What is quishing, and why is it spreading in Europe?
Quishing (QR-code phishing) is simple: criminals place malicious QR codes in the real world or in messages, and the code points your phone at a fake website that steals passwords, card numbers, or multi-factor codes. Because the link is hidden inside the code's pattern, all your email-trained instincts about suspicious URLs stop working.
Europe is fertile ground for it. QR payments exploded at restaurants, cafés, parking meters, and tourist spots across the continent; parcel volumes keep rising with e-commerce; and contactless habits from the pandemic never faded. Fraudsters follow that volume. Europol — including its European Cybercrime Centre (EC3) — and ENISA, the EU's cybersecurity agency, have both flagged QR-code phishing as one of the growing fraud techniques in their threat reporting. No agency claims any single figure, but the direction is consistent: more QR codes in daily life means more malicious ones mixed in.
The good news: quishing fails the moment you slow down. Nearly every attack relies on one of the red flags below. Learn them once and you'll spot the pattern everywhere.
Flag 1 — The sticker-over-sticker on a parking meter
🧷 A code that looks freshly applied on top of the original
This is the classic quishing trick. Scammers print their own QR sticker and slap it over the legitimate code on a parking meter, EV-charging station, or ticket machine. You think you're paying the city; you're paying a criminal. Run a fingernail across the code — if an edge lifts, the layer beneath is different, or the placement looks crooked, pay through the official app or website instead of scanning.
Flag 2 — Fake parking tickets tucked under your windscreen wiper
🎟️ A "fine" with a handy QR for instant payment
Reported across several European cities: you return to your car and find what looks like a parking fine, complete with an official-looking QR code offering a "quick discount if you pay now." Real fines never work like this — municipalities send fines by post or through official channels, not surprise QR slips. Never pay a wiper ticket by scanning; verify any fine on the official city website.
Flag 3 — Fake parcel-delivery cards
📦 "We missed you — reschedule with a small fee"
A card through the door or an SMS claiming your parcel needs a small redelivery fee, with a QR code to pay it. Europe's huge e-commerce volumes make this endlessly repeatable. Real carriers never ask for surprise fees via a QR code on a card. Go to the carrier's official site and track the parcel number there — or call the number on their verified website.
Flag 4 — Restaurant menu stickers promising "fast checkout"
🍽️ Table tents swapped for fraudulent payment pages
Swapped-out table tents or menu stickers offer a too-convenient "scan to view the menu and pay." The fake page harvests your card details or login. At restaurants and cafés, prefer paying at the till or through the official app of a known provider — and if the menu code is a fresh sticker on a table that never had one, ask the staff before scanning.
Flag 5 — Crypto giveaway codes — "double your coins"
🪙 Free crypto, celebrity endorsements, limited-time offers
QR codes promising a crypto giveaway, airdrop, or "send 0.1 ETH, get 0.2 back" are never legitimate. Crypto transactions are irreversible — once sent, they're gone. These codes appear on social media, flyers, even stickers in public places. The rule is absolute: no real giveaway asks you to send crypto first.
Flag 6 — Unexpected codes in emails and messages
📧 "Verify your identity" or "reset your MFA"
Quishing moved online too: emails or messages asking you to scan a code to "verify your account," "reset two-factor authentication," or "confirm a payment." Legitimate banks and services almost never ask you to scan a QR code sent in an unexpected message. Treat it like any phishing email: navigate to the official site yourself, never follow the code.
Flag 7 — The preview URL doesn't match
🔍 Read the link your phone shows before you tap
Every modern phone camera shows a preview of the destination URL before opening it. Read it. Watch for misspelled brands (paaypaI.com), odd extensions (.xyz, .top instead of .de/.fr/.com), random characters, URL shorteners where a brand name should be, and any "https" that doesn't actually load the official domain. If anything looks off, close the preview and type the address manually.
Flag 8 — Artificial urgency or a too-good-to-be-true offer
⏰ "Pay within 24 hours" / "You won a €500 voucher"
Scammers create pressure because pressure shuts down judgment: expiring fines, account suspension warnings, limited-time prizes. Any QR code that makes you feel rushed deserves extra suspicion. Legitimate organizations give you time; fraudsters don't. When you feel the rush, that's your cue to stop and verify through official channels.
Flag 9 — The landing page wants everything, immediately
💳 Passwords, full card details, or downloads on page one
After scanning, a page that instantly demands your login, full card number with CVV, one-time passcodes, or asks you to download an app outside the official store is a fraud page. Real payment flows explain what you're paying for first. Close the page — do not "test" it by entering partial details.
I scanned a bad code — what now?
Don't panic. Scanning alone almost never infects a phone — the damage happens only if you entered data or downloaded something. Act in this order:
- Close the page immediately. Don't enter anything else and don't download anything.
- If you typed in passwords: change them now, starting with your email (your email unlocks password resets everywhere), then banking and social accounts. Turn on two-factor authentication where available.
- If you entered card details: call your card issuer at once using the number on the back of your physical card — never a number from the suspicious site. Freeze or replace the card and watch statements for unfamiliar charges.
- If you downloaded something: delete the file, don't open it, and run your phone's security scan.
- Document evidence: take a screenshot of the page and note where the QR code was and who sent it.
- Report it: tell your bank first, then report to your country's national cybercrime or fraud reporting portal — most EU countries run one, and national police pass serious cross-border cases to Europol. Reporting helps get the fake site taken down before others scan it.
- Monitor: enable transaction alerts on your banking app and check statements over the next weeks. EU payment rules (notably PSD2) give consumers strong protections on genuinely unauthorised transactions — reporting quickly strengthens your position.
Safe-scanning habits that take 3 seconds
- Inspect before you scan: tampered sticker, bubbling, misalignment, or a code that doesn't belong there — don't scan.
- Read the preview URL every time before tapping "open."
- Context check: does this business normally take QR payments? Ask staff when unsure.
- Use official apps for parking, banking, and payments instead of random public codes.
- Type sensitive addresses manually for banking and government services.
- Keep your phone updated and two-factor authentication on for email, banking, and payment accounts.
- Generate your own codes when you share links — a QR code built from a trusted source is one you know is safe.
📥 Free download: Safe QR-Scanning Checklist
A one-page pocket checklist of all 9 red flags + the after-scan steps — print it, stick it on the fridge, share it with family.
Make your own safe QR codes
The safest QR code is one you create yourself. Our free QR Code Generator builds codes entirely in your browser — for your links, text, contact details, or Wi-Fi credentials — with nothing stored or sent anywhere. Share your own codes confidently, and scan everyone else's with the habits above.