Quishing: How to Tell if a QR Code Is Safe Before You Scan
What quishing is, where fake QR codes have turned up, what the FBI, FTC and NCSC advise, and a checklist for checking a code before you scan it or print one.
Quishing is phishing with a QR code: a fake sticker on a parking meter, a code in an email PDF, a letter or a package sends you to a page that steals passwords or card details, or to malware. Microsoft detected 18.7 million QR phishing emails in March 2026, and cities from New York to Asheville have found fake stickers on meters. Check for a sticker over the original code, preview the link and read the domain, use your phone's built-in scanner, never install an app from a code, and pay for parking at the meter or in the operator's official app.
- Feel for a sticker over the original code.
- Preview the link and read the domain before you tap.
- Pay for parking at the meter or in the operator's official app.
- Use your phone's built-in scanner and never install an app from a code.
- If you print codes, put a short URL next to them and check placements.
Quishing is phishing with a QR code. A scammer puts a code where you'll scan it without thinking – a sticker on a parking meter, a PDF in your inbox, a letter or a package – and the link takes you to a fake page that collects your card details or password. Microsoft detected 18.7 million QR phishing emails in March 2026 alone (Microsoft, April 2026).
To tell if a QR code is safe, check three things before you tap. Is there a sticker on top of the original code? Does the link your phone shows belong to the business you expect? And were you expecting a code here at all? If you're paying for parking, the safest route is the meter or the operator's official app.
What is quishing?
Quishing is a phishing link hidden in a QR code. You can't read a QR code by looking at it, so you can't judge the link until your phone decodes it. The FBI warned about it in 2022 and the FTC in 2023, and the scams have since taken three main forms:
- Stickers over real codes on parking meters, pay stations and EV chargers, leading to fake payment pages.
- QR codes in emails, often inside a PDF attachment, leading to fake Microsoft 365 or Google login pages.
- QR codes in letters and packages you didn't expect, leading to phishing pages or malware.
In the UK, Action Fraud (since replaced by Report Fraud) received 784 quishing reports from April 2024 to April 2025, with almost £3.5 million lost (Action Fraud, June 2025). Most came from car parks, where criminals stuck fake codes over the real ones on payment machines. Others hit people selling on online shopping platforms, who were sent QR codes by email.
Why does quishing work?
A QR code moves you from a protected device to a less protected one. In a January 2026 FLASH alert, the FBI said North Korean hackers known as Kimsuky sent QR codes in spearphishing emails to "force victims to pivot from their corporate endpoint to a mobile device." That pivot is the point: your employer's security tools can check a link you click on a work laptop, but they usually can't see what you open on your own phone.
The FBI says the fake pages copied Microsoft 365, Okta or VPN login portals, and in one run of emails in May–June 2025, a Google login page. These attacks often end in session-token theft. A session token is what a site hands your browser after you log in, so you stay signed in. With it, an attacker can get into your account without passing your MFA check. That's why the FBI tells organizations to require phishing-resistant MFA and to warn staff about unexpected QR codes "regardless of their source (email, letter, flyer, packaging)."
Stickers in the street work for a plainer reason. A code on a parking machine that says "scan to pay" looks like it belongs there, and you're usually in a hurry.
How common are QR code scams?
Microsoft's data shows a sharp rise in early 2026. Its count of QR phishing emails rose 146% in two months, from 7.6 million in January 2026 to 18.7 million in March. Each company counts only the mail it scans, so treat these as separate snapshots.
| Source | Period | What it measured | Finding |
|---|---|---|---|
| Microsoft | Jan–Mar 2026 | QR phishing emails Microsoft detected | 7.6M in January, 18.7M in March (+146%) |
| Barracuda | Mid-June to mid-Sept 2024 | Phishing emails with a QR code inside a PDF | More than 500,000 |
| Abnormal Security | Report published Feb 2024 | Who receives QR phishing attacks | C-suite executives were 42x more likely to receive one |
| Cofense | May–Aug 2023 | One campaign aimed at Microsoft 365 logins | 1,000+ emails with malicious QR codes; about 29% went to one major US energy company |
A few details matter more than the headline numbers. Most QR phishing emails hide the code in a PDF: Microsoft found PDF attachments carried 65% of QR attacks in January and 70% in March. Barracuda found the fake PDFs impersonated Microsoft, SharePoint or OneDrive in 51% of cases, DocuSign in 31% and Adobe in 15%. So a "document shared with you" or "please sign" PDF with a QR code deserves a second look.
Abnormal's 42x figure is often misquoted. It measures how often executives receive QR attacks and says nothing about how often they fall for them. The same report found 89.3% of QR attacks aimed to steal login details, and 27% in the second half of 2023 used fake notices saying the target's MFA was about to expire.
We couldn't find an official figure for quishing losses in the US. The clearest official count is Action Fraud's UK number above.
Where have fake QR codes turned up?
