Skip to content
Whooshly Blog · QR codes

Quishing: How to Tell if a QR Code Is Safe Before You Scan

What quishing is, where fake QR codes have turned up, what the FBI, FTC and NCSC advise, and a checklist for checking a code before you scan it or print one.

Updated Sep 2026·9 min read

Quishing is phishing with a QR code. A scammer puts a code where you'll scan it without thinking – a sticker on a parking meter, a PDF in your inbox, a letter or a package – and the link takes you to a fake page that collects your card details or password. Microsoft detected 18.7 million QR phishing emails in March 2026 alone (Microsoft, April 2026).

To tell if a QR code is safe, check three things before you tap. Is there a sticker on top of the original code? Does the link your phone shows belong to the business you expect? And were you expecting a code here at all? If you're paying for parking, the safest route is the meter or the operator's official app.

What is quishing?

Quishing is a phishing link hidden in a QR code. You can't read a QR code by looking at it, so you can't judge the link until your phone decodes it. The FBI warned about it in 2022 and the FTC in 2023, and the scams have since taken three main forms:

  • Stickers over real codes on parking meters, pay stations and EV chargers, leading to fake payment pages.
  • QR codes in emails, often inside a PDF attachment, leading to fake Microsoft 365 or Google login pages.
  • QR codes in letters and packages you didn't expect, leading to phishing pages or malware.

In the UK, Action Fraud (since replaced by Report Fraud) received 784 quishing reports from April 2024 to April 2025, with almost £3.5 million lost (Action Fraud, June 2025). Most came from car parks, where criminals stuck fake codes over the real ones on payment machines. Others hit people selling on online shopping platforms, who were sent QR codes by email.

Why does quishing work?

A QR code moves you from a protected device to a less protected one. In a January 2026 FLASH alert, the FBI said North Korean hackers known as Kimsuky sent QR codes in spearphishing emails to "force victims to pivot from their corporate endpoint to a mobile device." That pivot is the point: your employer's security tools can check a link you click on a work laptop, but they usually can't see what you open on your own phone.

The FBI says the fake pages copied Microsoft 365, Okta or VPN login portals, and in one run of emails in May–June 2025, a Google login page. These attacks often end in session-token theft. A session token is what a site hands your browser after you log in, so you stay signed in. With it, an attacker can get into your account without passing your MFA check. That's why the FBI tells organizations to require phishing-resistant MFA and to warn staff about unexpected QR codes "regardless of their source (email, letter, flyer, packaging)."

Stickers in the street work for a plainer reason. A code on a parking machine that says "scan to pay" looks like it belongs there, and you're usually in a hurry.

How common are QR code scams?

Microsoft's data shows a sharp rise in early 2026. Its count of QR phishing emails rose 146% in two months, from 7.6 million in January 2026 to 18.7 million in March. Each company counts only the mail it scans, so treat these as separate snapshots.

SourcePeriodWhat it measuredFinding
MicrosoftJan–Mar 2026QR phishing emails Microsoft detected7.6M in January, 18.7M in March (+146%)
BarracudaMid-June to mid-Sept 2024Phishing emails with a QR code inside a PDFMore than 500,000
Abnormal SecurityReport published Feb 2024Who receives QR phishing attacksC-suite executives were 42x more likely to receive one
CofenseMay–Aug 2023One campaign aimed at Microsoft 365 logins1,000+ emails with malicious QR codes; about 29% went to one major US energy company

A few details matter more than the headline numbers. Most QR phishing emails hide the code in a PDF: Microsoft found PDF attachments carried 65% of QR attacks in January and 70% in March. Barracuda found the fake PDFs impersonated Microsoft, SharePoint or OneDrive in 51% of cases, DocuSign in 31% and Adobe in 15%. So a "document shared with you" or "please sign" PDF with a QR code deserves a second look.

Abnormal's 42x figure is often misquoted. It measures how often executives receive QR attacks and says nothing about how often they fall for them. The same report found 89.3% of QR attacks aimed to steal login details, and 27% in the second half of 2023 used fake notices saying the target's MFA was about to expire.

We couldn't find an official figure for quishing losses in the US. The clearest official count is Action Fraud's UK number above.

Where have fake QR codes turned up?

Parking payment is the most documented target. Since late 2021, cities in Texas, New York, North Carolina and British Columbia have found fake stickers on meters. Freedom of Information requests by The Bureau of Investigative Journalism found 123 UK councils reporting car parks targeted in a single year (June 2025).

PlaceDateWhat happenedSource
San Antonio, TXDec 2021More than 100 pay stations stickered with fraudulent codesFOX 7 Austin
Austin, TXJan 2022Fake stickers on 29 pay stations; the city said it does not use QR codes on its infrastructure at allFOX 7 Austin
SwitzerlandOct 2024Fake codes on parking meters led to payment pages taking Twint or cards; victims were charged several hundred francsSwiss NCSC
SwitzerlandNov 2024Fake MeteoSwiss letters with a QR code that installed Android malware aimed at logins for more than 383 apps, including banking appsThe Record
Cheshire West and Chester, UKJan 2025Codes on privately owned car parks; the council said it does not use QR codes for parking paymentsCouncil
GermanyMar 2025Stickers on EV chargers led to fake charging operator sitesADAC
New York CityJun 2025At least one fake sticker on a ParkNYC meter; the city began inspecting meters citywideNY1
UK, nationwideJun 2025123 of 373 councils that replied reported targeted car parks; about 400 car parks and 20+ hospitals hit; in Sheffield, all 370 ticket machinesTBIJ
Asheville, NCFeb 2026About 20 stickers on meters on Biltmore Ave, Coxe Ave, Pack Square and S Market StCity of Asheville
New Westminster, BCAug 2026"Scan to pay" stickers on meters; several victims, one of whom lost C$2,000New Westminster Police

Notice what the cities said. Austin, Asheville and New Westminster all told residents they don't use QR codes for parking payments. New York's DOT put it plainly: the only way to pay is the official ParkNYC app or a physical ParkNYC meter. In places like these, any QR code on a meter is a fake.

The losses are real money. In Cirencester, a woman lost £406 to a fake lookalike of a PayByPhone payment site, according to the Bureau's report. In Switzerland, the stolen card details were then used to buy gift cards.

The EV charger scams added a trick. The ADAC, a German motoring club, said the fake sites sent victims on to the real operator's site afterwards, which hid the fraud. ADAC had no complaints from its own members yet, but cited several cases documented by *Auto Motor und Sport*.

Email campaigns follow the same pattern at scale. In 2023, Cofense tracked a campaign aimed at Microsoft 365 logins, with lures about MFA and account security. 26% of its links used Bing redirect URLs, so the link started on a Microsoft address before it went anywhere else. That's a good reason to look past the first part of any link.

What about restaurant menus? The UK NCSC says QR codes in pubs and restaurants are "probably safe for you to scan." A fake sticker on a table or menu is possible, but we found no reputable news report of it happening. Treat it as a small risk and use the same checks.

What do the FTC, FBI and NCSC say about QR codes?

They agree on nearly everything: check the link before you open it, look for a sticker, be wary of codes you didn't expect, and don't install apps from QR codes. The FTC's newest alert, from September 3, 2026, warns that scammers are covering legitimate parking meter codes with their own.

AgencyDateWhat it advises
FBI IC3Jan 18, 2022Check the URL after scanning; check for a sticker over the original code; don't download an app from a code, or any QR scanner app; to pay, type a known, trusted URL
FTCDec 6, 2023Inspect the URL for misspellings or switched letters; don't scan codes in emails or texts you weren't expecting, especially urgent ones; update your phone and use MFA
Canadian Centre for Cyber SecurityUpdated Jan 16, 2024Don't scan a code on a label that could be covering another; ask staff to confirm it; set your phone to ask before opening a code's action; use the built-in camera
UK NCSCFeb 8, 2024Pub and restaurant codes are probably safe; stations and car parks might be riskier; be careful with codes in emails; use the phone's built-in scanner
FTCJan 23, 2025Beware packages from unknown senders asking you to scan a code to see who sent them; if you entered a password, change it and turn on two-factor authentication
Ireland NCSCJan 2025Check the preview matches the official website; ask whether the code is behind glass or on a display, or a sticker
Swiss NCSCMay 8, 2025Look closely and feel for stickers; use the scanner's preview; be extremely cautious if asked for passwords or card details
Action FraudJun 20, 2025Look for a sticker; if in doubt, don't scan and search for the official website or app; use the built-in scanner
FBI FLASHJan 8, 2026Organizations: train staff on unsolicited QR codes from any source and require phishing-resistant MFA
FTCSep 3, 2026Parking meter codes are being covered; check the link preview for spelling mistakes; report to ReportFraud.ftc.gov

