Quishing: how QR code scams work, and how to check a code before you scan it

Quishing is phishing through a QR code: on a parking meter, in an email, on a flyer or a package you never ordered. How each version works, what the FTC and FBI advise, and how to see where a code goes first.

A link you cannot read

"Quishing" is phishing with a QR code instead of a link. It works for one simple reason: you can read a link before you tap it, but you cannot read a QR code. It is a square of dots until your phone turns it into an address, and by then most phones are one tap away from opening it.

That makes a QR code the perfect wrapper for a scam page. It also slips past things that would catch a plain link. An email filter that checks every link in a message can miss the one printed inside a picture.

The four places it shows up

Parking meters and pay stations. Scammers print their own QR code and stick it over the real one, or on a sign next to it. You scan it, land on a page that looks like a parking payment site, and type in your card. In September 2026 the FTC warned about exactly this: "scammers covering up legit QR codes on parking meters with a QR code of their own" (FTC). Cities have said the same. New York City's transport department told drivers that secure payments can only be made through the ParkNYC app or with a credit card at the meter (NYC DOT), and Raleigh told residents plainly not to scan QR codes on its meters (City of Raleigh).

Emails and texts. A message says your password expires today, a package needs a customs fee, or a document is waiting for your signature, and there is a QR code to "verify". The code opens a copy of a login page. The FTC's advice is short: don't scan a QR code in an email or text message you weren't expecting (FTC).

Packages you never ordered. In 2025 the FBI warned about unsolicited packages that arrive with a QR code inside, often with no sender, inviting you to scan to find out who sent it. Its advice: don't scan QR codes from unknown origins (FBI IC3).

Stickers on real things. Restaurant tables, posters, charging stations, flyers on a car window. A sticker costs almost nothing, and it sits on top of something you already trust. We wrote a separate guide to spotting a QR sticker placed over the real one.

Before you scan

  • Look at the code, not just the sign. Is it a sticker on top of the printed material? Is it crooked, or does it cover part of the design? The FBI's advice is to make sure the code has not been tampered with, "such as with a sticker placed on top" (FBI IC3).
  • Use the official app or the website you know. For parking, that is the city's own app or the meter's card reader. For a company, type its address yourself. A QR code is never the only way to pay a real bill.
  • Ask whether you were expecting it. A code in an email, a text or a package nobody told you about is a reason to stop, not to scan.

When you do scan

Most phones show you the address before they open it. Read it. The FTC points out that many QR readers preview the link they will send you to, and that you should look for misspellings or a switched letter.

Read the address the same way you would any link: the site is the part just before the first single slash, read from the right. parkingpay.city-meters.top is a site called city-meters.top, not your city. If you are not sure how to read one, our guide to checking whether a link is safe goes through it step by step.

Then two hard rules from the FBI: don't download an app from a QR code, and avoid making payments through a site you reached from a QR code (FBI IC3).

See where it goes without opening it

Take a photo or a screenshot of the code, and upload it to our QR and link checker. We read the code from the picture, so your phone never opens it. If it is a web link, we follow it in a browser that is not yours, through every redirect, and tell you where it really ends, how old that domain is, whether it is on public blocklists, whether the page asks for a card or a password, and whether people have reported it. If it is a payment code, we tell you what kind of payment it is. It is free and there is no sign-up.

"Low risk" means we found nothing wrong at that moment. It does not make a code safe to pay through. If a code on a parking meter leads to a page asking for your card, the city's own app is still the better way.

If you already paid through one

  • Card: call the number on the back of your card, report the charge as fraud and ask for a new card. Follow up the dispute in writing.
  • Typed a password: change it on the real site, and anywhere you reused it, and turn on two-step verification.
  • Installed an app: delete it.

Then report it to the FTC at reportfraud.ftc.gov, and tell whoever owns the meter, the restaurant or the poster, so the sticker comes off before the next person scans it.

Check a link before you click it

Paste the link or scan the QR code. We open it for you and show the real destination, the redirects on the way, and whether anyone has reported the seller behind it.

Check a link
Add Glar as a friend on LINE and have him check links for you