We’ve covered phishing (fake emails) and smishing (fake texts) in past tech corners, and now there’s a new one to add to the list: “quishing,” or QR code phishing. If you’ve scanned a QR code at a restaurant table, on a parking meter, or in an email lately, this one is worth your attention.
QR codes exploded during the pandemic as a touch-free way to pull up menus, pay for parking, or connect to Wi-Fi, and they’ve stuck around ever since. Scammers have taken notice. Quishing attacks are reported to be up roughly 146% in just the first part of this year, and one survey found that about 73% of Americans scan QR codes without ever checking where they actually lead. That gap between how much we trust QR codes and how little we verify them is exactly what scammers are counting on.
How it typically works:
- Physical stickers: Scammers place a fake QR code sticker directly over a legitimate one on parking meters, restaurant table tents, or charging stations. You think you’re paying for parking; you’re actually handing over your card details to a stranger.
- Fake notices: Some scammers mail or post “official-looking” notices, like fake traffic tickets or toll violations, with a QR code urging you to “pay now” or risk added fees.
- Email and text codes: Instead of a clickable link (which security software is good at catching), the scam email embeds the malicious link inside a QR code image, which many filters can’t read.
- The “switch” trick: Some codes are designed to point somewhere harmless when first sent, then get quietly redirected to a scam site after they’ve already cleared your email’s security scan.
Once you scan one of these, you’re usually led to a fake login page, payment page, or app download built to steal your credentials, credit card number, or personal information.
A few tips to protect yourself:
- Before you tap, look. Most phones show a preview of the web address before opening it. Read it carefully. If it looks off (misspelled brand name, random letters, an unfamiliar domain), don’t proceed.
- Check for tampering. On parking meters or public signage, look for a sticker that seems slightly raised, crooked, or placed over another code.
- Skip QR codes in unexpected emails or texts, especially ones creating urgency, like a “ticket,” “toll,” or “delivery issue” you need to resolve immediately.
- Go direct instead. If a QR code claims to be for your city, bank, or a company you use, skip the code and type the company’s known website or app directly.
- Never enter sensitive info right after scanning. If a page asks for a password, credit card, or Social Security number immediately after you scan a code, treat that as a red flag.
QR codes themselves aren’t the problem, they’re just a tool, and a genuinely convenient one. The lesson here is the same one we keep coming back to in this column: slow down for a second before you tap, click, or scan. That little pause is usually all it takes to spot a scam before it spots you.
Any content, resident submissions, guest columns, advertisements, and advertorials are not necessarily endorsed by or represent the views of Best Version Media LLC (BVM) or any municipality, homeowners associations, businesses, or organizations that this publication serves. BVM is not responsible for the reliability, suitability, or timeliness of any content submitted, inclusive of materials generated or composed through artificial intelligence (AI). All content submitted is done so at the sole discretion of the submitting party.





