QR Code Scams (‘Quishing’): How They Work and How to Stay Safe

QR codes have become a routine part of daily life — on restaurant menus, parking meters, posters and packaging — which is exactly what’s made them useful to criminals too. The UK’s National Cyber Security Centre (NCSC) has flagged a specific rise in “quishing,” a term combining QR code and phishing, as a growing scam tactic worth understanding.

What quishing actually is

According to NCSC guidance, QR codes are increasingly being used within phishing emails as a technique to disguise links to malicious websites. Rather than including a clickable text link — which email security filters and cautious users have become reasonably good at spotting — criminals embed the malicious destination inside a QR code image instead. Scanning it with a phone camera takes you to the same kind of fraudulent website a traditional phishing link would, but the QR code format makes the destination far less obvious at a glance, and can slip past some automated email security scanning that’s tuned to detect suspicious text links rather than image content.

Why NCSC is specifically flagging this now

NCSC guidance notes it is seeing an increase in this type of quishing attack, which reflects a broader pattern in cyber crime: as awareness and defences against one attack method improve, criminals adapt to newer formats that current protections aren’t yet tuned to catch. QR codes sit in a particularly useful gap for attackers, since most people are now comfortable scanning them without a second thought, given how normalised the format has become in everyday, legitimate use.

The everyday context matters

It’s worth being precise about where the actual risk sits, since blanket “avoid all QR codes” advice isn’t practical or what NCSC guidance actually says. QR codes are usually safe to use in physical, everyday contexts like pubs and restaurants, where the code is printed on a physical menu or table and the risk of tampering is generally low. The caution NCSC guidance specifically recommends is around QR codes received within emails, where a link’s true destination is harder to verify and the delivery context (an unsolicited or slightly unexpected email) is itself a red flag independent of the QR code format.

Practical steps NCSC recommends

  • Be wary of QR codes in emails, particularly unsolicited ones or those creating a sense of urgency (a “verify your account” or “package delivery” theme is common in phishing generally, including quishing variants).
  • Use your phone’s built-in QR scanner rather than a separate app downloaded from an app store, since NCSC guidance specifically recommends this — third-party scanner apps introduce an additional layer of trust and potential risk beyond the QR code itself.
  • Check the preview URL before tapping through — most modern phone cameras show a preview of the destination link before opening it in a browser; take a moment to read it rather than tapping immediately.
  • Treat a scanned QR code link with the same scepticism you’d apply to a text link — if it asks for login details, payment information or personal data unexpectedly, that’s a reason to stop and verify independently rather than proceed.

If you’ve already scanned a suspicious code

If you’ve scanned a QR code and entered details on the resulting page, or downloaded something from it, treat it the same way you would a phishing link you clicked in error: change the password on any account where you entered details, monitor relevant financial accounts for unusual activity, and report the phishing email to the NCSC via their reporting service if it arrived by email.

A familiar scam in a newer format

Quishing isn’t a fundamentally new type of fraud — the underlying goal (tricking you into visiting a malicious website and entering details) is identical to traditional phishing. What’s changed is the delivery mechanism, and NCSC guidance is essentially a reminder to extend existing phishing caution to a format that many people haven’t yet learned to be sceptical of.

Where else quishing shows up beyond email

While NCSC’s specific guidance focuses on QR codes embedded in phishing emails, the same underlying tactic has been reported in physical settings too — fraudulent QR code stickers placed over genuine ones on parking meters, event posters or public noticeboards, redirecting a scan intended for a legitimate service toward a fraudulent payment page instead. The general caution NCSC recommends for email-based QR codes applies equally here: checking the previewed destination URL before proceeding, and being suspicious of a QR code that looks physically tampered with, stuck over another code, or positioned somewhere slightly unusual for the context.

A useful general habit is treating any QR code presented in an unexpected or unsolicited context — an email you weren’t expecting, a sticker that looks added rather than originally printed, a code handed out by someone you don’t know — with the same scepticism you’d apply to an unsolicited link sent by text or email. Where a QR code is genuinely needed for a payment (topping up a parking meter, for instance), using the official app or website for that service directly, rather than scanning a physical code you can’t fully verify, avoids the risk altogether.

Sources