Protection Tools

How to Spot a Quishing QR Code Scam Before You Scan It in 2026

QR codes on parking meters, restaurant tables, and delivery flyers are being hijacked with sticker overlays. Here's how the scam works and how to check a code safely.

📅 Aug 3, 2026·⏱️ 5 min read·✍️ Cikal Studio Labs
🔳

What Is Quishing?

"Quishing" is QR-code phishing: a scammer prints a fake QR code sticker and places it directly over a real one — on a parking meter, a restaurant table tent, a package "redelivery" flyer, or even a fake parking ticket left on a windshield. Because a QR code is unreadable to the naked eye, you have no way of knowing where it actually leads until you scan it and your phone opens the link. By then, you may already be on a convincing fake payment page.

Why QR Codes Are Such an Effective Attack Surface

Traditional phishing training focuses on suspicious email links and text messages, but most people have never been warned about QR codes specifically. A sticker over a parking meter QR code looks completely normal — there's no broken padlock icon, no obviously misspelled sender, nothing that visually signals danger. The attack relies entirely on the gap between what you can see (a black-and-white square) and what it actually encodes (a URL you cannot preview).

Common Quishing Scenarios

  • Fake parking fines: a code stuck to your windshield claims you owe a fee, with a QR code to "pay now."
  • Restaurant table scams: a sticker over the real menu/payment QR code redirects to a fake payment collector.
  • Fake package redelivery: a flyer left at your door asks you to scan a code to reschedule delivery, landing on a phishing page that harvests your card details.
  • Public charging stations and posters: codes offering "free Wi-Fi" or a discount that actually lead to malware downloads or credential-harvesting pages.

Red Flags a Decoded QR Link Might Reveal

Once a QR code is decoded, it behaves just like any other link, and the same URL red flags apply:

  1. Raw IP addresses instead of a real domain name — legitimate businesses essentially never link directly to an IP.
  2. URL shorteners (bit.ly, tinyurl.com, etc.) that hide the real destination until after you click.
  3. Throwaway top-level domains like .top, .xyz, or .click, which are cheap and heavily abused for short-lived scam pages.
  4. Brand-lookalike domains using character substitution, like paypa1.com instead of paypal.com.
  5. Payment demands — parking fines, tolls, or "redelivery fees" requested through the link.
  6. Urgency language printed on the sign or flyer itself, pressuring you to scan and pay immediately.

How to Check a QR Code Safely

Before scanning any QR code in a public place, especially one attached with a sticker rather than printed directly onto a sign, take a moment to inspect it. If you've already scanned it and see a preview link on your phone (most modern phones show the URL before opening it), stop and check that URL manually rather than tapping through. If you have a photo of the QR code, you can decode and analyze it entirely offline before ever visiting the link.

What to Do If You Already Scanned a Bad Code

If you entered payment information on a page you now suspect was fake, contact your card issuer immediately to dispute the charge and consider requesting a new card number. If you entered login credentials, change that password immediately, and enable two-factor authentication if you haven't already. Report the physical sticker to the property owner (parking authority, restaurant, delivery company) so they can remove it.

The Bottom Line

QR codes aren't inherently dangerous, but the fact that they're unreadable to humans makes them a uniquely convenient way to disguise a malicious link in a physical, trusted-looking location. Treat an unexpected QR code — especially one attached with a sticker — with the same skepticism you'd apply to an unsolicited text message link, and check the decoded destination before you act on it.

Frequently Asked Questions

What exactly is a "quishing" scam?

Quishing is QR-code phishing — scammers place a fake QR code sticker over a legitimate one (on parking meters, restaurant tables, or delivery flyers) so scanning it takes you to a malicious site instead of the real destination.

Do I need to install an app to check a QR code?

No. The QR Code Quishing Scam Detector decodes the image directly in your browser using an embedded offline QR reader — no app, account, or internet connection required after you load the page.

Is there a tool that can check a QR code for scams before I scan it with my phone?

Yes — the QR Code Quishing Scam Detector lets you upload a photo of the code (or paste an already-decoded link) and scores it for phishing red flags like raw IPs, shorteners, and lookalike domains. It's a one-time $5.99 purchase — no subscription, no account required.

What if I don't have a photo of the QR code, only the link it opened?

You can switch to the "Paste Decoded Link" tab and enter the URL or text directly — the same heuristic scoring runs either way.

Can this tool guarantee a link is 100% safe?

No automated heuristic tool can guarantee complete safety. It flags known scam patterns to help you make a more informed decision, but you should still avoid entering payment or login details on any site you don't fully trust.