S.M.M.

Stop Manipulating Me · A Field Guide to Psychological Influence

ENTRY No. T14.23
CATEGORY Social Engineering
CLEARANCE Public / Essential
EDITION 01
Dossier · Manipulation Tactic

QR-Code Lures

Digital Lure · Quishing · Rising
High Alert
How It WorksSEC 01

QR-code lures — “quishing” — use a malicious QR code, printed, displayed, or embedded in a message, to redirect the scanner to a phishing page, a fraudulent payment, or a malware download. The whole trick is the repackaging: a person cannot read a QR code’s URL by looking at it, so the usual “inspect the link before you click” defense is unavailable at the moment of decision.

Two deployment patterns dominate. In the physical pattern, an attacker places or overlays a code where people expect to scan one — a sticker over a legitimate parking-meter, EV-charger, restaurant-menu, or payment QR; a fake “package could not be delivered” notice; a poster or flyer — so a routine, trusting scan lands on a fraudulent site. In the digital pattern, the code is embedded as an image inside a phishing email, letting the lure slip past URL-scanning filters (there is no clickable link text to analyze) and pushing the victim onto their phone — often a less-managed, less-protected device.

Because scanning shifts the interaction to a mobile browser with a small screen and truncated address bar, the downstream page benefits from the same reduced-scrutiny conditions as smishing. The recognition constant: an unexpected or out-of-place code, or one urging you to scan-and-act quickly, that leads somewhere you can’t verify in advance.

Warning SignsSEC 02
  • A code where you didn't expect one. A QR code embedded in an email asking you to scan with your phone, or on an unsolicited notice.
  • A sticker applied over an existing code. A code that looks overlaid, misaligned, or covering surrounding text — a tampering tell on public payment surfaces.
  • An unpaid-fee or missed-delivery hook. A code on an "unpaid toll/invoice" or "package could not be delivered" slip.
  • The scan lands on a login or payment. A resulting URL that is a look-alike or shortened domain, or that immediately asks for credentials or payment.
  • Urgency to scan-and-pay. "Scan to avoid a fine / claim before it expires / pay now."
  • You can't verify the destination first. The core weakness: the code's target is unreadable to the eye before scanning.
Frequently Paired WithSEC 03
  • Phishing · T14.2
    The parent technique the code delivers
  • Smishing · T14.9
    Sibling vector sharing the mobile-scrutiny weakness
  • Fake Support Portals · T14.22
    The credential-harvest page a code leads to
  • Package / Delivery Scams · T24.9
    QR-bearing fake notices
How the Attack UnfoldsSEC 04
  • Stage 01 · Placement
    A malicious code is placed where a scan is expected — an overlaid sticker on a payment surface, or a code embedded in an email.
  • Stage 02 · Reflex Scan
    The routine, trusting scan fires without inspection; the destination is unreadable to the eye and often shifts you to a less-protected phone.
  • Stage 03 · Landing
    The scan lands on a fraudulent payment or credential-harvest page under small-screen, low-scrutiny conditions.
Counter-ProtocolSEC 05
Defense: Preview the destination, and don't scan unsolicited or out-of-place codes.
  • Preview the URL before opening. Use a scanner (most modern phone cameras do this) that shows the destination link, and read it — treat any credential or payment request reached via QR as a phishing link.
  • Don't scan out-of-place codes. Skip codes in unexpected emails, on unsolicited notices, or that look like stickers overlaid on a surface; inspect physical codes for tampering.
  • Pay through official channels. For payments and parking, use the merchant's official app or a keyed-in official URL rather than a posted code.
  • Navigate to accounts via bookmarks, not QR destinations, and rely on phishing-resistant MFA / passkeys so a harvested credential fails.
  • Report tampered codes to the venue, and apply mobile threat defense and URL filtering on managed devices.