Skip to main content

What Is Quishing? The QR Code Scam Google Just Issued a Warning About in 2026

What Is Quishing? The QR Code Scam Google Just Issued a Warning About in 2026

QR code phishing emails jumped 5x in just three months, and Google's own June 2026 advisory calls it out by name. Here's exactly what quishing is, why it beats spam filters, and how to scan safely in 2026.

"What is quishing?" is one of the fastest-rising security questions people are typing into Google right now, and for good reason, this isn't a fringe threat anymore. Google's own June 2026 fraud and scams advisory specifically named quishing as one of the techniques reshaping how phishing reaches Gmail inboxes, and the data behind it is striking: QR-based phishing emails climbed from roughly 46,000 in August 2025 to about 250,000 by November, a fivefold jump in just three months. This guide answers exactly what quishing is, why it slips past defenses that catch normal phishing, and the specific habits that keep you safe from it.

What Does "Quishing" Actually Mean?
Quishing combines "QR code" and "phishing" into a single term describing a specific attack method: instead of embedding a clickable malicious link directly in a text message or email, scammers hide that same malicious destination inside a QR code. The underlying goal is identical to any phishing attack  stealing login credentials, payment details, or personal information, or installing malware on your device. What changes is purely the delivery mechanism, and that single change is precisely what makes quishing so much harder to catch.

Why Does a QR Code Bypass Security That Would Normally Catch a Scam Link?
This is the central question behind why quishing has exploded so quickly, and the answer comes down to how security systems actually work. Traditional email security filters are built to scan visible text and parse readable URLs, flagging known malicious domains before a message ever reaches your inbox. A QR code is an image, not text. Because most filters aren't designed to decode and analyze the destination hidden inside a graphic, a malicious link embedded in a QR code routinely slips straight past defenses that would have caught the exact same URL if it had simply been written out as a clickable link.

There's a second, equally important shift happening at the same time: scanning a QR code moves the entire interaction from your computer, which is often protected by antivirus software and enterprise security tools, onto your personal smartphone, which is typically far less protected. This combination  invisible to filters, executed on a less-defended device  is exactly why security researchers describe quishing as attacking "the edge of the web and mobile," deliberately exploiting the gap between two different security environments.

Why Do People Fall for This So Easily?
QR Codes Don't Reveal Their Destination Before You Scan
A normal phishing link at least gives a careful person a chance to hover over it and inspect the actual web address before clicking. A QR code offers no such preview. The destination stays completely hidden until after your phone has already opened it, removing one of the most basic, widely taught scam warning signs people rely on.


Years of Normal Use Have Removed Natural Suspicion
Restaurant menus, parking meters, event check-ins, product packaging, contactless payments  QR codes have become so routine in everyday life that most people scan them automatically, without the same instinctive caution they'd apply to an unexpected email link. This normalization is exactly what scammers are counting on.

There's No Sender Name to Doubt
Unlike an email that might display a slightly wrong sender address, a QR code carries no visible identifying information at all. There's nothing obviously "off" to notice before scanning, since the code itself is just a printed or displayed pattern.

Where Are These Scam QR Codes Actually Showing Up?
Stickers placed directly over legitimate QR codes at parking meters, redirecting drivers to fake payment pages designed to steal card details

Fraudulent codes swapped onto restaurant tables, replacing a genuine menu code with one leading to a phishing page or malware download

Emails and PDFs disguised as invoices, delivery notices, or account alerts, using an embedded QR code instead of a standard clickable link specifically to evade spam filtering

Fake parcel delivery notices, asking recipients to scan a code to "confirm" or "reschedule" a delivery

Cryptocurrency scam ads, where on-screen QR codes direct viewers toward phishing forms or malicious software specifically flagged in Google's own June 2026 advisory

Posters and public signage in general, wherever a legitimate QR code could plausibly be swapped or covered without immediately looking suspicious

What Happens After You Scan a Malicious QR Code?
Once scanned, the code typically redirects your phone's browser to a convincingly designed fake website  often a near-identical copy of a real bank, delivery service, or login page, sometimes using a deliberately similar-looking domain name designed to pass a quick glance. From there, the attack usually follows one of two paths: either you're prompted to enter login credentials or payment details directly into the fake page, or the site prompts a file download that installs malware on your device without your full awareness of what's actually happening.


How Does This Connect to Google's Broader June 2026 Warning?
Quishing didn't appear in isolation, Google's advisory grouped it alongside a more advanced technique called Adversary-in-the-Middle, or AITM, attacks. In an AITM attack, a fake page sits directly between you and the real login service, relaying whatever you type to the genuine site in real time while quietly capturing both your password and your session cookie as they pass through. This is specifically what allows AITM-style attacks, sometimes launched through a quishing link, to defeat multi-factor authentication entirely  you complete the real verification step yourself, and the attacker simply uses the stolen session token to walk in behind you, without ever needing your MFA code directly.

Google has also flagged a related tactic called "Calendar Phishing," where fake renewal notices or malicious QR codes are inserted directly into Google Calendar invites, exploiting the fact that calendar notifications tend to be trusted and often auto-added without a second thought.

Is Scanning QR Codes Inherently Unsafe?
No  the QR code technology itself isn't the problem. The risk comes entirely from where a specific code leads, not from the format itself. Millions of legitimate QR codes are scanned safely every day for payments, menus, and check-ins. The danger is specifically tied to unexpected, unverified codes appearing in emails, unsolicited messages, or physical locations where a sticker could plausibly have been placed over a genuine one.

How to Protect Yourself From Quishing
Never Scan a QR Code From an Unexpected Email or Message
This is the single safety tip Google's own advisory leads with: treat any QR code arriving through an unsolicited email, text, or notification with the same suspicion you'd apply to an unexpected link, and avoid scanning it on your personal device.

