Security guide

QR code phishing (quishing): how attacks work and how to stop them

QR codes look harmless, but they hide the destination URL. Attackers exploit that trust with sticker overlays and forged codes — especially on restaurant tables, parking meters, and payment posters.

How a QR code scam usually works

  1. An attacker prints a malicious QR sticker that looks legitimate.
  2. They place it over a real menu, parking, or payment QR code.
  3. Victims scan and land on a fake login or payment page.
  4. Credentials or card details are stolen — often before anyone notices.

Why normal QR generators cannot stop this

A classic QR code is just data (usually a URL). There is no issuer identity, no tamper check, and no revocation. If the sticker is replaced, the phone happily opens the attacker’s page.

Stopping QR phishing requires secure QR codes that carry a cryptographic signature and a public verification step.

How QRalo blocks quishing

  • Signature: each code is signed with Ed25519 by your organization.
  • Verification: scanners check the signature before redirect.
  • Status: expired or revoked codes fail verification instead of silently opening.
  • Visibility: customers see who issued the code — not just a raw URL.

High-risk places to protect first

What customers should do

Use a verifier when available. With QRalo, anyone can open the scanner or follow our guide on how to verify a QR code before trusting a payment or login page.

Replace vulnerable QR codes today

Generate signed QR codes for free and give customers a clear authenticity check.

Start free with QRalo