A QR code is a promise you can't read. It's a little black-and-white square that says "trust me, I'll take you somewhere good," and your phone believes it. Scammers noticed. In summer 2026 they've been slapping fake QR stickers on parking meters, mailers, and package labels, and the destination is typically a login or payment page dressed up to look like a brand you know.

What is "quishing," and why now?

Quishing is just phishing delivered through a QR code (the "Q" gives it away). Instead of a link you can hover over and read, you get a square of dots. Point your camera at it, and it quietly resolves to a web address. The whole design goal of a QR code is to hide the URL so you don't have to type it, which is convenient for restaurants and menus, and equally convenient for anyone who wants you to arrive somewhere without looking first.

This isn't a fringe trick. Microsoft's security team reported that QR code phishing was the fastest-growing email attack vector in the first quarter of 2026. Attack volume climbed from 7.6 million in January to 18.7 million in March, a 146% jump over the quarter. To put that in context, Microsoft detected roughly 8.3 billion email-based phishing threats in that same three-month window. QR codes are a small slice of that flood, but they're the slice growing fastest.

The delivery is shifting too. Per the same Microsoft report, QR codes embedded directly in the body of an email surged 336% in March 2026, and the share carried inside PDF attachments grew from 65% to 70% between January and March. A code buried in a PDF invoice sails past a lot of filters because, to the software scanning your mail, it's just a picture.

It isn't only email. This summer the FBI and FTC warned about a wave of travel and parking QR scams, where crooks stick a fake QR label right over the real one on a parking meter or a delivered package. You scan what looks like the official "pay here" code and land on a page that collects your card details instead. A different variant surfaced in China this month: a state-broadcaster investigation found criminals hijacking the expired web domains behind official public QR codes — on street lamps and even a park shuttle bus — so the original, legitimate codes started redirecting to scam and porn pages, as Sixth Tone reported.

A QR code is not a website. It's an instruction to go to a website, and you can't see which one until you're already on the way. That gap between scanning and seeing is the entire scam.

Why does it work so well?

A few things line up in the scammer's favor, and this plain-language explainer of QR phishing lays most of them out:

And it's getting easier for scammers to make convincing bait. AI-assisted phishing has climbed sharply, from about 4% of phishing in November 2025 to 56% in December 2025 by Hoxhunt's count (a roughly 14x rise, reported alongside smishing and voice-clone trends). Better fake pages, same delivery trick.

Where fake QR codes turn up

How to see where a QR code really goes

The good news: your phone almost certainly shows you the address before it opens it. The whole game is to slow down for the two seconds it takes to read that preview.

  1. Read the preview, don't tap it. When you point your camera at a QR code, most phones show the URL as a banner or notification first. Read that address before you tap through. If your camera opens links instantly, check for a setting to preview links first, or use a scanner app that shows the destination.
  2. Look at the real domain, not the whole address. The part that matters is the domain, the name right before the first single slash. In your-bank.secure-pay.info/login, the real domain is secure-pay.info, not your-bank. Read it right to left.
  3. Watch for the classic tells. The explainer above flags three: misspellings of a brand name, suspicious subdomains (the real brand name stuffed in front of an unrelated domain), and URL shorteners that hide the true destination entirely.
  4. Be suspicious of any code that asks for money or a login. A menu is one thing. A QR code that lands you on a payment or sign-in page, especially one you didn't go looking for, deserves a hard pause.
  5. On a physical code, check for a sticker. If the QR label peels, sits crooked, or is stuck over another one, treat it as fake and pay through the official app or website instead.
  6. Copy the address and check it. Long-press the preview to copy the link, then paste the domain into IP Tracker to get a second opinion in seconds.
A short link like bit.ly/xxxx tells you nothing about where you'll end up. If a QR code resolves to a shortener, that's a reason to slow down, not a reason to trust it.

How IP Tracker helps you check the destination

IP Tracker is a free Chrome extension. Once you've read a QR code's preview and copied the address, paste the domain (or a full email address, if the scam arrived by mail) into the popup. The free tier gives you 25 checks a day, with no account and no tracking. Only the value you paste is looked up.

For the destination domain, it runs the checks that are hard to do by eye. It normalizes look-alike characters and compares the domain against the official addresses of more than 120 widely impersonated brands, banks, payment and shipping companies, big tech, and more, so a lookalike like paypa1.com or a brand name buried in a suspicious subdomain gets named for what it is. It also shows whether Google Safe Browsing (Google's list of reported dangerous sites) has flagged the domain, how many security vendors flag it on VirusTotal, community abuse reports, and the domain's creation date. A domain registered a few days ago, which is common for the freshest scam pages, shows up as a supporting clue.

What it can't do is scan the QR code image for you. You still need to surface the address first, using your phone's preview, and then paste it in. IP Tracker checks the destination once you can see it.

What can't it do?

Honesty matters more than comfort here, so four limits worth knowing:

"Not flagged" is not the same as "safe." Every result is a signal for your judgment, not a verdict. IP Tracker names the tricks it can see in a domain. It can't scan the code for you, and it won't promise a page is safe.

A QR code trades a link you could have read for a square you can't. That trade is fine at a restaurant table and dangerous on a parking meter. The fix is the same either way: make your phone show you the address, read the real domain, and check it before you hand over anything.

To summarize:

Scan smart! 😎