Resource icon

QR phishing: when a code hides the destination

QR phishing, sometimes called quishing, uses a QR code to send you to a deceptive site. The code itself is a way to encode a destination; the danger is the page it opens and the action you take there. Printed stickers can even cover a legitimate code.

A useful example​

A parking-meter sticker says to scan and pay. Your camera previews a domain unrelated to the parking operator. Stop, use the operator's official app or type the known address, and tell the operator about the sticker. If you entered card details, contact the issuer through its official channel.

What to check​

Read the URL preview before opening it. Check the full domain, not just a logo or the first word. A QR code in a trusted-looking email or public poster deserves the same scrutiny as an ordinary link. The FBI's QR-code advisory describes tampered codes and payment redirection. A secure-looking padlock does not prove the merchant is legitimate.

Practical distinction​

A printed code cannot be judged by design alone. Check whether a sticker covers the original and whether the previewed domain matches the organization you intended to reach.
Posted by
Jack
Views
2
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack