Be Careful of Quishing

QR Code Phishing Is On The Rise

And quishing is something you need to be careful about

Quishing is now more of a problem, because the use of QR Codes to promote events and businesses is now very popular. QR codes are quick and easy to create, and give everyone with a Smartphone easy access to event and company webpages, flipbooks, menus, special offers, product information, etc, etc, etc.

Criminals have noticed the trend, and are now creating and spreading QR Codes that take the unknowing user to fraudulent websites, fake login pages and websites that deliver malware. Everything an email phishing attack did, thus the name Quishing.

They Normally Get Past Spam Filters

The challenge with QR codes is that malware software and anti-spam software don’t see any code – just an image. It’s when you click on the QR code that the code with the link gets activated. So anti-spam software can’t warn you that the email is dodgy.

Often, the malware is on the website the QR Code takes you to, not the actual QR Code itself. It is when you get to the website you are asked to enter personal details, or click on links that will download malware.

So How Do You Stay Safe Quishing?

Protecting yourself from Quishing is no different to protecting yourself from phishing emails.

  1. Be aware that quishing is a threat
  2. Check the details of the email address are correct
  3. Look for bad English – incorrect spelling, bad grammar
  4. Check the url of the website that the QR Code has taken you to
  5. Be extra careful before entering personal information and making payments
  6. Be extra careful before downloading anything through a site accessed by a QR code

You need to be aware that there is the threat and then be vigilant. QR Codes take you to a website, so when you get there check it out.

  • Is it the website you are expecting?
  • Is it reasonable for them to ask you to download an app?
  • Would you expect them to ask you for your password?
  • Be extra cautious if they are asking you to make any payment.

All the questions you would ask if you clicked on an email that took you to a website.

My hope is that just warning you that there is this increasing threat will enable you to protect you from being caught by quishing.

February 2025