Security

Stop the "quishing" threat: how to keep your brand's QR codes secure

QR phishing can hide a harmful destination behind a familiar pattern. Use these practical checks for printed codes, destinations, and incident response.

Daniel··8 min read

How QR phishing works

"Quishing" means phishing delivered through a QR code. The code may appear in an email or message, or a fraudulent sticker may cover a legitimate code in a public place. The destination can imitate a real site and ask for login, payment, or personal information.

The FTC has received reports of scammers covering legitimate QR codes on parking meters. Its guidance says people should inspect the previewed URL for misspellings or switched letters and avoid unexpected QR codes that create urgency. Businesses can make that check easier by printing the expected domain beside the code.

Why QR codes are an attractive attack vector

A QR code hides the full destination until it is scanned. On a small screen, a lookalike domain or unexpected path can be easy to miss, especially when a sign or message creates urgency.

Additionally, the small preview URL that appears in a scan dialog is easy to disguise. A URL like qrt4cer.io/r/abc123 (note the substituted character) looks nearly identical to a legitimate redirect at a casual glance, especially on a small phone screen in a busy environment.

Physical context can also create trust. A code attached to a table, sign, or payment point may look official even when a sticker has been placed over the original.

Security involves the printed placement, the destination website, account access, and a clear owner. A managed redirect helps with inventory and destination changes, but it does not prevent someone from covering the printed code. Start with our QR code generator to see how managed codes work.

Managed QR codes provide several security properties that unmanaged static codes cannot:

  • Inventory: Keep each managed code, destination, placement, and owner in one account.
  • Redirect control: An authorised owner can change the destination of the legitimate dynamic code or disable it. A malicious overlay still requires physical removal.
  • Scan review: Scan reports can help prioritise investigation, but location estimates are not proof of fraud and should not be treated as automatic threat detection.
  • Account protection: Protect the email account and credentials used to administer QR destinations, and remove access when responsibilities change.

One dashboard, one source of truth

By centralising your codes in one dashboard, you create a "single source of truth" for your QR infrastructure. Your IT and marketing teams can audit every active link in the company at any moment. You can see which codes are live, what they point to, when they were last scanned, and from which locations.

Record the physical placement as well as the dashboard entry. A dashboard cannot tell you whether a sticker has covered the original code, so scheduled physical checks remain necessary.

Practical steps to protect your codes today

Regardless of which platform you use, there are baseline practices that reduce your exposure:

  1. Display the expected destination URL near the code. A printed line that says "Scan to visit example.com/menu" gives users a reference point to detect tampering.
  2. Use tamper-evident labels on codes deployed in high-traffic public spaces. These show visible damage if a sticker is placed over them.
  3. Set an inspection schedule based on exposure. Public payment points need more frequent checks than codes inside controlled premises.
  4. Review scan reports as context. Unexpected changes can prompt an inspection, but approximate geography alone does not establish compromise.
  5. Separate overlay response from account response. Remove or cover a malicious physical sticker; change or disable the legitimate dynamic destination only when that destination or account is also at risk.

Create a QR code for your link

Frequently asked questions

What is quishing?

Quishing is phishing delivered through a QR code. The code can lead to an impersonation site that requests credentials or payment details. In physical locations, a fraudulent sticker may cover a legitimate code.

How can I protect my business QR codes from being tampered with?

Keep an inventory of deployed codes and owners, print the expected domain beside each code, inspect public placements for overlays, use tamper-evident materials where appropriate, and provide a trusted reporting route.

How quickly can I disable a compromised QR code?

An authorised owner can change or disable a dynamic code through the provider's controls. That protects the legitimate code, but it cannot disable a separate malicious sticker placed over it; the overlay must be removed physically.