There's one split. Ireland's NCSC recommends "a trusted QR code scanning app." The FBI, the UK NCSC, Action Fraud and the Canadian Cyber Centre all say to use the scanner built into your phone, and the FBI says not to download a QR scanner app at all. We'd follow the majority.

How do you check a QR code before scanning?

The FTC, FBI, Ireland's NCSC and the Swiss NCSC all tell you to check the link before you open it, and the FBI adds a physical check: look for a sticker placed over the original code. Take these steps any time a code asks you to pay, sign in or install something.

  1. Ask if you expected it. The FTC says not to scan a QR code in an email or text you weren't expecting, especially one that pushes you to act now. The same goes for packages: the FTC's January 2025 alert describes a "gift" from an unknown sender with a note telling you to scan a code to find out who sent it.
  2. Look and feel for a sticker. The Swiss NCSC says to feel for any stickers covering the original code. If a code is on a label that could be hiding another one, the Canadian Cyber Centre says to ask a staff member first.
  3. Preview the link and read the domain. Most phone cameras show the link before you tap it. Check the domain for misspellings or switched letters, as the FTC advises. Then read the end of the domain, just before the first single slash (for endings like .co.uk, read the part before that). In cityparking.com.pay-zone.net/zone4, the site belongs to pay-zone.net, whatever the start says. If you can't tell who owns the address, don't open it. Action Fraud's advice is to search for the official website or app instead.
  4. Never pay for parking from a scanned sticker. Use the meter itself or the operator's official app. The FBI says to avoid paying through a site you reached from a QR code and to type a known, trusted address instead.
  5. Use your phone's built-in scanner and never install an app from a QR code. Canada also suggests setting your phone to ask before it opens whatever a code points to.
  6. Stop before you type a password or card number. The Swiss NCSC says to be extremely cautious if a page asks for either, and to check the amount and who you're paying before you confirm.
  7. Keep your phone updated and MFA turned on. The FTC recommends both, and they limit what one bad scan can do.

Where you scan matters too. The UK NCSC says codes in open spaces like stations and car parks "might be riskier" than those in pubs and restaurants. In open spaces, anyone can walk up and stick a label on a code.

What should you do if you scanned a fake QR code?

Act quickly. If you entered login details, the FTC's advice is to "change your password right away" and turn on two-factor authentication. If you gave card details, call your bank. Then report it, so the stickers or emails can be taken down before they catch someone else.

  • You entered a password. Change it on the real site, typing the address yourself, and anywhere else you use it. Turn on two-factor authentication.
  • You entered card or bank details. Call your bank or card issuer on the number on the back of your card. Ask them to block the card and check recent charges.
  • You installed an app. Delete it, call your bank, and change passwords from a different device. If the app won't uninstall, ask your bank or a phone repair shop about a factory reset. The Android malware in the fake MeteoSwiss letters went after banking logins.
  • It was your work account. Tell your IT team right away. If a page stole your session token, a password change alone may not end the attacker's access, so IT may need to sign out your active sessions too.
  • Report it. In the US, use ReportFraud.ftc.gov. In England, Wales and Northern Ireland, report to Report Fraud, the police service that replaced Action Fraud in late 2025 (Scotland: Police Scotland on 101). Tell the parking operator or city as well, so they can remove the sticker.

How can businesses make their QR codes harder to fake?

If your code sits in a public place, someone can cover it with their own. The Bureau of Investigative Journalism found that all 370 ticket machines in Sheffield had been targeted. These steps come from the official guidance and the incidents above, plus one of our own.

