2020-2021: The setup
The pandemic drove a rapid, genuine shift toward QR codes for contactless menus, check-ins, and payments — normalizing scanning unfamiliar codes as a routine daily action. In 2021, QR codes were used in only about 0.8% of phishing attacks, according to Egress security research — a tactic that existed but hadn't yet been widely adopted by attackers.
2022: First major documented incidents
In January 2022, the FBI's Internet Crime Complaint Center issued a public service announcement warning that criminals were tampering with QR codes at parking meters, cryptocurrency kiosks, and restaurant payment terminals to redirect payments to fraudulent destinations. Shortly after, in late 2021 and early 2022, Austin, San Antonio, and Houston all reported fraudulent stickers placed over legitimate parking meter QR codes, redirecting to a fake payment site — among the first widely reported physical quishing incidents in the U.S. Quishing use roughly doubled that year, reaching about 1.4% of phishing attacks.
2023: Rapid growth
2023 marked the real inflection point. Quishing jumped to roughly 12.4% of observed phishing attacks — a nearly ninefold increase from 2021 — with one industry analysis measuring a 587% year-over-year rise in quishing incidents specifically. Restaurant and retail menu spoofing (see our documented case file) became a widely reported pattern during this period alongside the parking meter attacks.
2024-2025: Evasion tactics evolve
As detection tools began specifically targeting QR-based phishing, attackers adapted. Security researchers documented "split" and "nested" QR codes — malicious payloads fragmented across multiple images or pages specifically to defeat both image-based and text-based detection simultaneously. Quishing rates stabilized around 10-11% of phishing attacks during this period, suggesting the tactic had reached a durable, ongoing place in attackers' toolkits rather than fading as a passing trend.
2026: State-linked actors and AI-paired follow-ups
In January 2026, the FBI issued a flash alert reporting that North Korean-affiliated actors were targeting think tanks, academic institutions, and U.S. government entities with quishing campaigns aimed at stealing session tokens and bypassing multi-factor authentication. Separately, attackers began pairing the initial QR scan with AI-generated follow-up messages nudging victims to "complete verification" — a more convincing, harder-to-distinguish second stage layered onto the original attack.
Every stage of this timeline shares one constant: quishing works by hiding a destination from both automated filters and human instinct simultaneously. That's exactly the gap a tool like CheckThisQR is built to close — see our guide to checking a QR code before you scan.