What Is Quishing? How QR Code Phishing Scams Work (2026)

Reviewed by IT Cares certified technicians · Updated August 2026

Fake QR code sticker placed over a real parking payment sign — an example of a quishing (QR code phishing) scam
A sticker with a fake QR code placed directly over a real parking payment sign is one of the most common quishing setups — it looks completely routine until you check where it actually leads.
📱
Already scanned a suspicious QR code and not sure what happened next? Our certified technicians can look at your phone remotely and tell you plainly whether anything was actually installed or accessed.
Get Help Now →

Quishing is QR code phishing — fraudulent QR codes designed to redirect your phone to a fake website that steals your login credentials, payment details, or personal information, or in some cases prompts you to install malware. The name blends "QR code" and "phishing," and like every other phishing variant, it borrows the same con: create a routine, believable premise, and get you to act before you think to verify it. What makes quishing distinct — and, in a lot of ways, more dangerous than email or text phishing — is that a QR code is opaque by design. You cannot read where it leads just by looking at it, the way you can at least glance at a link in an email or a text.

Quishing has spread quickly because QR codes themselves went from a niche curiosity to a genuinely normal part of everyday life in just a few years — restaurant menus, parking payments, event check-ins, delivery slips, and public transit all lean on them now. Every one of those legitimate use cases gives a scammer a plausible cover story, and a small printed sticker is all it takes to hijack one.

This guide covers exactly how quishing works, why it slips past defenses people already trust, the specific scam formats showing up across Canada right now, real-world case studies, how quishing compares to email phishing and smishing, safe scanning habits, and what businesses should do to protect customers and staff from QR-based attacks on their own premises. For the email-based version of this same threat, see our what is phishing guide; for the text-message version, see our what is smishing guide.

Who wrote this guide

This article was written and reviewed by IT Cares certified technicians based on the recurring calls we field from clients who scanned a QR code in a parking lot, at a restaurant, or on a delivery notice and later realized something felt off. Quishing has grown fast precisely because so few people apply the same scrutiny to a printed code that they've started to apply to suspicious links and texts — this guide exists to close that gap.

How Quishing Actually Works

A QR code is nothing more than a visual encoding of data — most often a URL — that a camera decodes into something your phone can act on. There's no inherent security check baked into that process; the code itself has no way of proving who created it or where it genuinely leads. That single fact is the entire foundation of quishing.

The physical swap

The most common method requires no technical skill at all: a scammer prints a sticker with a malicious QR code and places it directly over a legitimate one, on a parking meter, a menu, a poster, or a payment terminal. It takes seconds, needs no special equipment beyond a home printer, and in an unsupervised public location it can go unnoticed for hours, days, or longer.

The fabricated notice

Instead of covering a real code, some scams fabricate an entire fake notice from scratch — a printed "parking violation" slip left on a windshield, a "delivery attempted" door hanger, or a flyer posted in a building lobby — with a malicious QR code built in as the primary call to action from the start.

The digital version

Quishing isn't limited to physical stickers. Malicious QR codes increasingly show up embedded in emails and PDFs too, specifically because QR codes bypass some traditional email security filters that scan for suspicious text-based links but don't always analyze an embedded image the same way. An employee who wouldn't click a suspicious link in an email will sometimes scan the exact same destination without a second thought when it's presented as a QR code instead.

What happens after the scan

Once scanned, the code typically leads to one of a few outcomes: a fake login page built to harvest credentials, a fake payment page built to capture card details, a page prompting an app install that turns out to be malware, or occasionally a page that simply confirms your phone number or email is active, feeding future scam attempts. The specific destination varies, but the mechanism is always the same — the QR code is just the delivery vehicle for a link you didn't get to see in advance.

📊 IT Cares field note: Almost every quishing case we've cleaned up afterward started with some version of "it was just sitting there on the meter/table/door, why would I think to check it?" That instinct is exactly right for a real QR code and exactly wrong for a swapped one — and there's no visual difference between the two until you actually read the URL preview.

Worried you've already scanned a malicious QR code?

Our certified technicians can check your phone or computer remotely and tell you honestly whether anything was compromised — no upsell, from $119.99.

