Skip to content

tagblick

Monday, 10 August 2026

Search

Sponsored

Consumer

Quishing: how fraudsters abuse QR codes — and how to spot safe ones

Stickers on parking machines, forged letters from the bank: in “quishing”, manipulated QR codes lead to phishing pages. How the scam works, how trustworthy codes can be recognised and what those affected should do.

Quishing: how fraudsters abuse QR codes — and how to spot safe ones
Illustrative photoPhoto: Ralf Roletschek · Wikimedia Commons · CC BY-SA 3.0 at

The parking fee has been paid, or so you believe — in reality the credit card details have just landed on a fraudster's server. What makes that possible is a sticker: a forged QR code, stuck over the machine's genuine one. “Quishing” is the name of this scam, a portmanteau of QR and phishing. Consumer advice centres and police authorities have been warning for some time about such cases at parking machines, at charging points and in forged letters from banks. That is no cause for panic — but it is reason to review your own scanning habits.

Why QR codes of all things? Because they are the perfect hiding place. A link in an email can be read before you click it; a QR code is a meaningless pattern to the human eye. Where it leads is something you only learn after the scan. On top of that comes the context: a code on an official machine inherits that machine's credibility — hardly anyone reckons with the local council having been stuck over. And the effort for the perpetrators is minimal: a sheet of adhesive labels and any code generator will do. The technology itself is as neutral as paper and printer's ink — anyone can use any tool to generate a code pointing to any address at all.

The known scams resemble one another. At parking machines and electric charging points, codes stuck over the originals lead to deceptively genuine payment pages that ask for credit card details. In forged letters purporting to come from banks, the QR code replaces the classic phishing link — paper appears trustworthy and bypasses every spam filter. Fictitious parking tickets with an invitation to pay conveniently by code are documented as well, as are stickers on parcel delivery notices. The aim is always the same: payment details or login credentials, collected on a rebuilt website.

However different the settings, the dramaturgy is similar. Almost always the scam works with time pressure: the account will be blocked, the car towed away, the late fee due, unless action is taken within minutes. Added to that is often an unusual route for an everyday matter — the bank that suddenly asks you by letter to scan something, the authority that handles payments via an unknown page. Both are classic signals of social engineering, and both work independently of the technology: the QR code is merely the carrier. Anyone who gets into the habit of slowing down precisely when they feel under time pressure takes away the scam's most important lever — no reputable provider punishes you for making a payment five minutes later by the official route.

The most important protection has long been built in, but is rarely used consciously: the link preview. Modern telephones first display the destination address after a scan, before they open a page. That second is the decisive one. It pays to read closely — and to read from the back: what counts is the actual domain immediately before the ending, not the beginning of the address. “yourbank.payment-service.example” does not belong to the bank but to the operator of “payment-service.example”. Transposed characters, extra hyphens and unusual endings are warning signs too.

Two subtleties make the reading harder than it sounds. First, some camera apps abbreviate long addresses in the preview — what is visible is then only the harmless-looking beginning, not the decisive domain. Anyone who is unsure has the full address displayed before opening it. Second, there are domains using characters from other alphabets that look confusingly similar to Latin letters; for protection, many browsers display such addresses in a technical notation with the prefix “xn--”. Anyone seeing such a character string in the preview when they were expecting a familiar brand has every reason for caution. Short-link services, finally, conceal the actual destination entirely — with anything to do with money or login credentials, typing in the known address yourself is the safest route.

The second look is at the code itself. Is it stuck on the machine, rather than printed on it or sitting behind film? Is it crooked, does it overlap other lettering, can it be felt standing proud of the surface? A label over the original is the most common pattern in quishing in public spaces. In case of doubt the rule is: take the official route — the operator's app, the printed service number or the terminal itself.

Third: sensitive transactions have no business following a scan in a public space. Anyone asked to enter payment details, passwords or a transaction number after scanning a code does better to break off and type in the known address themselves, or use the official app. With letters containing a QR code, a telephone call to the bank helps — using the number on the bank card, not the one in the letter. Reputable institutions accept this detour without complaint; anyone pressing for haste makes themselves suspect.

