What is changing now
The current pattern.
QR phishing—sometimes called quishing—is now used alongside adversary-in-the-middle login pages that can capture passwords and active session information. Official alerts also describe QR codes arriving in unsolicited physical packages, not only emails and posters.
How it works
Confidence first, then pressure.
A QR code converts a destination into an image. That convenience hides the full address until after a phone has interpreted the code, making it harder to notice a misspelled domain or unrelated service.
The code may appear in a renewal notice, parking sign, parcel, invoice, shared document or calendar invitation. It can lead to a copied sign-in page, a payment request or instructions to install software. More advanced phishing pages relay a real login flow while stealing credentials or session information.
A code printed on professional stationery or placed on a familiar object is not automatically trusted. Stickers can be replaced, email accounts can be compromised and reputable cloud services can host misleading content.
Worked example
A realistic pattern, separated into evidence.
This composite example is educational. It does not describe a real person or reproduce a live malicious message.
A security notice moves the login onto a phone
- 01The opening
An email that appears to come from a workplace service says a document cannot be opened until the recipient scans a QR code. The message uses the company logo and names a real internal project.
- 02The escalation
The QR code opens a mobile sign-in page that looks familiar and requests an email address, password and approval code. A countdown says the document will expire in ten minutes.
- 03The decision point
The code deliberately hides the destination and moves the login away from the device where mail security tools may be active. The unexpected second login and deadline are stronger signals than the quality of the page design.
Warning signs
Reasons to stop and verify.
- A code in an unexpected email, calendar invitation, document or parcel
- A warning that an account, subscription, delivery or payment expires immediately
- Instructions to scan with a personal phone to bypass a work computer
- A sign-in request after scanning when you were already signed in
- A payment page whose domain does not exactly match the organisation
- A sticker placed over another code or a code with no clear owner and purpose
Independent verification
Test the request without using its evidence.
These checks deliberately move the decision away from the person, link, number or account that introduced the request.
- 01
Identify the expected service
Ask what legitimate account or transaction the code supposedly relates to. Open that service through its established app or bookmark without scanning.
- 02
Read the registrable domain
If a destination preview is available, identify the actual domain that controls the page—not a familiar brand word placed in a subdomain or URL path.
- 03
Check the physical context
For a public code, look for a replacement sticker, damaged sign or conflicting payment instructions. Contact the venue or operator through a separately found channel.
- 04
Refuse a surprise sign-in
A QR code that unexpectedly leads to credentials, payment, a download or a security-setting change should be closed until the request is independently confirmed.
Safer response
Move the decision outside the contact.
- 01
Use the normal route
Open the official app, use a saved bookmark or type the known website address instead of following the code.
- 02
Inspect before opening
If your camera shows a destination preview, read the full domain. A familiar word inside a longer unrelated domain is not enough.
- 03
Do not continue a surprise login
Close the page if scanning unexpectedly leads to credentials, payment, a download or a request to change security settings.
- 04
Report replaced public codes
Tell the venue, parking operator, employer or service that owns the sign so it can remove or investigate the code.
If you already acted
Protect access and contact the real provider.
- Close the page and do not approve any login or security prompt.
- Change a submitted password through the real service and sign out other sessions.
- Contact your bank if card or account information was entered, even if no payment completed.
- Remove an unfamiliar app and seek trusted technical help if software was installed.
- Preserve the code’s location or original message without scanning it again, then report it to the organisation being impersonated.
Sources
Official guidance used for this article.
Stop & Verify summarises these sources for general education. Reporting routes and legal protections vary by location.