What is changing now
The current pattern.
QR phishing—sometimes called quishing—is now used alongside adversary-in-the-middle login pages that can capture passwords and active session information. Official alerts also describe QR codes arriving in unsolicited physical packages, not only emails and posters.
How it works
Confidence first, then pressure.
A QR code converts a destination into an image. That convenience hides the full address until after a phone has interpreted the code, making it harder to notice a misspelled domain or unrelated service.
The code may appear in a renewal notice, parking sign, parcel, invoice, shared document or calendar invitation. It can lead to a copied sign-in page, a payment request or instructions to install software. More advanced phishing pages relay a real login flow while stealing credentials or session information.
A code printed on professional stationery or placed on a familiar object is not automatically trusted. Stickers can be replaced, email accounts can be compromised and reputable cloud services can host misleading content.
Warning signs
Reasons to stop and verify.
- A code in an unexpected email, calendar invitation, document or parcel
- A warning that an account, subscription, delivery or payment expires immediately
- Instructions to scan with a personal phone to bypass a work computer
- A sign-in request after scanning when you were already signed in
- A payment page whose domain does not exactly match the organisation
- A sticker placed over another code or a code with no clear owner and purpose
Safer response
Move the decision outside the contact.
- 01
Use the normal route
Open the official app, use a saved bookmark or type the known website address instead of following the code.
- 02
Inspect before opening
If your camera shows a destination preview, read the full domain. A familiar word inside a longer unrelated domain is not enough.
- 03
Do not continue a surprise login
Close the page if scanning unexpectedly leads to credentials, payment, a download or a request to change security settings.
- 04
Report replaced public codes
Tell the venue, parking operator, employer or service that owns the sign so it can remove or investigate the code.
If you already acted
Protect access and contact the real provider.
- Close the page and do not approve any login or security prompt.
- Change a submitted password through the real service and sign out other sessions.
- Contact your bank if card or account information was entered, even if no payment completed.
- Remove an unfamiliar app and seek trusted technical help if software was installed.
- Preserve the code’s location or original message without scanning it again, then report it to the organisation being impersonated.
Sources
Official guidance used for this article.
Stop & Verify summarises these sources for general education. Reporting routes and legal protections vary by location.