8 Real Quishing Scenarios You'll Probably Recognize

These are the specific QR-code scam formats showing up repeatedly. Descriptions are kept generic rather than naming specific companies or agencies, since scammers borrow whichever brand or authority happens to be believable in a given region — the tactic stays identical regardless of which name is being used.

1. The fake parking payment or parking fine QR code

A sticker reading "Scan to pay for parking" or "Unpaid parking violation — pay to avoid penalty" is placed on a meter, a windshield notice, or a posted sign. This has become one of the most reported quishing formats in North American cities, precisely because paying for parking by QR code is now a genuinely normal, legitimate practice in many municipalities.

Red flags: A sticker that looks slightly different in print quality, size, or placement compared to the surrounding official signage; a payment page that doesn't match the municipality's or parking operator's known branding; a generic reference number instead of your actual license plate or space number.

2. The fake package delivery notice

A QR code appears on a door-hanger slip, in a text, or on an email claiming a delivery attempt failed, directing you to scan to "reschedule" or "confirm your address," leading to a fake page that harvests personal or payment information.

Red flags: No tracking or order number that matches something you actually ordered; a request for payment to redeliver a package, which legitimate carriers essentially never do by QR code; a notice left in a location a real carrier wouldn't typically use, like a community mailbox rather than your specific door.

3. The fake restaurant menu QR code

A sticker replacing or overlaying the real QR code on a table tent or menu leads to a fake ordering or payment page instead of the restaurant's actual digital menu, sometimes harvesting card details under the pretext of prepaying an order.

Red flags: A visibly different sticker material or placement compared to other tables; a page asking for full payment card details before showing any menu at all, which is unusual for a browse-first digital menu; a URL that doesn't match the restaurant's actual name or domain.

4. The fake event ticket or check-in QR code

A QR code shared for event check-in, a raffle entry, or a "scan to win" promotion at a public event leads to a page collecting personal information or payment details under the pretext of confirming entry or claiming a prize.

Red flags: Excessive urgency ("scan now, limited spots"); a request for payment card details to "confirm" a free entry or prize; a code posted loosely on a wall or table rather than distributed directly by event staff.

5. The fake utility or government notice QR code

A printed notice, sometimes left at a door or posted publicly, claims a utility shutoff, a government benefit, or an unpaid fee, with a QR code to "resolve" the issue immediately by scanning and providing banking or personal details.

Red flags: Utility and government agencies in Canada generally don't resolve account or payment issues through an unsolicited QR-code notice; threats of imminent shutoff or legal action within an unusually short window; a request for banking details to "avoid" a problem rather than a direction to the agency's own known website or phone line.

6. The fake charity donation QR code

A QR code posted at an event, in a public space, or shared after a real disaster or crisis in the news solicits donations, leading to a fake payment page that captures card details without any donation actually reaching a real charity.

Red flags: No verifiable charity name or registration number provided; pressure tied to a very recent news event, designed to exploit genuine urgency before people have time to verify the organization; a code posted without any accompanying official signage or staff presence.

7. The fake public Wi-Fi or transit QR code

A code posted in a transit station, airport, or public space claims to provide free Wi-Fi access or a transit fare top-up, leading either to a credential-harvesting captive portal or a fake payment page for fare loading.

Red flags: A request for a full email and password combination just to access "free" Wi-Fi, when legitimate public Wi-Fi portals rarely require a real account login; a fare top-up page that doesn't match the transit authority's actual app or website branding.

8. The QR code embedded in a phishing email or PDF

Instead of a clickable text link, a phishing email or attached PDF includes a QR code as the main call to action — "scan to verify your account" or "scan to view your invoice" — specifically because this format can slip past email security filters that scan visible link text but don't always fully analyze an embedded image.

Red flags: Any unsolicited email or PDF asking you to scan a code rather than simply click a link, which itself is unusual outside of specific legitimate use cases like boarding passes; the same urgency and credential-harvesting patterns as classic email phishing, just delivered through an image instead of text.

Quishing vs Smishing vs Classic Phishing: What's Actually Different

The underlying goal is identical across all three — trick you into handing over information or installing something malicious — but the delivery channel changes how easy the scam is to spot before any damage happens. Quishing consistently comes out as the hardest to inspect in advance, which is exactly why it's spreading.