Preview the URL Before Opening It
Most modern phone cameras display a preview of the destination web address before fully opening it after a scan. Take the extra moment to read that preview carefully, checking specifically for misspellings or unfamiliar domains rather than tapping through immediately.

Navigate Directly to the Official Website Instead
Rather than scanning a QR code claiming to lead to your bank, a delivery service, or an account page, open your browser separately and type the company's known, official web address directly, or use their verified app instead.

Inspect Physical QR Codes for Signs of Tampering
For codes encountered in public spaces  parking meters, restaurant tables, posters  check whether the code appears to be a sticker placed over another one, which can indicate a swapped, malicious code covering a legitimate original.

Use a QR Scanner With Built-In Reputation Checking
Some security-focused scanner apps check a destination URL against known malicious site databases before fully opening it, adding a layer of protection beyond your phone's default camera scanner.


What Should You Do If You've Already Scanned a Malicious QR Code?
Close the site immediately without entering any further information, if you haven't already submitted anything.

Avoid entering any personal or payment details if the page is still open and hasn't been interacted with yet.

Change any passwords immediately if you did enter login credentials, using the legitimate service's official app or website, not the scanned link.

Enable multi-factor authentication on the affected account if it isn't already active, for an additional layer of protection going forward.

Contact your bank or card issuer directly if any payment or banking information was submitted, using the number on your card rather than any contact detail from the suspicious page.

Run a security scan on your device to check for any malware that may have been installed during the interaction.

Frequently Asked Questions (FAQs)
Q1: What is quishing in simple terms?
Quishing is a form of phishing where scammers hide a malicious link inside a QR code instead of a regular clickable link, tricking people into scanning it and visiting a fake or dangerous website.
Q2: Why do QR code scams bypass email security filters?
Most email security filters are built to scan and analyze visible text-based links, but a QR code is an image, so the hidden malicious destination inside it often goes undetected until after someone scans it.
Q3: Are QR codes themselves dangerous?
No, the QR code format itself is safe. The danger comes entirely from where a specific code leads, meaning risk depends on the source and context of the code, not the technology itself.
Q4: Can a QR code scam bypass two-factor authentication?
Yes, when combined with an Adversary-in-the-Middle attack, a malicious QR code can lead to a fake login page that captures your session cookie in real time, allowing an attacker to bypass MFA without ever needing your verification code directly.
Q5: What should I do immediately after scanning a suspicious QR code?
Close the page without entering any information if possible, change any passwords you may have entered using the legitimate official site, and contact your bank directly if payment details were submitted.

Conclusion
Quishing represents a genuine evolution in phishing tactics, exploiting a simple but effective gap: security tools built to catch visible text-based links largely can't see the malicious destination hidden inside an image. With Google's own June 2026 advisory confirming this as an active, growing threat and data showing a fivefold increase in QR-based phishing emails within months, the most reliable protection remains straightforward  treat unexpected QR codes with the same caution as suspicious links, preview the destination before opening it, and navigate directly to official websites rather than trusting a scanned code to take you somewhere safe.

Comments

Popular posts from this blog

AI Job Scams in 2026: 7 Red Flags Every Job Seeker Must Know Before It's Too Late

AI Job Scams in 2026: 7 Red Flags Every Job Seeker Must Know Before It's Too Late AI-powered job scams have pushed losses past $500 million as deepfake recruiters and fake offer letters flood LinkedIn and email inboxes. Here are the 7 red flags that still expose them in 2026, and what to do if you've already been targeted. For years, job seekers were told that bad grammar and awkward phrasing were the easiest way to spot a fake recruiter. That advice no longer holds. Generative AI can now produce outreach messages, offer letters, and even live video interviewers that are functionally indistinguishable from the real thing. Reported losses from job search fraud jumped from $90 million in 2020 to more than $500 million in 2024, and industry researchers project that by 2028, roughly one in four candidate profiles circulating online will be entirely fake. This isn't a distant future risk  it's actively reshaping how hiring works right now, targeting new graduates...

AI-Generated Investment Scams: How Fake Crypto Platforms Are Stealing Billions in 2026

AI-Generated Investment Scams: How Fake Crypto Platforms Are Stealing Billions in 2026 Every year, artificial intelligence gets better at doing useful things  writing code, analyzing data, generating images. Unfortunately, scammers have been paying just as much attention to these advances as legitimate businesses have, and in 2026, they've turned AI into the most effective fraud tool the financial world has ever seen. What used to be obvious, badly-written scam emails have evolved into polished trading platforms with real-looking dashboards, AI-generated "proof" of returns, and even deepfake videos of celebrities and CEOs vouching for products that don't exist. The result is a wave of losses running into the billions of dollars, hitting everyone from retirees to tech-savvy young professionals who assumed they were too smart to fall for it. Understanding exactly how these scams work  not just that they exist  is the difference between recognizing one in the...

The New UPI Scam That's Draining Bank Accounts in Seconds: How It Works and How to Spot It

The New UPI Scam That's Draining Bank Accounts in Seconds: How It Works and How to Spot It UPI fraud has surged as scammers exploit fake customer care numbers, QR codes, and screen-sharing apps. Here's exactly how India's most common UPI scams work in 2026, real cases, and the 3-day rule that could save your money. A Bihar grocer lost ₹58,000 from his bank account without clicking a single link or receiving a single call. A Chennai user complained about a failed transaction on Twitter and had ₹1.8 lakh drained from his SBI account within minutes, after a fake "Paytm Care" account responded to his post and talked him into installing a screen-sharing app. A Jaipur street vendor scanned a QR code a "customer" sent him to receive payment  and instead authorized a debit. None of these victims were reckless. All of them fell for scams built around a simple, unchanging truth about UPI: the system is instant, irreversible, and requires the victim...