What it is
Quishing is phishing through QR codes. The code leads to a fake site or a malicious download. It shows up on stickers placed over real ones (parking meters, restaurants, charging stations) or in emails, where it bypasses filters that only read text.
How it works
- 1The attacker sticks a fake QR over a real one or puts it in an email or attachment.
- 2Whoever scans it opens a clone site asking for credentials or payment details.
- 3A personal phone is often less protected than a work one: the attack steps outside the company perimeter.
How to spot it
- A sticker with a QR placed over another
- An unexpected QR in an “urgent” email (access, payment, fine)
- The link preview shows an odd domain
- The site immediately asks for a login or a payment
How to defend
- Read the address preview that appears before opening
- Check whether a QR has been stuck over another
- Do not enter credentials or payment details after an unexpected QR
- For payments use official apps
- In companies: do not accept QR codes in internal communications without verification
If you think you have been hit
- Close the page and enter nothing else
- If you entered credentials, change them and enable multi-factor authentication
- If you paid, tell your bank at once
And there are many, many more
The attacks above are only some of the most common: there are hundreds, and new ones appear every week. If the one that concerns you is not among them, write to me: I will tell you whether it really affects you and how to defend.
Contact meOther attacks
Watch the Shorts on YouTubeMatteo Russo · Updated October 2026