FactorQuishing (QR code)Smishing (SMS)Classic email phishing
Destination visibility before acting None at all until scanned — the code hides the URL completely Partial — a link is visible in the text but often shortened Best — a sender domain and full link are usually visible
Typical setting Physical, real-world locations — parking, menus, notices, posters Digital, on your phone's messaging app Digital, in your email inbox
Filtering / automated detection Little to none — most security tools don't fully analyze embedded QR images Little to no equivalent of a spam folder most people check Spam filters and link-scanning catch a large share automatically
Tampering method A physical sticker placed over a real code, or a fabricated notice Sender ID spoofing on a text message Spoofed sender address or lookalike domain
Common bait Parking, delivery, menus, event check-in, utility notices Delivery notices, bank alerts, 2FA codes, tolls Invoices, password resets, shared documents, urgent account notices

The practical takeaway is that a QR code deserves at least as much scrutiny as a link in an email or text — arguably more, since it's the one format that gives you zero information about its destination until after you've already taken the first action. Treating every QR code as an unverified link, rather than a trusted shortcut, is the single biggest mindset shift that closes this gap.

Three Canadian Case Studies

The following case studies are composite, illustrative scenarios built from patterns common to Canadian quishing incidents in 2026 — names and identifying details are fictional, but the mechanics and outcomes reflect realistic cases.

Case 1 — A downtown Ottawa parking lot, individual commuter

A commuter parked in a municipal lot and scanned a "Scan to pay for parking" sticker on the meter, exactly as she'd done dozens of times before. The resulting page looked convincing, but before entering her card details, she noticed the URL preview showed a domain with an unfamiliar extension rather than the city's known parking portal. She backed out, called the city's parking line directly, and paid through the official app instead. The sticker was reported and later confirmed as a tampering scam affecting several meters in the same block. Cost: the two minutes spent checking the URL preview.

Case 2 — A restaurant in Kitchener, Ontario (small independent business)

A regular customer scanned the table QR code expecting the usual digital menu and instead landed on a page asking for full payment card details before showing any food items — unusual, since the restaurant's real ordering flow always let customers browse first. He mentioned it to staff, who checked the table tent and found a thin sticker layered directly over the restaurant's real code. The restaurant removed and replaced all table codes with tamper-evident holographic stickers the same week and began a weekly physical check as a standing policy. Financial loss: $0 for this customer, though staff couldn't rule out that other tables may have been affected earlier that week.

Case 3 — A small logistics company in Surrey, British Columbia (11 employees)

An employee received what looked like an internal IT email asking staff to scan a QR code to "re-verify" their Microsoft 365 login ahead of a claimed security update — a request that would have looked exactly like a normal phishing email, except it used a QR code instead of a clickable link, which slipped past the company's email security filter that scanned text-based links but not embedded images. The employee scanned it on her phone rather than her work computer, entered her credentials on the fake page, and the attacker used them to access the company's email system within the hour, sending further scam requests to two vendors before IT caught the unusual login location and forced a password reset. No funds were transferred, but the company spent roughly $2,800 CAD on incident response and adopted QR-code-aware email filtering afterward.

Safe QR Code Scanning: The Checklist

These habits work regardless of whether the code is on a parking meter, a menu, an email, or a poster — the response is the same no matter where the code physically or digitally appears.

Safe QR Scanning Habits Checklist

  • Look closely at the sticker or code itself for signs of tampering — misalignment, a different material, or visible edges over an existing sign.
  • Always read the URL preview your phone shows before tapping through to open the page.
  • Never enter payment card details or a login password on a page reached through a QR code without verifying the domain first.
  • Be extra cautious with codes in unsupervised public locations — parking meters, utility poles, bulletin boards, unattended tables.
  • Use your phone's built-in camera app rather than a random third-party QR scanner app.
  • Treat an urgent payment demand tied to a QR code (parking, toll, utility, delivery fee) as unverified until checked through the agency's own known website or number.
  • If a restaurant or business's code looks physically different from what you remember, ask a staff member to confirm it before scanning.
  • Never scan a QR code embedded in an unsolicited email or PDF asking you to "verify" an account — treat it exactly like a suspicious link.
  • If you scan something and land on an unexpected page, simply close it — viewing a page without entering information generally causes no damage on its own.
  • Report a suspicious sticker or notice to the property owner, municipality, or business on-site so it can be checked and removed for others.

