Abdolmadjid Masoomi

QR Code Scams (Quishing): Why a Sticker Beats Your Spam Filter

QR codes move a link out of screened channels and onto an unmanaged phone, often in the physical world.

Signed
Abdolmadjid Masoomi
Published
2026-09-14
Length
9 min read · 1,940 words
Status
opinion

Quishing exploits the blind spot between digital security and physical reality. By moving phishing links from screened email inboxes to unmanaged mobile cameras, attackers bypass traditional defences. The solution is not more software, but a shift to contextual verification and manual address entry.

QR code scams, or quishing, succeed because they relocate a phishing link from a screened channel to an unmanaged device. Email filters and browser extensions analyse text and URLs before a user sees them. A QR code contains no text until it is scanned. The security boundary shifts from the computer you trust to the phone in your hand.

This shift is not theoretical. Attackers place stickers over legitimate codes on parking meters, restaurant tables, and public transport validators. The victim scans the sticker, believing it to be the official payment gateway. The phone connects to a server controlled by the attacker. The link has bypassed every technical control designed to catch phishing attempts.

The practical defence is contextual rather than technical. You cannot rely on a spam filter to protect you in a car park. You must verify the physical context before interacting with the digital outcome. Never pay or log in through a code whose physical placement you cannot vouch for. Type known addresses instead. This simple behaviour change closes the gap that quishing exploits.

What a QR code actually hides

A QR code is a compact way to encode data, most often a URL. It does not contain executable code that runs on your device. It does not install malware directly. It simply directs your browser or app to a specific web address. The danger lies entirely in where that address leads and what the destination site asks for.

Scanning a code typically hands the link to your normal mobile browser, which retains its usual phishing warnings, rather than opening a restricted web view. The real risks are that the small screen makes the address easy to misread or truncate, some third-party scanner apps open links in their own limited view, and the frictionless flow encourages tapping through without checking.

The data inside the code can be manipulated in several ways. An attacker can generate a new code pointing to a malicious site. They can replace a legitimate code with a malicious one. They can even use dynamic QR codes, which point to a redirect whose destination can be altered at any time after printing, meaning a code that once led to a harmless page may now direct to a malicious one. The static nature of the printed image gives a false sense of permanence.

Understanding that a QR code is merely a pointer helps demystify the threat. It is not a virus. It is a shortcut. The risk comes from trusting the shortcut without checking the destination. This requires a different mindset than clicking a link in an email. In an email, you can hover to see the URL. With a QR code, you must rely on the device’s preview or your own memory of the legitimate address.

Why email filters miss it

Traditional email security focuses on content analysis and reputation. Filters scan the body text for known phishing keywords. They check the sender’s domain against blocklists. They analyse the URLs embedded in the message for malicious destinations. This system works well for text-based attacks. It fails when the attack vector is an image or a code.

A QR code is an image. Most email filters do not decode every image to extract hidden URLs. Even if they do, the URL inside the code may point to a legitimate-looking domain that has been recently compromised. Such a domain can carry a clean reputation due to its established history, whereas a brand-new domain may simply lack the history required for a filter to judge. The filter sees a valid certificate and a known provider. It allows the message through.

This is where bypassing traditional email security filters becomes relevant. Attackers know that technical controls are improving. They adapt by moving the payload to a medium that is harder to scan. The QR code is that medium. It moves the link out of the email body and into a separate action.

The email itself may contain no malicious text. It may look like a normal notification. The malicious element is the code. The user must take an active step to trigger the threat. This reduces the effectiveness of automated detection. The burden of verification shifts to the human. Humans are slower and less consistent than algorithms. This is the core advantage for the attacker.

Sticker-over-sticker attacks in public

The most common form of quishing in the physical world is the sticker overlay. An attacker prints a QR code on a small label. They place it directly over the official code on a parking meter, a bike rack, or a menu. The official code is still visible underneath, but it is covered.

This technique relies on speed and convenience. People want to pay quickly. They do not want to search for the original code. They assume the first code they see is the correct one. The attacker exploits this assumption. The sticker is often printed on glossy paper to mimic the original. It may even include fake branding or logos to look official.

The physical placement matters significantly in this context. A sticker on a public object is outside the control of the property owner. The owner cannot monitor every surface for tampering. This creates a blind spot in security. You are interacting with a device that has been physically altered. The digital trust model assumes the physical interface is authentic. That assumption is broken.

