What quishing is

Quishing is a blend of "QR" and "phishing" — a scam that uses QR codes to send you to fake sites or install malicious apps. It exploits the fact that people can't easily read a URL by eye from a QR code.

A common tactic is sticking a fake QR sticker over parking notices, restaurant menus, or public signs. It looks legitimate but leads to a fake page that steals payment or login information.

Check before you scan

Be suspicious of sticker-style QR codes that look pasted over something else, or whose print quality differs from its surroundings. It's also safer to build a habit of previewing the destination URL rather than opening it immediately.

The "Scan QR" tool on this site does not open links automatically — it shows the decoded address first. Confirm the domain matches what you expect before tapping "Open link." For unsafe schemes that aren't http/https (such as javascript: or data:), the open button is not offered at all.

Warning-sign checklist

Strong warning signs include a shortened URL that hides the real domain, urgent requests to log in or enter payment or personal details, or a page impersonating an institution like "XYZ Bank" while the domain is completely different.

A legitimate institution won't suddenly ask for your full password or card number on a page reached via QR. If anything feels off, stop entering information and verify through the official app or a URL you type yourself.

Safe habits summary

(1) Don't scan QR codes from unknown sources, (2) check the URL first after scanning, (3) be extra skeptical of requests for personal or payment data, and (4) keep your device and browser up to date.

If you received a suspicious QR as an image file, a good approach is to check the address first using this site's image-upload scan, before pointing your camera at it.