Quishing (a blend of "QR" and "phishing") is a scam where a malicious link is hidden inside a QR code instead of being sent as plain text. When you scan the code, your phone's browser opens the hidden link automatically — often before you've had any real chance to check where it leads.

It works the same way traditional phishing does: a fake login page, a bogus payment form, or a page that quietly downloads malware. The difference is entirely in the delivery method, and that difference is exactly why it's spreading.

Why quishing is growing so fast

Most email security tools are built to scan text for suspicious links. A QR code is just a picture — the malicious URL is encoded as a pattern of black and white squares, not as readable text, so many automated filters simply don't see it. That lets quishing slip past defenses that would catch an ordinary phishing email in seconds.

It also exploits a habit gap. People have spent years learning to hover over links and check sender addresses before clicking — but scanning a QR code feels more like a physical action, similar to using a menu or tapping a poster, so that same instinct to pause rarely kicks in.

Worth knowing

A QR code that looks perfectly normal can point anywhere. There's no visual way to tell a safe destination from a malicious one just by looking at the pattern itself — the only way to know is to check the link it actually contains.

Where quishing shows up

How to protect yourself

The core defense is simple: never let a QR code take you somewhere before you know where that is. A few habits go a long way:

Next step

See real examples of how these attacks have actually played out in our QR code scam examples guide, or jump straight to how to check a QR code before scanning it.