QR-Code Phishing: Check the Destination Before Acting
A QR code is a shortcut to information, not a trust mark. Before signing in or paying, verify the destination and the reason you were asked to scan.
By ZoraSafe · Content reviewed · Originally published
What quishing means
Quishing is phishing that uses a QR code to send someone to a deceptive destination. The FTC describes altered parking-meter codes and messages that use urgency to encourage scanning.
Check without rushing
- Inspect the displayed destination if your scanner offers a preview.
- For payments, use the provider’s official app or a known address rather than a code from an unexpected message.
- Do not install an app or enter credentials just because a QR page asks.
- If a physical code looks replaced or tampered with, check with the operator through an independent channel.
Sources: FTC: Scammers hide harmful links in QR codes
Related guidance: QR Codes at Events: Verify Before Signing In
Scanning is not the same as sharing a password
The response depends on what happened after scanning. If you entered account information, use account recovery steps; if you paid, contact the payment provider. Ask Zora can provide context for a QR code or link you choose to check, but cannot guarantee a destination is safe.
Sources: FTC: What to do if you were scammed; ZoraSafe: Product capabilities and limitations
Related guidance: MFA Manipulation and Account Takeover: What to Do
Sources and product references
Reviewed 2026-10-07. Source dates and scope matter; a linked source supports the associated guidance, not every claim about every product.
