QR Code Payment Scams: How Quishing Works and How to Stay Safe
QR codes have moved from novelty to necessity, powering everything from restaurant menus to peer-to-peer payments. That ubiquity has attracted fraudsters, who have coined a new attack: quishing, or QR code phishing. Because a QR code is unreadable to the human eye, it is the perfect disguise for a malicious link.
Why QR Codes Are Easy to Abuse
A QR code is simply an encoded instruction, usually a URL. You cannot tell a legitimate code from a fraudulent one by looking at it, and that opacity is the core of the problem. Scanning happens fast, on a small screen, and users rarely scrutinize the destination before it loads.
- No visual verification: The payload is hidden until scanned.
- Implicit trust: A code printed on official-looking signage feels legitimate.
- Small screens: Shortened or spoofed URLs are hard to inspect on a phone.
Common Quishing Techniques
Sticker Overlays
Fraudsters print malicious QR stickers and place them over legitimate ones, on parking meters, EV chargers, or restaurant tables. Payments and personal data flow straight to the attacker.
Fake Payment Requests
Scammers send QR codes claiming you need to scan to receive a refund or claim a prize. In reality, scanning and confirming authorizes a payment out of your account.
Phishing Landing Pages
A scanned code leads to a convincing but fake login or payment page that harvests your credentials.
A recurring trick exploits confusion between sending and receiving: you never need to scan a code or approve a transaction to receive money.
Malicious App Installs
Some quishing codes do not lead to a payment page at all but instead prompt you to download an app. That app may be malware designed to capture keystrokes, intercept one-time codes, or overlay fake screens on top of legitimate banking apps. Because the download begins from a QR scan rather than an official app store search, users often skip the scrutiny they would normally apply.
How to Protect Yourself
- Preview the URL: Most phone cameras show the destination link before opening it. Read it, and be wary of misspelled or unfamiliar domains.
- Inspect physical codes: Check for stickers placed over original codes, especially in public and unattended locations.
- Never approve to receive: If a payment app asks you to confirm a payment in order to get money, stop. That authorizes an outgoing transfer.
- Use official apps: Enter merchant details manually or use in-app payment features rather than scanning codes from messages or emails.
For Businesses
Merchants should tamper-proof displayed codes, inspect them regularly, and educate staff so they can reassure customers about which codes are legitimate. Printing codes directly onto laminated or engraved surfaces makes sticker overlays harder to apply unnoticed, and displaying a short, verifiable destination alongside the code lets customers confirm where they are headed. Staff who can confidently answer where a code should lead are a strong first line of defense against tampering.
Conclusion
Quishing thrives on the one weakness of QR codes: you cannot see where they lead. The defense is to slow down, preview every destination, and remember that receiving money never requires you to approve a payment. A moment of verification before you scan is all it takes to keep convenient payments from becoming costly ones.