Parking payment is the most documented target. Since late 2021, cities in Texas, New York, North Carolina and British Columbia have found fake stickers on meters. Freedom of Information requests by The Bureau of Investigative Journalism found 123 UK councils reporting car parks targeted in a single year (June 2025).
| Place | Date | What happened | Source |
|---|---|---|---|
| San Antonio, TX | Dec 2021 | More than 100 pay stations stickered with fraudulent codes | FOX 7 Austin |
| Austin, TX | Jan 2022 | Fake stickers on 29 pay stations; the city said it does not use QR codes on its infrastructure at all | FOX 7 Austin |
| Switzerland | Oct 2024 | Fake codes on parking meters led to payment pages taking Twint or cards; victims were charged several hundred francs | Swiss NCSC |
| Switzerland | Nov 2024 | Fake MeteoSwiss letters with a QR code that installed Android malware aimed at logins for more than 383 apps, including banking apps | The Record |
| Cheshire West and Chester, UK | Jan 2025 | Codes on privately owned car parks; the council said it does not use QR codes for parking payments | Council |
| Germany | Mar 2025 | Stickers on EV chargers led to fake charging operator sites | ADAC |
| New York City | Jun 2025 | At least one fake sticker on a ParkNYC meter; the city began inspecting meters citywide | NY1 |
| UK, nationwide | Jun 2025 | 123 of 373 councils that replied reported targeted car parks; about 400 car parks and 20+ hospitals hit; in Sheffield, all 370 ticket machines | TBIJ |
| Asheville, NC | Feb 2026 | About 20 stickers on meters on Biltmore Ave, Coxe Ave, Pack Square and S Market St | City of Asheville |
| New Westminster, BC | Aug 2026 | "Scan to pay" stickers on meters; several victims, one of whom lost C$2,000 | New Westminster Police |
Notice what the cities said. Austin, Asheville and New Westminster all told residents they don't use QR codes for parking payments. New York's DOT put it plainly: the only way to pay is the official ParkNYC app or a physical ParkNYC meter. In places like these, any QR code on a meter is a fake.
The losses are real money. In Cirencester, a woman lost £406 to a fake lookalike of a PayByPhone payment site, according to the Bureau's report. In Switzerland, the stolen card details were then used to buy gift cards.
The EV charger scams added a trick. The ADAC, a German motoring club, said the fake sites sent victims on to the real operator's site afterwards, which hid the fraud. ADAC had no complaints from its own members yet, but cited several cases documented by *Auto Motor und Sport*.
Email campaigns follow the same pattern at scale. In 2023, Cofense tracked a campaign aimed at Microsoft 365 logins, with lures about MFA and account security. 26% of its links used Bing redirect URLs, so the link started on a Microsoft address before it went anywhere else. That's a good reason to look past the first part of any link.
What about restaurant menus? The UK NCSC says QR codes in pubs and restaurants are "probably safe for you to scan." A fake sticker on a table or menu is possible, but we found no reputable news report of it happening. Treat it as a small risk and use the same checks.
What do the FTC, FBI and NCSC say about QR codes?
They agree on nearly everything: check the link before you open it, look for a sticker, be wary of codes you didn't expect, and don't install apps from QR codes. The FTC's newest alert, from September 3, 2026, warns that scammers are covering legitimate parking meter codes with their own.
| Agency | Date | What it advises |
|---|---|---|
| FBI IC3 | Jan 18, 2022 | Check the URL after scanning; check for a sticker over the original code; don't download an app from a code, or any QR scanner app; to pay, type a known, trusted URL |
| FTC | Dec 6, 2023 | Inspect the URL for misspellings or switched letters; don't scan codes in emails or texts you weren't expecting, especially urgent ones; update your phone and use MFA |
| Canadian Centre for Cyber Security | Updated Jan 16, 2024 | Don't scan a code on a label that could be covering another; ask staff to confirm it; set your phone to ask before opening a code's action; use the built-in camera |
| UK NCSC | Feb 8, 2024 | Pub and restaurant codes are probably safe; stations and car parks might be riskier; be careful with codes in emails; use the phone's built-in scanner |
| FTC | Jan 23, 2025 | Beware packages from unknown senders asking you to scan a code to see who sent them; if you entered a password, change it and turn on two-factor authentication |
| Ireland NCSC | Jan 2025 | Check the preview matches the official website; ask whether the code is behind glass or on a display, or a sticker |
| Swiss NCSC | May 8, 2025 | Look closely and feel for stickers; use the scanner's preview; be extremely cautious if asked for passwords or card details |
| Action Fraud | Jun 20, 2025 | Look for a sticker; if in doubt, don't scan and search for the official website or app; use the built-in scanner |
| FBI FLASH | Jan 8, 2026 | Organizations: train staff on unsolicited QR codes from any source and require phishing-resistant MFA |
| FTC | Sep 3, 2026 | Parking meter codes are being covered; check the link preview for spelling mistakes; report to ReportFraud.ftc.gov |
There's one split. Ireland's NCSC recommends "a trusted QR code scanning app." The FBI, the UK NCSC, Action Fraud and the Canadian Cyber Centre all say to use the scanner built into your phone, and the FBI says not to download a QR scanner app at all. We'd follow the majority.
How do you check a QR code before scanning?
