QR-code lures — “quishing” — use a malicious QR code, printed, displayed, or embedded in a message, to redirect the scanner to a phishing page, a fraudulent payment, or a malware download. The whole trick is the repackaging: a person cannot read a QR code’s URL by looking at it, so the usual “inspect the link before you click” defense is unavailable at the moment of decision.
Two deployment patterns dominate. In the physical pattern, an attacker places or overlays a code where people expect to scan one — a sticker over a legitimate parking-meter, EV-charger, restaurant-menu, or payment QR; a fake “package could not be delivered” notice; a poster or flyer — so a routine, trusting scan lands on a fraudulent site. In the digital pattern, the code is embedded as an image inside a phishing email, letting the lure slip past URL-scanning filters (there is no clickable link text to analyze) and pushing the victim onto their phone — often a less-managed, less-protected device.
Because scanning shifts the interaction to a mobile browser with a small screen and truncated address bar, the downstream page benefits from the same reduced-scrutiny conditions as smishing. The recognition constant: an unexpected or out-of-place code, or one urging you to scan-and-act quickly, that leads somewhere you can’t verify in advance.