What to Do If You've Already Scanned a Suspicious Code

If you've already scanned a quishing code, the priority shifts from prevention to damage control — and how much damage control depends heavily on what happened after the scan.

If a page prompted you to install something

Disconnect the device from Wi-Fi and mobile data immediately if you're unsure whether an install completed or is still running. This limits any app or malicious profile's ability to communicate out while you assess the situation. Then, without reconnecting to the internet, check your list of installed apps and, on Android, your device admin or accessibility permissions for anything unfamiliar.

If a page loaded but you didn't enter anything

Close the page and don't enter any information into it, even out of curiosity. Simply viewing a well-built phishing page without submitting anything generally causes no damage on its own.

If you did enter information

Change the relevant passwords immediately — from a different, clean device rather than the one that may have been exposed. Prioritize email and banking passwords first, since those typically unlock everything else. Enable two-factor authentication anywhere you haven't already, using our two-factor authentication setup guide if you need a walkthrough.

Monitor your accounts closely afterward

Check bank and credit card statements for unrecognized charges over the following weeks, and consider a credit monitoring alert if you entered sensitive personal information. Our identity theft recovery guide walks through the fuller recovery process if information beyond a single password was exposed.

Not sure what actually happened after you scanned?

If you scanned a suspicious QR code and you're not confident about what — if anything — was installed or accessed, IT Cares can check your device remotely and give you a straight answer rather than leaving you to guess.

The Business Angle: Protecting Customers and Employees

For businesses that use QR codes at all — restaurants, parking operators, retail, events, and any office running QR-based check-ins or Wi-Fi access — quishing isn't just a customer-facing risk. It's also a real threat to employees, since an attacker who compromises one login through a quishing email can pivot into the wider business network exactly the way Case 3 above played out.

For customer-facing QR codes

Physically inspect posted QR codes on a regular schedule — table tents, meters, posters, and signage — checking for stickers, overlays, or anything that looks like it doesn't match the original printing. Where practical, use tamper-evident materials such as holographic stickers or codes printed directly into laminated signage rather than easily removable adhesive labels. Consider adding a short, visible statement near the code reminding customers that your business never asks for full payment details before showing a menu or confirming an order, which gives customers a concrete reason to pause if a scanned page doesn't match that expectation.

For employee-facing risk

Extend existing phishing-awareness training to explicitly cover QR codes, since many staff who've been trained to distrust suspicious email links have never been told to apply the same scrutiny to a scanned code. Configure email security filtering to analyze embedded QR images where the platform supports it, rather than relying solely on text-based link scanning. Reinforce the same out-of-band verification habit used for email and text requests: any QR code asking for a login, payment, or sensitive action tied to a work account should be verified through a known channel before acting, regardless of how official the surrounding email or document looks.

📊 IT Cares field note: The businesses we've seen handle this best don't try to eliminate QR codes entirely — they just treat the physical code the way a careful IT team treats a link: assume it can be tampered with, check it periodically, and make it easy for both customers and staff to report something that looks off.

Budget: Prevention Cost vs. the Cost of a Real Incident

Framing this as a budget decision rather than an abstract security concern tends to make the case clearer for a small or medium Canadian business, so here's the comparison in real dollars.

ItemTypical cost range (CAD)Notes
Tamper-evident QR stickers, per location $50 – $300 One-time reprint of table tents, meter signage, or posted codes with tamper-evident materials
Staff QR-code phishing awareness add-on training $15 – $40 per employee/year Extension of existing phishing training to explicitly cover quishing scenarios
Email security review with QR/image-link scanning $119.99 – $600 One-time assessment and filtering configuration for a small business
Regular physical code-inspection routine Effectively $0 A five-minute weekly check by existing staff, added to an opening or closing routine
Single successful quishing-driven credential compromise or fraud incident $1,000 – $50,000+ Typical range for a Canadian SMB, depending on what the compromised account led to

Even generously priced, tamper-evident signage plus a short annual training refresh for a small team lands well under a few hundred dollars a year for most businesses. Set against even the low end of a single credential-compromise incident, the math is straightforward — the prevention cost is small enough to be a rounding error next to the incident it's meant to avoid. If you want a straight, no-pressure read on where your business's email security and QR-related exposure actually stands, our cybersecurity services for Canadian businesses cover exactly this kind of review.