To defend against this, you must inspect the physical object. Look for edges of the sticker. Look for mismatched fonts or logos. Look for codes that are slightly raised or have adhesive residue. If the code looks new or out of place, do not scan it. This is a basic physical security check. It is often overlooked in digital security discussions, but it is the first line of defence.

Reading the URL preview properly

Modern smartphones often show a preview of the URL before opening it. This is a critical feature for security. It allows you to verify the destination without committing to the visit. You should always look at this preview. Do not just tap to open.

The preview may be truncated. It may not show the full path. It may hide the domain if the link is shortened. If the URL looks suspicious, stop. Do not proceed. If the domain does not match the expected service, abort. For example, a parking payment link should come from a known municipal or vendor domain. It should not come from a generic URL shortener or a random string of characters.

This practice connects to the contextual risks of mobile payment codes. Mobile browsers often have fewer extensions than desktop browsers. They may not have the same level of phishing protection. Relying on the OS-level preview is essential. It is the only check you have in many cases.

If the preview is not available, or if it is unclear, do not scan. This is a hard rule. The inconvenience of not scanning is far less than the cost of being phished. You can always ask for a receipt or use an alternative payment method. The goal is to avoid the unknown. Verification is not optional when the stakes are financial.

Safer ways to pay for parking and menus

The safest way to pay is to avoid the QR code entirely. Go to the official website or app. Type the address manually. This eliminates the risk of a malicious code. It ensures you are on the legitimate platform. It allows you to use the security features of the official site.

If you must use a code, verify the source. Ask the staff for the official code. Look for the code printed on the official receipt or terminal. Check the URL preview carefully. If you are unsure, use a different payment method. Cash is still valid in many places. Contactless cards are widely accepted.

This approach requires a shift in habit. It requires you to pause and think. It requires you to prioritise security over convenience. This is a necessary trade-off. The cost of a few extra seconds is far less than the cost of identity theft or financial loss.

The principle applies to all physical QR codes. Restaurant menus, event tickets, and public transport validators. In each case, the code is a shortcut. Shortcuts are risky if you do not know the destination. Verify the destination before you take the shortcut. This is a simple rule that works everywhere.

If you paid through a fake code

If you suspect you have paid through a fake code, act immediately. Contact your bank or card issuer. Report the transaction as fraudulent. They can often reverse the charge. This is the most effective step. Time is critical. The sooner you report it, the better the chance of recovery.

Change your passwords if you entered them. If you logged in to an account, change the password immediately. Enable two-factor authentication if you have not already. This prevents further access. Monitor your accounts for unusual activity. Look for small test transactions that attackers may use to verify the card.

This scenario highlights the importance of physical placement in security. The default assumption is that the physical interface is secure. When that assumption is violated, the consequences are severe. You must be prepared to respond. Knowing the steps in advance reduces panic and improves outcomes.

Do not ignore small charges. They may be a sign of a larger breach. Report them all. Keep records of your communications with the bank. This documentation may be needed for disputes. Stay vigilant for the next few months. Attackers may try to use stolen details later.

Questions people ask

Are qr code scams real and common?

Yes, they are real and increasingly common. Attackers use them because they bypass traditional email and web filters. They are particularly effective in public spaces where physical security is weak. The ease of creating a QR code makes them a low-effort, high-reward tool for fraudsters.

How to tell if a qr code is safe?

You cannot tell if a QR code is safe just by looking at it. You must verify the destination URL before opening it. Check the physical placement for signs of tampering. Use the official app or website instead of scanning a code. If the URL looks suspicious or is shortened, do not proceed.

What happens if you scan a malicious qr code?

Scanning a malicious QR code opens a link in your browser. This link may lead to a phishing site that steals your credentials. It may initiate a download of malware if your device allows it. It may redirect you to a payment page that charges your card. The immediate effect is usually just a webpage load, but the consequences can be severe.

Close

Quishing works because it exploits the gap between digital security and physical reality. Email filters protect your inbox. They do not protect your phone’s camera. Attackers know this. They use QR codes to move the threat out of the screened channel and into the physical world.

The defence is simple. It requires no new software. It requires no complex policies. It requires you to verify the physical context before you scan. If you cannot vouch for the placement, do not scan. Type the address manually. Use the official app. This small change in behaviour closes the gap.

Security is not just about technology. It is about behaviour. It is about understanding where the risks lie. In the age of QR codes, the risk is often physical. Stay aware. Verify everything. Protect yourself not with more tools, but with better habits.