Phishing that hides a malicious link inside a QR code, bypassing the usual URL scrutiny.
Quishing embeds a scam URL in a QR code printed on a flyer, sticker, email, or “onboarding” document. Because the destination is hidden until scanned — and often opens on a phone with less protection — victims skip the usual link check.
Preview the URL before opening it, and be wary of QR codes tied to payments or logins.
Red flags
- A QR code that leads to a login or payment page
- Codes on unsolicited mail or “hiring” documents
- A shortened or unfamiliar URL after scanning
Deep-dive guide
Quishing: QR-Code Job Scams and Why Codes Bypass Your Instincts
Frequently asked questions
Why are QR codes risky?
A QR code hides its destination until you scan it, so you can't eyeball the link first. Use a scanner that previews the full URL, and don't scan codes from unsolicited messages or documents.