something suspicious

Stop interacting with the page immediately and don't enter anything further. If you did enter credentials, change that password now — and anywhere you reused it. Enable or re-enrol multi-factor authentication, which forces existing stolen sessions to re-authenticate. Watch your financial accounts for unfamiliar activity over the following weeks, and tell the business or venue whose code was tampered with, because you're almost certainly not the only person who scanned it.

For businesses printing QR codes

If you deploy codes in public, you inherit part of this problem — a customer defrauded through a sticker on your table blames you, not the attacker.

Print codes into the artwork, never apply them as stickers. A printed-in code on a laminated card or directly on packaging can't be covered without visible damage. Adhesive labels invite exactly the attack described above.

Brand the code. A code carrying your logo and colours is measurably harder to substitute convincingly — and research on restaurant menus found branded codes earn roughly 30% higher scan rates than anonymous black squares, precisely because they read as trustworthy rather than as phishing.

Print the URL underneath in readable text. This does double duty: it's an accessibility fallback for anyone who can't scan, and it lets a cautious customer verify the destination against what their camera shows.

Check your codes on a rotation. If you run QR ordering or payment, someone should physically inspect the codes on a schedule. Tampering is invisible until you look.

The codes that arrive on your screen

Physical stickers get the coverage, but a growing share of quishing arrives digitally — and the usual advice doesn't cover it.

In emails. A QR code embedded in a message or, more often, inside a PDF attachment. The reason attackers do this is specific: your email provider inspects links, but it sees an image and moves on. The code then moves you onto your phone, away from whatever protections your computer had. If you're scanning a code from an email at work, you are performing the exact step the attacker designed the email to produce.

In messaging apps. A forwarded image with a code and a short message — a delivery notice, a payment request, a "look at this". The forwarding chain launders the origin: by the time it reaches you, it came from someone you trust, who got it from someone they trust.

On screens you don't control. Codes on digital signage, on a shared TV in a waiting room, on a slide at an event. Nothing physical to peel back, no sticker edge to notice. The only defence left is reading the URL preview.

The rule that covers all three: a code you didn't go looking for deserves more suspicion, not less. A code on the table you chose to sit at is different from one that arrived in your inbox.

If you're responsible for a workplace rather than just yourself, the defences are structural rather than behavioural, and we cover them separately in quishing at work.

Scanning while travelling

Travel is where people scan most and verify least, and attackers know it.

Hotels. Codes for WiFi, room service, check-in. A sticker on a nightstand or a lift wall is trivial to place and nobody on staff inspects them. Get the WiFi password from reception rather than from a sticker.

Airports and stations. Charging stations, parking payment, transit tickets. High footfall, high urgency, low familiarity with the local legitimate branding — you have no idea what the real parking payment page is supposed to look like in a country you've never visited.

Rental scooters and bikes. Codes on the vehicle itself, outdoors, unmonitored for weeks at a time. Check for a sticker layered over the moulded or printed original.

Restaurant tables abroad. You can't tell a plausible local payment brand from a fake one. If a scan leads to a payment page, pay at the counter instead.

The general travel rule: prefer the app or the counter over the code. Use the transit operator's own app, pay a human, ask staff. The convenience a code saves is thirty seconds; the cost of a compromised card abroad is a ruined trip.

If you already entered details

Move quickly, in this order.

If you entered a password: change it immediately on the real site, and change it anywhere you reused it. Then enable or re-enrol multi-factor authentication — re-enrolling forces existing sessions to re-authenticate, which is what actually evicts an attacker holding a stolen session token.

If you entered card details: call your bank or use the app to freeze the card, then request a replacement. Don't wait to see whether a charge appears. Ask specifically about a chargeback if anything has already gone through — fraudulent card-not-present transactions are normally recoverable, but time limits apply.

If you paid by bank transfer: contact your bank the same day. Transfers are far harder to reverse than card payments, and the window is measured in hours.

Report it. Tell the venue or business whose code was tampered with — they usually have no idea, and you're rarely the only victim. Report to your national fraud or cybercrime body; in many countries this is what triggers action against the hosting infrastructure.

Watch for the follow-up. Victims of one scam are frequently contacted again by "recovery" services offering to retrieve the lost money for a fee. That is the same operation, running its second act.

Helping someone who's a likelier target

If you help an older relative with technology, three things are worth doing once rather than explaining repeatedly.

Check that the camera shows the URL preview and that they know to read it before tapping. On some phones this has been disabled or the preview appears briefly and is easy to miss.

Agree one rule, not a checklist. "Never type a password or card number into anything that opened from a scan." A single rule is remembered; a list of seven warning signs is not.

Tell them there's no penalty for asking. Most successful scams work because the target didn't want to seem foolish by checking. Make it explicitly fine to send you a photo and ask.

So — are QR codes safe?

The code itself is not the risk. A QR code is a container for text; it can't execute anything, install anything, or read anything from your phone. Every documented QR attack is really an attack on the destination, using the code purely to hide where you're going.

Which points to the practical rule: treat a QR code exactly as you'd treat a link from an unknown sender. Same caution, same scepticism, same refusal to type a password into whatever appears.

One structural note worth understanding. A static QR code encodes its destination directly in the pattern — the information is the black and white squares themselves, with no server in between. It cannot be silently redirected later, because there's nothing to redirect. A dynamic code encodes a short redirect URL owned by a third-party service; the destination can be changed at any time, after printing, by whoever controls that account. That flexibility is genuinely useful, but it's also an extra party who can change where your code sends people — and an extra service that can go out of business, expire, or be compromised.

For anything printed and left in public, static codes remove a category of risk entirely. Every code generated with VixQR is static by design, produced entirely in your browser: the content you encode never reaches a server, and the finished code points where you told it to, permanently.

All articles