A calm guide to how quishing works in the real world
Eric O’Neill | 8 min read
Published June 19, 2026
You are at a parking meter, already late, with traffic collecting behind you and your phone in your hand. The sign gives you the easy answer: scan here to pay. There is no person asking for trust, no suspicious email, no strange caller. Just a printed square in a setting that feels routine. That is why this works. Quishing and the broader QR code scam economy succeed by hiding a fake destination inside an ordinary physical moment. If you pay by phone, sign in from a posted code, check a package notice, scan a menu, or pass security advice along to family and co-workers, this matters to you. What follows is a practical case file: how the QR code scam starts, how mobile makes it easier to miss, where it shows up next, and which calm defenses are actually worth forwarding.

A routine public scan can hide a redirected destination, which is what makes a fake QR code so effective.
A QR code scam is not about the code
A QR code scam is rarely about the graphic itself. The code is only a shortcut. The real question is where it sends your phone and what that page asks you to do next. A fake code may be printed on a sticker and placed over the real one. It may lead to a payment page, a sign-in form, a package claim screen, guest Wi-Fi access, or an account verification step. The scam succeeds when the destination looks close enough to the setting that you keep moving instead of slowing down. In practical terms, quishing is a physical doorway into a mobile phishing flow.
That framing matters because the infrastructure behind modern scams is organized and reusable, not improvised one target at a time. As the FT reported, scam operations now resemble multinational enterprises that diversify and scale across regions.That same reporting noted that crime-as-a-service has lowered the technical bar for fraud, which helps explain why the QR code scam economy can spread so quickly through copied pages, scripts, and payment routes.
The con works because the task already feels familiar
The sequence is usually straightforward. First, the scammer chooses a place where people expect to scan quickly: parking, menus, parcel lockers, event entry, guest access, or a utility notice. Next, they insert a code or replace a legitimate one with a destination they control. Then the page asks for the next normal action: pay, log in, confirm a card, download a receipt, or fix a failed transaction. If the person complies, the operator gets card data, credentials, or a direct payment. After that first handoff, the fraud can widen into credential theft, account takeover, follow-up texts, or more convincing impersonation attempts. The trap opens because the task feels familiar before it feels risky.
The whole sequence works by preserving momentum and reducing doubt, which is why it adapts so well to a service model. The FT film on organized cybercrime describes syndicates that sell scam kits and subscriptions, making it easier to tailor familiar lures to new targets. A QR code scam fits that model neatly because it needs only a believable setting, a working redirect, and a page that asks for one more step.

A simple scam flow makes the mobile phishing handoff easier to see.
Mobile is the perfect stage for borrowed trust
Phones make this easier in quiet ways. The screen is small, so full URLs and domain clues get less attention. The setting is often rushed, public, and task-oriented, which lowers the chance that anyone will inspect the destination carefully. The scan also skips a useful moment of friction. If you typed the site yourself, you might notice the address looks wrong or the request feels out of place. On mobile, payment tools, autofill, and familiar interface patterns can make a fake page feel legitimate faster than it deserves. People are not ignoring risk so much as finishing a task they believe has already been vetted by the place around them.
That is also why these scams fit the pattern seen across Eric’s newsletter: the strongest traps are situational, not abstract. An ordinary object becomes the front door to fraud because the story around it feels complete. The fake QR code does not need to earn trust from scratch. It borrows trust from the menu stand, the meter, the package room, or the lobby sign already in front of you.
The next wave will appear wherever scanning comes first
Expect this to keep appearing anywhere people are trained to begin with a scan: restaurant tables and hotel check-in materials, parking and transit payment points, package pickup notices, event tickets, posters, lobby signs, and print notices that push the next step onto a phone. The forward-looking point is simple. As more legitimate businesses teach people to scan first, attackers only need to borrow the setting, not build trust from scratch.
The organized-crime angle matters here, too. In Love, Lies, and Labor Camps, Eric described modern scam infrastructure as a cartel with an HR department, built on reusable systems, quotas, and repeatable deception. The right response is not to fear every code. It is to reinsert one short verification step before the first tap.
The best defenses are short enough to forward
- Pause before paying or logging in from any QR code posted in public.
- Check the web address after the scan and before the next tap.
- Prefer the official app or a manually typed site for payments and sign-ins.
- Treat stickers, damaged placards, and unusually placed codes as reasons to stop.
- If a code leads to a login page, back out and enter through a known channel instead.
- When in doubt, ask the venue for the official payment or menu path.
These habits add a few seconds, but they restore the inspection step the quishing flow depends on removing.
Most people do not fail on the scan
Most people do not fail on the scan. They fail on the second click. The common mistake is assuming the physical setting proves the digital destination. Another is focusing on whether the QR graphic looks normal instead of whether the link and request make sense. A third is entering credentials because the page matches the moment, not because the domain is trusted. The trade-off is real: the safest path is slightly less convenient, especially when the legitimate service was built for speed. And there is an edge case worth keeping in view. Some businesses really do rely on QR-only menus or payment starts, so the answer is verification, not blanket refusal. Readers do not need a new rule for every code. They need a better pause point before the next tap.

A short verification habit matters more than perfect suspicion.
The real lesson is to slow the handoff
QR codes are not dangerous by themselves. They are efficient, and efficiency is exactly what scammers borrow. The QR code scam economy works when a familiar setting does the trusting for us. You do not need technical expertise to reduce that risk. You need one repeatable habit before the next tap: check the destination before you continue. That small pause brings scrutiny back into a moment built for convenience, and it is often enough to break the flow the scam depends on.
For more stories and practical lessons from the intersection of spycraft, scams, and cybercrime, subscribe to Spies, Lies & Cybercrime: https://spies-lies-cybercrime.ericoneill.net/
Frequently Asked Questions
Q: What is quishing in plain English?
A: Quishing is a QR-based phishing scam. The code sends you to a fake or misleading page that asks for payment, login details, or other sensitive information.
Q: Should I avoid every QR code I see?
A: No. The safer rule is to verify the destination before you continue, especially if the scan leads to payment, sign-in, or urgent account action.
Q: How can I tell whether a QR code is fake?
A: You often cannot tell from the code alone. What you can inspect is the setting, the condition of the sign or sticker, the web address after the scan, and whether the requested action makes sense for that moment.
Q: Why do QR code scams work so well on mobile?
A: Phones compress the details that help people spot problems, and public scanning moments are usually fast, distracted, and task-driven. That combination makes it easier to trust the page before you inspect it.
Q: What should I do if I already scanned one and entered information?
A: Stop the session, change affected passwords through the official site or app, contact your bank if payment data was involved, and monitor the account for follow-on messages or login attempts.