A phishing tactic that works even offline
What makes quishing distinctive is that it doesn't rely on a text message or email. It shows up on posters, table stickers, and flyers in the physical world. Because a QR code can't be checked for authenticity just by looking at it, the habit of checking the destination link after scanning becomes even more important.
Similar tricks to text-message phishing, different delivery
Like SMS phishing scams that use a text link, quishing often relies on manufactured urgency or impersonating a familiar service. The key difference is simply that the code is placed somewhere in the physical world rather than sent to your phone.
Frequently Asked Questions
Is it dangerous just to scan a QR code?
Simply scanning a code with your camera to preview the address is generally safe. The risk comes from actually visiting that address, installing an app, or entering information as instructed.
I already visited a suspicious QR code link and entered information, what should I do?
Change the password for any account you entered immediately, and if you entered payment details, contact your card issuer or bank to review recent transactions. If you installed a malicious app, uninstall it and run a security scan.