"Quishing" is a form of phishing that uses QR codes as the entry point. Instead of a link or attachment in an email, the attacker places a QR code that, once scanned, leads to a fraudulent website designed to steal your personal data, credentials, or payment information.
Warning signs
Before scanning a QR code from an unknown source, watch out for these signs:
- Stickers or overlays: a QR code stuck over another poster, invoice, or sign, especially in public places like parking meters, restaurants, or advertising boards.
- Shortened URLs or strange domains: after scanning, check the address that appears before opening it; be wary of domains you don't recognize or of link shorteners without context.
- Urgency or a prize: messages like "scan now to claim your prize" or "your package is on hold, verify here" are common tactics to get you to act without thinking.
- Out-of-place context: a QR code in an email or letter you weren't expecting, or in a location where one wouldn't normally be.
Good practices before scanning
- Always check the destination URL shown by your phone before tapping to open it.
- Don't enter passwords, banking details, or personal information on a site you reached from a QR code of unknown origin, unless you fully trust the source.
- If the code is in a physical location, check that it isn't stuck over another code or the original sign.
- When in doubt, don't scan. Look up the information through another trusted channel instead.
LibreQR doesn't control the final content that QR codes created by other users point to, so verifying the destination before scanning is always the responsibility of the person scanning it.