🌙

SajiloQR

Guides & Tutorials

QR Code Scams and Quishing

QR codes have a built-in trust problem: the pattern hides its destination until you scan it. You see a small square, but you can't tell whether it opens a menu, a payment page, or a fake login form designed to steal your password. Criminals have noticed, and QR-based phishing — nicknamed "quishing" — is now a routine tactic. The good news is that the defences are simple and don't require you to distrust every code you see.

How QR phishing actually works

The classic attack is physical tampering. A scammer prints a malicious QR code on a sticker and places it over a legitimate code — on a parking meter, a restaurant table, a poster, a package. When you scan, the code opens a convincing fake page: a payment screen for a parking fine, a login for your email, a survey that "rewards" you. Enter your details and they're captured.

The digital version arrives in email. A message that looks like it's from your bank, your courier, or your boss contains a QR code you're urged to scan — perhaps because "the link is blocked". Scanning moves the action from a computer to a phone, which bypasses many corporate security filters and, conveniently for the attacker, out of sight of trained email users.

Why do these work? Because scanning a code is a habit now. People tap "Open" almost reflexively, never glancing at the address that appears. The entire scam depends on that reflex — which means one small pause defeats it.

Preview the link before you open it

When a phone scans a QR code that points to a website, it shows a preview: the URL and the message "Open in browser?" in most camera apps. This preview is your checkpoint. Before tapping open:

SajiloQR's scanner makes this even easier: it shows you the decoded text before you decide whether to open anything, so a URL is visible in full rather than hidden behind a camera-app preview.

Look for tampering

Physical codes deserve a two-second inspection before scanning:

Email and messaging codes

Business owners: protect your own codes

If you run a venue, a shop, or anything with printed codes, you have a stake in this too. A customer scammed through a code in your business is bad for them and worse for your reputation:

What to do if you think you've been scammed

The balanced view

None of this means QR codes are dangerous. They're a hugely useful technology — and they're also just text in a box. The safety rule is the same one that applies to every link on the internet: look before you open. Scan, read the destination, then decide. A single second of attention removes almost all the risk.

For a hands-on look at what a code actually contains, scan one with SajiloQR's scanner — it shows you the decoded text first, no page-opening required. If you'd like to understand the technology these scams rely on, see how QR codes work.