Frequently Asked Questions

Can scanning a QR code alone infect my phone, without me tapping anything else?
On a modern, updated phone, simply scanning a QR code with your camera app is very unlikely to install anything by itself — the camera just decodes the code into a URL and shows you a preview before you choose to open it. The real risk begins when you tap through to that link and either enter information on a fake page or are prompted to install something. Keeping your phone's operating system current still matters, since rare exploits that require no interaction beyond a scan have existed for other technologies in the past and get patched through updates.
How do scammers actually swap out a real QR code for a fake one?
Almost always with a simple adhesive sticker printed with a malicious QR code, placed directly over the legitimate one on a parking meter, menu, poster, or payment terminal. It requires no technical skill and can be done in seconds in a public location with no supervision. Some more targeted cases involve printing entirely fake signage, menus, or flyers with a malicious code built in from the start, rather than covering an existing real one.
Are QR codes on restaurant menus generally safe?
Most are, since they're typically printed directly on table tents, stickers, or printed menus controlled by the restaurant itself and checked periodically by staff. The risk rises with codes on removable table tents or standalone stickers that could be swapped, and especially with codes in outdoor seating areas or waiting lines that are less closely watched. When in doubt, ask a staff member to confirm the code, or simply ask for a physical menu instead.
Why do parking QR code scams specifically target parking meters and lots?
Because paying for parking by QR code has become a genuinely common, legitimate practice in many Canadian cities, which means people don't find it unusual to see a payment QR code on a meter or posted sign. That familiarity is exactly what the scam exploits — a sticker reading "Scan to pay for parking" on top of, or beside, a real meter blends in perfectly with a routine people already expect, unlike an email that has to work harder to look legitimate.
Does my phone show me the actual website before I open a QR code link?
On most current iPhones and Android phones, yes — the built-in camera app shows a URL preview banner after scanning, before you tap to actually open the page. This preview is one of the most useful and underused defenses against quishing, but it only works if you actually read it rather than tapping through automatically out of habit. A slightly misspelled domain or an unusual URL structure is often visible right there, before any risk begins.
Can a business be held responsible if a customer is scammed by a fake QR code on their premises?
It depends heavily on the specifics, but a business that displayed an official QR code that was later tampered with by a third party generally isn't automatically liable for a customer's loss, since the business itself was also a victim of the tampering. That said, reputational damage is real and immediate regardless of legal liability, and a pattern of unchecked codes at a location can raise questions about reasonable care. The practical takeaway for businesses is prevention — regular physical checks of posted codes — rather than relying on a legal defense after the fact.
What's the difference between quishing and regular phishing or smishing?
All three share the same underlying goal — tricking someone into visiting a malicious link or handing over information — but the delivery method changes the mechanics. Phishing arrives by email, smishing arrives by text message, and quishing arrives through a QR code, usually encountered in a physical, real-world location rather than a digital inbox. Quishing is arguably the hardest of the three to inspect beforehand, since a QR code gives no readable clue about its destination until after it's scanned, unlike a visible email sender address or a text message you can read in full first.

For the broader background this guide builds on, see our what is phishing guide for the email fundamentals, and our what is smishing guide for the text-message version of the same threat. If a QR-code scam led to a live scam phone call, our tech support scam warning signs guide covers what to do next.

Not Sure If That QR Code (or Your Device) Is Actually Safe?

IT Cares can check your phone or computer remotely and tell you honestly whether a suspicious QR code did anything, and help you lock down your accounts if it did.

Comments (3)

FL
Francis L., Gatineau
August 6, 2026

Scanned a parking QR code last month and the URL preview showed something totally unrelated to the city's site. Backed out immediately. Never would've thought to check before reading this kind of thing.

NV
Nadia V., Kitchener
August 5, 2026

We run a small cafe and started checking our table QR codes every morning after reading about this exact scam happening nearby. Takes five minutes, cheap insurance.

RD
Ryan D., Surrey
August 3, 2026

Didn't realize QR codes in emails could get past spam filters that catch normal links. That case study about the logistics company hit close to home, we use QR check-ins at our office too.

Leave a Comment

Need Help?