Skip to main content

    QR-Code Phishing: Check the Destination Before Acting

    A QR code is a shortcut to information, not a trust mark. Before signing in or paying, verify the destination and the reason you were asked to scan.

    By ZoraSafe · Content reviewed · Originally published

    What quishing means

    Quishing is phishing that uses a QR code to send someone to a deceptive destination. The FTC describes altered parking-meter codes and messages that use urgency to encourage scanning.

    Sources: FTC: Scammers hide harmful links in QR codes

    Check without rushing

    1. Inspect the displayed destination if your scanner offers a preview.
    2. For payments, use the provider’s official app or a known address rather than a code from an unexpected message.
    3. Do not install an app or enter credentials just because a QR page asks.
    4. If a physical code looks replaced or tampered with, check with the operator through an independent channel.

    Sources: FTC: Scammers hide harmful links in QR codes

    Related guidance: QR Codes at Events: Verify Before Signing In

    Scanning is not the same as sharing a password

    The response depends on what happened after scanning. If you entered account information, use account recovery steps; if you paid, contact the payment provider. Ask Zora can provide context for a QR code or link you choose to check, but cannot guarantee a destination is safe.

    Sources: FTC: What to do if you were scammed; ZoraSafe: Product capabilities and limitations

    Related guidance: MFA Manipulation and Account Takeover: What to Do

    Sources and product references

    Reviewed 2026-10-07. Source dates and scope matter; a linked source supports the associated guidance, not every claim about every product.