QR codes are everywhere — restaurant menus, parking meters, event badges, product packaging, and marketing materials. But that ubiquity has made them one of the fastest-growing attack surfaces for cybercriminals.
Quishing — a portmanteau of "QR" and "phishing" — is the practice of using malicious QR codes to steal credentials, distribute malware, or redirect victims to fraudulent websites. And it's growing at an alarming rate.
The Scale of the Quishing Threat
The numbers tell a sobering story:
| Metric | Value | Source |
|--------|-------|--------|
| Quishing attack growth (2023-2024) | 587% | Check Point |
| Phishing emails using QR codes | 12-22% of all phishing | Abnormal Security |
| Executive targeting rate | 42x more likely than average | Keepnet Labs |
| Mobile-targeted attacks | 68-76% | Industry aggregate |
| Average cost of a QR breach | $2.4 million | IBM |
In January 2026, the FBI issued a flash advisory identifying a North Korean APT group (Kimsuky) using QR codes in targeted phishing campaigns. This isn't a niche threat — it's a mainstream attack vector that every organization using QR codes needs to understand and address.
Why QR Phishing Is So Effective
QR codes exploit several blind spots in both human behavior and security infrastructure:
1. The Destination Is Invisible
Unlike a clickable link in an email, you cannot preview a QR code's destination URL before scanning it. The encoded URL is hidden behind a pattern of black and white squares. Users must trust the code, scan it, and then see where it leads — by which point, the damage may already be done.
2. Email Security Filters Can't Read Images
Modern email security tools are excellent at parsing URLs, detecting malicious domains, and flagging suspicious links in text. But QR codes are embedded as images. Traditional email security filters don't parse the encoded URL within a QR image, meaning malicious QR codes sail through spam filters undetected.
3. Inherent User Trust
People associate QR codes with legitimate businesses. A QR code on a parking meter, a restaurant table, or a FedEx delivery notice feels inherently trustworthy. Attackers exploit this trust by placing fake QR code stickers over legitimate ones — a technique that's particularly effective for parking meters, EV charging stations, and restaurant menus.
4. Mobile Devices Weaken Security
QR codes are scanned on mobile phones, which operate outside the corporate security perimeter. Mobile browsers show truncated URLs, display weaker phishing warnings, and lack the enterprise browser extensions that protect desktop users.
5. Physical Credibility
A QR code on a physical surface carries an implied authenticity that a digital link doesn't. When someone sees a QR code sticker on a parking meter, they assume it was placed by the parking authority — not a scammer who spent $2 on a printed sticker at a copy shop.
Common Quishing Attack Vectors
Digital Delivery
The most common delivery method. Attackers embed QR codes in phishing emails, SMS messages, social media posts, and even legitimate-looking documents (PDFs, Word files). The QR code redirects the victim to a credential-harvesting page that looks identical to a real login screen.
Physical Tampering
Attackers place fake QR code stickers over legitimate ones in public spaces. Known targets include:
- Parking meters — Fake payment QR codes that redirect to attacker-controlled payment pages
- Restaurant menus — Transparent QR code overlays placed on real menu QR codes
- EV charging stations — Fake QR codes that claim to be for payment or app download
- Delivery notices — Fake "missed delivery" notices on doors and mailboxes
Multi-Stage Attacks
The most sophisticated quishing campaigns use multi-stage attacks:
- QR code redirects to a legitimate-looking intermediate page
- That page injects a malicious overlay that steals credentials or installs malware
- Or the QR code redirects through a chain of redirects to make detection harder
In 2025-2026, attackers have also started using AI to generate more convincing phishing pages that are harder for both users and automated tools to distinguish from legitimate sites.
What This Means for QR Code Creators
If your organization creates and distributes QR codes — whether for marketing, operations, or customer engagement — you have a responsibility to ensure those codes are safe. A single compromised QR code on your materials can destroy customer trust and expose your organization to liability.
The Platform Liability Question
Under Section 230 of the Communications Decency Act, QR code platforms are generally not considered publishers of the content they redirect to. However, negligence in monitoring and preventing abuse can create liability. Proactive security measures demonstrate good faith and provide legal protection.
