QR QR Studio

news

Quishing in 2026: what the FBI, FTC and Microsoft have said and how to scan safely

Published 7 September 2026 · 2 min read

“Quishing” is phishing by QR code. The code carries a link to a fake login page, a fake payment page or a malware download, and the attack works because a QR code hides the address until you scan it. Here is what the authorities said over the last year, and what to do about it.

The advisories

  • FBI IC3, 31 July 2025. A public service announcement about packages arriving unsolicited with a QR code inside, inviting the recipient to scan to find out who sent the gift. The code led to sites harvesting personal and financial information. IC3 PSA.
  • FTC, April 2026. A consumer alert about text messages claiming an unpaid traffic violation, some using QR codes and links to fake payment portals. FTC alert.
  • FTC, August 2026. A follow-up on “brushing” scams, unsolicited parcels with QR codes, echoing the FBI’s warning.
  • Microsoft, 2026. Microsoft’s threat intelligence reported QR-based phishing attempts rising from 7.6 million in January 2026 to 18.7 million in March 2026, with about 70% delivered as PDF attachments. Cited via Keepnet Labs; treat vendor-reported numbers as indicative.
  • Parking-meter stickers. Cities in the United States and the United Kingdom continue to report fake payment codes stuck over genuine ones on parking meters. The attack needs no technology beyond a sticker printer.

Why QR codes are attractive to attackers

Email filters read text and links. A QR code in an email or a PDF is an image, so the malicious address hides from the filter and moves the victim from a monitored work laptop to a personal phone. On a poster or a meter, a sticker costs pennies and needs no hacking at all.

The five habits

  1. Read the address. Your phone shows it before opening. Take the second.
  2. Be suspicious of urgency. Fines, parcels, prizes and account lockouts are the standard bait.
  3. Prefer the app. For parking, banking or deliveries, open the official app instead of a code on a sticker.
  4. Never enter credentials from a scan. If a code leads to a login page, close it and go to the site directly.
  5. Look at the sticker. A code on a label stuck over another label, or one that does not match the branding around it, is a red flag.

Try it in QR Studio

QR Studio’s scanner shows the full destination before opening anything and sends nothing about your scans anywhere. The free decoder tool does the same for a code in a photo or screenshot.

The security explainer goes deeper on how each attack works and what businesses can do to protect their own codes.

Frequently asked questions

Can a QR code itself infect my phone?

No. A QR code is text. The risk is where the text sends you, or what it asks you to do there. Your phone shows you the address first; that preview is the safety check.

How do I check a code before opening it?

Read the domain in the preview banner. If it is a shortened link or an unfamiliar domain on something official-looking, do not open it. Our free decoder shows the full text of any code from a photo.

What should a business do?

Print your name and logo as part of the code design, put codes behind laminate rather than as stickers, and check them each shift. A plain sticker over your branded code stands out.

Make yours in QR Studio

Unlimited static codes free, no ads, no watermark. AI design, dynamic codes and print-ready export when you need them.

Download on the App Store