Quishing — QR-Code Phishing
A QR code is just a link you can't read. Treat it like one.
Quishing is phishing that hides the malicious link inside a QR code, so you can't see where it goes until you've already scanned it — and often not even then. It's exploding across Europe precisely because QR codes feel harmless and official.
- A QR code is an unreadable link. You'd never click a link you couldn't see — don't scan one either, blindly.
- The danger spots in Europe right now: parking meters, fake fines, restaurant menus, invoices, and "package delivery" notices.
- Stickers get placed over real QR codes. The fake looks exactly as official as the real one.
- After scanning, check the URL before you do anything on the page. If it asks for payment or login, stop.
The threat in plain language
Someone prints a QR-code sticker that points to their fake page and sticks it over the genuine one on a parking meter, a poster, or a restaurant table. You scan it expecting to pay for parking; you land on a convincing payment page that simply pockets your card details. Because the code is physical and in an official-looking place, the usual "this email looks off" instinct never fires.
The invoice and delivery versions arrive digitally: a PDF invoice or an SMS with a QR code "to pay" or "to reschedule delivery," routing you to a card-harvesting page.
What to actually do
- Before scanning, ask: do I have another way to do this? Type the parking operator's known app/URL, or use the meter's card slot, instead of the sticker.
- After scanning, your phone previews the URL — read it. Look-alike or hyphenated domains are the tell.
- Never enter card or login details on a page you reached only via a QR code you didn't fully trust.
- Check the physical sticker — a sticker placed over the surface, slightly misaligned or different paper, is a red flag.
- Use your phone's built-in camera for scanning, not a random "QR scanner" app — those can add their own risks.
🇱🇺 In Luxembourg
- Quishing on parking and fake fines is a current, regionally relevant pattern — see Scam of the Month when it covers it.
- Report a quishing URL to CIRCL (URL-Abuse, circl.lu).
- Report a quishing email/SMS to SPAMBEE (spambee.lu).
- Paid on a fake page? Treat it as card fraud → call your bank, then file a plainte (Police Grand-Ducale).
Red flags
- A QR code is a sticker on top of another surface.
- The page after scanning asks immediately for payment or login.
- The URL is a look-alike of the real operator.
- A QR code arrives unexpectedly by SMS/email "to pay" or "to reschedule."
- There's urgency: "pay within 24h to avoid a penalty."
If it's already happened
You entered card details → I've Been Hit — "My bank account or card." Call your bank now.