What Responsible QR Platforms Do
A secure QR code platform should implement multiple layers of protection:
At creation time:
- URL format validation (reject non-HTTP protocols like
javascript:ordata:) - Domain reputation checking against threat databases
- Blocklist checking (Google Safe Browsing, PhishTank, URLhaus)
- Abuse detection (bulk creation patterns, disposable email signups)
At scan time:
- Re-verification of destination URL safety
- HTTPS-only redirects
- Destination preview (interstitial page showing where the QR leads)
- Open redirect prevention
- Rate limiting to prevent scan manipulation
For account holders:
- Two-factor authentication
- Session security (short-lived sessions, secure cookies)
- API key rotation
- Comprehensive audit logging
How WaypointQR Protects Against Quishing
WaypointQR was built with security as a first-class concern, not an afterthought. Here's how we protect your QR codes, your organization, and your customers:
URL Safety Scanning Pipeline
Every destination URL is checked at two critical points:
- When a QR code is created — The URL is validated, checked against threat databases, and assessed for domain reputation before the QR code is allowed to go live.
- When a QR code is scanned — The destination URL is re-verified at redirect time. If a previously safe domain has been flagged as malicious since the QR code was created, the scan is blocked.
This two-point validation catches threats that emerge after QR codes are already in circulation — a critical capability for codes printed on materials that can't be easily updated.
Threat Database Integration
WaypointQR integrates with multiple threat intelligence sources:
- Google Safe Browsing — Free, large coverage for known malicious sites
- PhishTank — Community-driven phishing site database
- URLhaus (Abuse.ch) — Free, malware-specific threat data
- VirusTotal — 70+ scanning engines for comprehensive analysis (at scale)
Destination Preview
Before redirecting, scanners see a brief interstitial page that displays the destination domain. This gives users a chance to evaluate whether the destination looks legitimate before proceeding. The interstitial is skippable with a tap and configurable per-workspace.
Abuse Prevention
Our platform actively monitors for abuse patterns:
- Bulk QR code creation triggers review
- Disposable email signups are blocked
- API abuse is throttled
- Suspicious scan patterns are filtered from analytics
Bot Detection
We detect and filter bot scans from analytics so that your scan data reflects real human engagement, not inflated numbers from automated scanners or security researchers.
What You Can Do
Even with platform-level protection, organizations should follow QR code security best practices:
For QR Code Creators
- Use a managed platform — Never use static QR codes for business purposes. Dynamic codes that can be monitored, updated, and deactivated are essential.
- Monitor your QR codes — Regularly review scan analytics for anomalies (unusual geographic patterns, sudden traffic spikes).
- Use custom domains — Branded short URLs (e.g.,
link.yourbrand.com) help users verify authenticity. - Test your QR codes — Before mass printing, test that QR codes redirect to the correct destination.
- Plan for abuse — Have a process for quickly deactivating compromised QR codes.
For End Users
- Check the destination — After scanning, look at the URL before entering any credentials.
- Be suspicious of QR codes in public spaces — Parking meters, EV chargers, and restaurant tables are common tampering targets.
- Don't scan QR codes from unexpected emails — If you receive an email with a QR code you weren't expecting, verify it through another channel.
- Use a QR scanner with preview — Some scanner apps show the destination URL before opening it.
The Future of QR Security
The threat landscape continues to evolve. Emerging threats include:
- AI-generated phishing pages that are harder to distinguish from legitimate sites
- QR code certificate fraud — using QR codes that claim to be digitally signed
- Deepfake QR contexts — placing malicious QR codes in AI-generated images of legitimate environments
Platforms that invest in proactive security — AI-based URL classification, real-time anomaly detection, and integration with threat intelligence feeds — will be best positioned to protect their users as threats evolve.
Conclusion
Quishing is not a theoretical threat — it's a rapidly growing attack vector that costs organizations millions of dollars annually. As QR codes become more embedded in business operations and consumer interactions, the security of those codes becomes a business-critical concern.
WaypointQR's security isn't a feature you pay extra for. It's built into every plan, at every level, for every QR code we serve. Because protecting your customers isn't optional — it's the minimum standard for any QR code platform in 2026.
Ready to deploy secure, managed QR codes? Get started for free — no credit card required.