Quishing

A QR code does not tell you where you are going: that is why attackers like it.

Request a consultation

What it is

Quishing is phishing through QR codes. The code leads to a fake site or a malicious download. It shows up on stickers placed over real ones (parking meters, restaurants, charging stations) or in emails, where it bypasses filters that only read text.

How it works

  1. 1The attacker sticks a fake QR over a real one or puts it in an email or attachment.
  2. 2Whoever scans it opens a clone site asking for credentials or payment details.
  3. 3A personal phone is often less protected than a work one: the attack steps outside the company perimeter.

How to spot it

  • A sticker with a QR placed over another
  • An unexpected QR in an “urgent” email (access, payment, fine)
  • The link preview shows an odd domain
  • The site immediately asks for a login or a payment

How to defend

  • Read the address preview that appears before opening
  • Check whether a QR has been stuck over another
  • Do not enter credentials or payment details after an unexpected QR
  • For payments use official apps
  • In companies: do not accept QR codes in internal communications without verification

If you think you have been hit

  • Close the page and enter nothing else
  • If you entered credentials, change them and enable multi-factor authentication
  • If you paid, tell your bank at once

And there are many, many more

The attacks above are only some of the most common: there are hundreds, and new ones appear every week. If the one that concerns you is not among them, write to me: I will tell you whether it really affects you and how to defend.

Contact me

Other attacks

Watch the Shorts on YouTube

Matteo Russo · Updated October 2026

Let's talk
no strings attached

Want to know how exposed you are, train your team, or just ask a question? Write to me: I reply personally.

  1. You writeA couple of lines about your case: person, company, doubt or request.
  2. We talkA short intro call to understand what you really need.
  3. Practical defenseAssessment, consulting or training, with clear, prioritized actions.

Request a consultation

For security, the email address is not written on the page: press the button to reveal it and copy it in one click.

For companies and individuals. No scaremongering, just practical defense.