Quishing: Pause before you scan that QR code

QR codes have become part of everyday life. We use them to view restaurant menus, pay for parking, access event information, connect to Wi-Fi and more.

A growing scam known as “quishing” combines QR codes and phishing to trick people into visiting malicious websites, sharing personal information or entering login credentials.

A simple square can hide malicious links

Unlike a traditional web link, a QR code doesn’t show you where it’s taking you before you scan it.

Imagine you’re walking through a building and notice a flyer advertising a giveaway. There’s a QR code to scan.

Or perhaps you’re at a parking kiosk and see a QR code that promises a faster payment option.

You scan the code without a second thought.

Instead of taking you to a legitimate website, the code directs you to a fake login page designed to steal your username and password. In other cases, it may ask for payment information or personal details.

The website may look convincing, complete with official logos and branding.

By the time you realize something is wrong, the information has already been submitted.

How QR code scams work

Cybercriminals use several tactics to make QR codes appear legitimate:

  • Placing fake QR code stickers over real ones
  • Including malicious QR codes in emails or text messages
  • Posting QR codes on flyers, posters, and social media
  • Directing users to fake Microsoft 365, banking, or payment websites

Because QR codes are difficult to inspect visually, they can be more effective than traditional phishing links.

Warning signs to watch for

Before scanning a QR code, ask yourself a few questions:

  • Do I trust the source?
  • Was I expecting this request?
  • Does the QR code seem out of place?
  • Is someone creating a sense of urgency?
  • Does the website address shown after scanning look legitimate?

Most smartphones display the destination URL before opening it. Take a moment to review the address carefully.

If the URL looks suspicious, don’t continue.

Stay safe when scanning

Protect yourself by following a few simple practices:

  • Verify before you scan: Only scan QR codes from trusted organizations and known sources.
  • Check the web address: After scanning, review the URL before entering any information.
  • Be cautious with login requests: If a QR code directs you to a Microsoft 365 login page, pause and verify that you’re on an official website before signing in.
  • Avoid unexpected payment requests: Be especially cautious if a QR code asks for payment information, gift cards or financial details.
  • Report suspicious activity: If you believe you’ve scanned a malicious QR code or entered your credentials on a suspicious website, change your password immediately and contact the IT Service Desk (785-532-7724).

Convenience should never replace caution

QR codes are useful tools, but they’re also becoming a favorite tool for cybercriminals.

The next time you see a QR code, take an extra second before scanning.

That small pause could be the difference between accessing helpful information and becoming the victim of a scam.

Share this post: