A surge in ‘quishing’ attacks sees QR codes on public posters and emails transformed into vectors for fraud, prompting urgent calls for caution amidst rising threats that can bypass traditional security measures.
QR code scams are no longer a nuisance limited to cautious tech users. They now sit at the intersection of convenience and fraud, turning everyday actions such as paying for parking, opening a menu or checking a parcel into a potential trap. The danger is simple: the code you scan may not belong to the business you think it does.
That is why “quishing”, the blend of QR code and phishing, has become a growing problem. Security researchers and consumer warnings alike describe the same basic trick: a code hides a malicious web address until after it is scanned, making it hard to judge whether the destination is safe before you are already on the way there. The result can be a fake payment page, a credential-stealing login screen or malware delivered to a phone.
The threat is especially effective in public places. Parking metres, restaurant tables, transit posters and shipping labels are all easy places for attackers to place a fake sticker over a genuine code or distribute a deceptive one through email and SMS. Security.org says these settings are common because people tend to trust the context and scan quickly without checking the destination first.
Recent reporting suggests the volume is rising sharply. Kaspersky said detections of QR code phishing jumped from 46,969 in August 2025 to 249,723 in November 2025, a fivefold increase in just a few months. The company said attackers were increasingly hiding malicious links inside emails and PDF attachments, taking advantage of the fact that many security tools focus on text rather than images.
That shift matters because QR codes are often opened on personal phones rather than protected work computers. Kaspersky and other security researchers note that this gives attackers a better chance of slipping past enterprise controls. Once the scan opens a convincing replica of a bank, courier or payment page, the victim can be asked to enter card data, passwords or one-time codes.
The scam is not limited to websites. QR codes can also launch Wi-Fi connections, prefilled messages, app links, calendar invites or payment instructions, which widens the attack surface. In more advanced cases, criminals use relay techniques that pass a one-time code to a real site in seconds, allowing them to hijack a session even when two-factor authentication is in place.
The safest approach is still the least glamorous one: pause before scanning, inspect the sticker or poster, and read the domain before tapping through. If a code arrives in an unsolicited email, a parcel or a text message, treat it as suspicious. For payments, it is better to open the official app or website yourself than to trust a code printed on a surface you did not control.
If you do scan something suspicious, act fast. Freeze the card, change passwords from a clean device, sign out of other sessions and check for unfamiliar apps or settings changes. If the code was on public property, alert the venue or local authority. The longer a scam goes unchecked, the more time attackers have to spend the money or lock in access.
Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.