The FTC, FBI, Ireland's NCSC and the Swiss NCSC all tell you to check the link before you open it, and the FBI adds a physical check: look for a sticker placed over the original code. Take these steps any time a code asks you to pay, sign in or install something.
- Ask if you expected it. The FTC says not to scan a QR code in an email or text you weren't expecting, especially one that pushes you to act now. The same goes for packages: the FTC's January 2025 alert describes a "gift" from an unknown sender with a note telling you to scan a code to find out who sent it.
- Look and feel for a sticker. The Swiss NCSC says to feel for any stickers covering the original code. If a code is on a label that could be hiding another one, the Canadian Cyber Centre says to ask a staff member first.
- Preview the link and read the domain. Most phone cameras show the link before you tap it. Check the domain for misspellings or switched letters, as the FTC advises. Then read the end of the domain, just before the first single slash (for endings like .co.uk, read the part before that). In
cityparking.com.pay-zone.net/zone4, the site belongs to pay-zone.net, whatever the start says. If you can't tell who owns the address, don't open it. Action Fraud's advice is to search for the official website or app instead. - Never pay for parking from a scanned sticker. Use the meter itself or the operator's official app. The FBI says to avoid paying through a site you reached from a QR code and to type a known, trusted address instead.
- Use your phone's built-in scanner and never install an app from a QR code. Canada also suggests setting your phone to ask before it opens whatever a code points to.
- Stop before you type a password or card number. The Swiss NCSC says to be extremely cautious if a page asks for either, and to check the amount and who you're paying before you confirm.
- Keep your phone updated and MFA turned on. The FTC recommends both, and they limit what one bad scan can do.
Where you scan matters too. The UK NCSC says codes in open spaces like stations and car parks "might be riskier" than those in pubs and restaurants. In open spaces, anyone can walk up and stick a label on a code.
What should you do if you scanned a fake QR code?
Act quickly. If you entered login details, the FTC's advice is to "change your password right away" and turn on two-factor authentication. If you gave card details, call your bank. Then report it, so the stickers or emails can be taken down before they catch someone else.
- You entered a password. Change it on the real site, typing the address yourself, and anywhere else you use it. Turn on two-factor authentication.
- You entered card or bank details. Call your bank or card issuer on the number on the back of your card. Ask them to block the card and check recent charges.
- You installed an app. Delete it, call your bank, and change passwords from a different device. If the app won't uninstall, ask your bank or a phone repair shop about a factory reset. The Android malware in the fake MeteoSwiss letters went after banking logins.
- It was your work account. Tell your IT team right away. If a page stole your session token, a password change alone may not end the attacker's access, so IT may need to sign out your active sessions too.
- Report it. In the US, use ReportFraud.ftc.gov. In England, Wales and Northern Ireland, report to Report Fraud, the police service that replaced Action Fraud in late 2025 (Scotland: Police Scotland on 101). Tell the parking operator or city as well, so they can remove the sticker.
How can businesses make their QR codes harder to fake?
If your code sits in a public place, someone can cover it with their own. The Bureau of Investigative Journalism found that all 370 ticket machines in Sheffield had been targeted. These steps come from the official guidance and the incidents above, plus one of our own.
- Print a short URL next to the code. Nottinghamshire County Council's content guidance says never to use a QR code on its own and to "always include a short URL." People who won't scan can type it, and people who do scan can compare it with the preview.
- Put codes behind glass or on a screen. Ireland's NCSC asks whether a code is tamper-proof, "such as behind glass or on a digital display." ADAC wants EV chargers to show codes on their own screens. Intertraffic's parking coverage also mentions printing codes on the ticket itself.
- Check your placements. Intertraffic mentions regular site checks. Finding at least one fake sticker led New York to inspect meters citywide.
- Say publicly how you take payment. Austin, Asheville, New York, New Westminster and Cheshire West all did this. New Westminster Police pointed drivers to the payment methods printed on signs above or on the meter. If you don't take payment by QR code, put that on the sign.
- Use a domain people recognize. This one is our reasoning; no regulator says it. The warnings above tell people to check the link. A code that opens yourbusiness.com passes that check at a glance. A code that opens an unfamiliar short-link domain looks no different from a scammer's, and asks your customer to trust it anyway.
What about dynamic QR codes?
Nottinghamshire recommends static codes, because dynamic codes rely on "a tracking or redirect link controlled by another service, which can break or change." That's a fair point. A static code holds the final address, with nothing in between. A dynamic QR code sends people through a redirect first, which is what lets you change the destination or count scans after printing.
If you use dynamic codes, the redirect is the part to get right. Know which company runs it, what its terms say happens to your codes if you stop paying, and whether the link your customers preview shows that company's domain or yours. When the redirect runs on your own domain, the address people check is yours.
To see who runs a code you already have, try Whooshly's free QR code checker: paste the link inside the code and it shows which host runs the redirect and, for the generators and shorteners we've studied, what their terms or our link-rot data say. It's not a malware scanner, and it doesn't check for phishing. If you print codes for a business, putting them on your own custom domain makes them easier for customers to recognize, and with Whooshly that comes with Core, a one-time $35 payment.