One widespread misconception deserves a warning of its own: the padlock symbol in the browser is not a seal of quality. It shows only that the connection is encrypted — not with whom you are communicating in encrypted form. Phishing pages use HTTPS almost throughout these days. The question is therefore never whether a page has a padlock, but who owns the domain.

The tool in your own hand makes a difference as well. The camera apps of modern telephones display the destination address and wait for a deliberate confirmation — that very pause is the protective mechanism. Third-party scanner apps, by contrast, sometimes open links automatically, display advertising or demand permissions that have nothing to do with scanning. Anyone using such an app does best to check whether automatic opening can be switched off — or does without it altogether: for everyday use the pre-installed camera is entirely sufficient. Where it is missing, on older devices for instance, a scanner app with a preview function and frugal permissions is the right choice.

Part of the truth, however, is this: not every redirect is suspicious. Many legitimate codes from advertising and retail first go via the short domain of a QR service before arriving at their destination — that is how dynamic codes work, codes whose destination remains changeable afterwards and whose scans are counted for measuring reach. An intermediate step via an unknown short address is therefore not in itself proof of fraud — any more than its absence is proof of safety.

How providers can deal with this question of transparency is shown by the German QR service QR2GO: for every code it offers a choice of several redirect modes — a visible redirect in which the intermediate step remains recognisable, a covert variant with counting, and a direct mode without the detour. For consumers the lesson nevertheless stays the same: what matters is not the route but the destination — which address ends up in the browser and what the page there demands.

A generator cannot prevent the abuse, after all — no provider controls where a code, once generated, gets stuck up, and fraudsters can use any tool they like. Protection therefore lies not in the technology but in the habit: read the destination address, check the context, become suspicious where money and passwords are involved. It is the same vigilance that has long since become established with email links — except that with a QR code it can only begin after the scan.

The topic has a facet of its own in working life. Security authorities and consumer protection bodies have for some time been observing phishing emails that contain a QR code instead of a link — with a calculated side effect: the code is scanned off the screen with a private telephone, and with that the attack leaves the secured company computer along with its filters and protection programs. The login screen that then appears on the handset often resembles the employer's portal down to the last detail. The counter-rule is simple and can be anchored in the team: work login credentials are on principle never entered on pages reached via a scanned code — and suspicious messages belong reported to the IT department, not in the waste bin.

Important for placing all this in context: the scan itself as a rule does no damage yet. It only becomes dangerous when the opened page prompts for input, offers downloads or presses for the installation of an app. Anyone who simply closes a suspicious page and has entered nothing usually has nothing further to fear — a checking glance at the next bank statements never does any harm all the same.

If something has happened after all, speed counts. If card details have been entered, the card should be blocked without delay — in Germany centrally via the blocking emergency number 116 116, or directly with the bank. Affected passwords belong changed at once, and, where they have been reused, on all other services too. Reporting the matter to the police is sensible even for small amounts, because it makes patterns visible to investigators; the consumer advice centres additionally collect phishing reports. Account movements should be checked attentively in the weeks that follow.

The other side can do something too. Companies that display codes in public strengthen trust by printing the destination address next to them in plain text — anyone who wishes can type it in, and everyone else can at least compare it with the preview. A consistent appearance with colours and a logo helps as well, but is not proof, because design can be copied. More effective is regular inspection on site — a code stuck over is noticed on the weekly round — and a placement that at least makes sticking over it harder.

For operators of machines and charging points this can be condensed into a fixed procedure: keep an overview of which code hangs at which location and where it leads; brief the staff so that a foreign sticker is noticed during emptying or maintenance; and set up a simple reporting route for tip-offs from customers. If a manipulation is discovered, the rule is: cover or remove the false code immediately, photograph the state beforehand, report it to the police — and indicate clearly at the machine that payments should be made only by the official routes. Anyone who additionally informs customers via their own channels limits the damage and wins back trust.

In the end quishing is not a new danger but an old one in new clothing: phishing follows attention, and attention has arrived at the QR code. The answer remains unchanged — a short, checking glance before data flows. Anyone who reads the destination address of a scanned code as attentively as the sender of a suspicious email has taken most of the terror out of the scam.