  • Print a short URL next to the code. Nottinghamshire County Council's content guidance says never to use a QR code on its own and to "always include a short URL." People who won't scan can type it, and people who do scan can compare it with the preview.
  • Put codes behind glass or on a screen. Ireland's NCSC asks whether a code is tamper-proof, "such as behind glass or on a digital display." ADAC wants EV chargers to show codes on their own screens. Intertraffic's parking coverage also mentions printing codes on the ticket itself.
  • Check your placements. Intertraffic mentions regular site checks. Finding at least one fake sticker led New York to inspect meters citywide.
  • Say publicly how you take payment. Austin, Asheville, New York, New Westminster and Cheshire West all did this. New Westminster Police pointed drivers to the payment methods printed on signs above or on the meter. If you don't take payment by QR code, put that on the sign.
  • Use a domain people recognize. This one is our reasoning; no regulator says it. The warnings above tell people to check the link. A code that opens yourbusiness.com passes that check at a glance. A code that opens an unfamiliar short-link domain looks no different from a scammer's, and asks your customer to trust it anyway.

What about dynamic QR codes?

Nottinghamshire recommends static codes, because dynamic codes rely on "a tracking or redirect link controlled by another service, which can break or change." That's a fair point. A static code holds the final address, with nothing in between. A dynamic QR code sends people through a redirect first, which is what lets you change the destination or count scans after printing.

If you use dynamic codes, the redirect is the part to get right. Know which company runs it, what its terms say happens to your codes if you stop paying, and whether the link your customers preview shows that company's domain or yours. When the redirect runs on your own domain, the address people check is yours.

To see who runs a code you already have, try Whooshly's free QR code checker: paste the link inside the code and it shows which host runs the redirect and, for the generators and shorteners we've studied, what their terms or our link-rot data say. It's not a malware scanner, and it doesn't check for phishing. If you print codes for a business, putting them on your own custom domain makes them easier for customers to recognize, and with Whooshly that comes with Core, a one-time $35 payment.

Frequently asked questions

What is quishing?

Quishing is phishing through a QR code. Scammers put a code on a sticker, in an email or PDF, or in a letter or package. The link leads to a fake page that steals passwords or card details, or to an app that installs malware.

Is this QR code safe? How can I tell?

Check for a sticker over the original code, preview the link and read the domain before you tap, and ask whether you expected a code there. Be most careful with codes that ask you to pay, sign in or install an app.

Is it safe to pay for parking with a QR code?

Pay at the meter or through the operator's official app. New York, Austin, Asheville and New Westminster, BC have all said they don't take parking payments by QR code, so a code on their meters is a fake. The FBI advises typing a known, trusted address to pay.

Are QR codes on restaurant tables safe?

The UK NCSC says codes in pubs and restaurants are probably safe to scan, while codes in open spaces like stations and car parks might be riskier. Still preview the link, and don't enter card details on a page you don't recognize.

Can a QR code put malware on my phone?

A QR code can lead you to download an app. Fake MeteoSwiss letters in 2024 used a QR code to install Android malware aimed at banking apps. The FBI's advice is never to download an app from a QR code.

What should I do if I scanned a fake QR code?

If you entered a password, change it right away and turn on two-factor authentication. If you gave card details, call your bank. Report it to ReportFraud.ftc.gov in the US or reportfraud.police.uk in England, Wales and Northern Ireland (Scotland: Police Scotland on 101), and tell the operator so the sticker comes down.

Should I use a QR scanner app?

The FBI, UK NCSC, Action Fraud and the Canadian Cyber Centre all say to use the scanner built into your phone's camera, and the FBI says not to download a QR scanner app. Ireland's NCSC is the exception and suggests a trusted scanner app.

Keep Whooshly in your Google results

If our link and QR guides are useful, add Whooshly as a Preferred Source in Google.

Add as a preferred source on Google

Tap. Whoosh. You're there.

Buy Whooshly once and own your campaign links for good.

Quincy R. · Whooshly AI assistantAsk Quincy

Answers about products, pricing, and setup.

What do you want to make?

Ask about links, QR codes, UTMs, pages, pricing, analytics, or custom domains.

Don't share passwords or private data. Privacy