← Security Awareness Hub Spot the scam

Quishing — QR-Code Phishing

A QR code is just a link you can't read. Treat it like one.

Quishing is phishing that hides the malicious link inside a QR code, so you can't see where it goes until you've already scanned it — and often not even then. It's exploding across Europe precisely because QR codes feel harmless and official.

TL;DR
  • A QR code is an unreadable link. You'd never click a link you couldn't see — don't scan one either, blindly.
  • The danger spots in Europe right now: parking meters, fake fines, restaurant menus, invoices, and "package delivery" notices.
  • Stickers get placed over real QR codes. The fake looks exactly as official as the real one.
  • After scanning, check the URL before you do anything on the page. If it asks for payment or login, stop.

The threat in plain language

Someone prints a QR-code sticker that points to their fake page and sticks it over the genuine one on a parking meter, a poster, or a restaurant table. You scan it expecting to pay for parking; you land on a convincing payment page that simply pockets your card details. Because the code is physical and in an official-looking place, the usual "this email looks off" instinct never fires.

The invoice and delivery versions arrive digitally: a PDF invoice or an SMS with a QR code "to pay" or "to reschedule delivery," routing you to a card-harvesting page.

What to actually do

  1. Before scanning, ask: do I have another way to do this? Type the parking operator's known app/URL, or use the meter's card slot, instead of the sticker.
  2. After scanning, your phone previews the URL — read it. Look-alike or hyphenated domains are the tell.
  3. Never enter card or login details on a page you reached only via a QR code you didn't fully trust.
  4. Check the physical sticker — a sticker placed over the surface, slightly misaligned or different paper, is a red flag.
  5. Use your phone's built-in camera for scanning, not a random "QR scanner" app — those can add their own risks.

🇱🇺 In Luxembourg

  • Quishing on parking and fake fines is a current, regionally relevant pattern — see Scam of the Month when it covers it.
  • Report a quishing URL to CIRCL (URL-Abuse, circl.lu).
  • Report a quishing email/SMS to SPAMBEE (spambee.lu).
  • Paid on a fake page? Treat it as card fraud → call your bank, then file a plainte (Police Grand-Ducale).

Red flags

  • A QR code is a sticker on top of another surface.
  • The page after scanning asks immediately for payment or login.
  • The URL is a look-alike of the real operator.
  • A QR code arrives unexpectedly by SMS/email "to pay" or "to reschedule."
  • There's urgency: "pay within 24h to avoid a penalty."

If it's already happened

You entered card details → I've Been Hit — "My bank account or card." Call your bank now.

Run a business with QR codes on display, invoices, or table-tents? Verifying your own codes can't be tampered with is a real operational control — johlem.net.