QR Code Scams (Quishing)
Scammers distribute malicious QR codes that, when scanned, redirect users to phishing websites designed to steal credentials or install malware .
QR Code Scams (Quishing): The Invisible Digital Trap
With the rise of contactless technology, QR codes have become a convenient way to access payments, menus, and digital services. But cybercriminals are exploiting this trust through "Quishing" — a blend of QR codes and phishing.
What is Quishing?
Quishing involves scammers creating and distributing fake QR codes. These codes, once scanned, redirect users to phishing websites designed to:
-
Steal login credentials
-
Install malware
-
Capture financial information
-
Hijack mobile devices
Attackers often paste these QR codes over legitimate ones in public places like restaurants, payment booths, parking meters, event posters, and even ATM machines.
How the Scam Works:
-
The user scans a QR code thinking it’s legitimate.
-
They are redirected to a site that looks like a real app or payment gateway.
-
The site prompts for login or payment details.
-
Once entered, the information is stolen and misused for fraud.
Real-World Example:
In 2024, multiple cases were reported where fake QR codes placed on electric bill payment centers led users to phishing portals that drained bank accounts. Similar scams now target UPI platforms, Paytm, GPay, and more.
Red Flags to Watch Out For:
-
QR code stickers pasted over original print
-
Websites with odd URLs or spelling errors
-
Requests for login credentials or payment immediately after scanning
-
No visible brand or verification on the QR interface
Safety Tips to Prevent QR Code Scams:
-
Verify the Source: Always check if the QR code is printed on an official or tamper-proof material.
-
Use Trusted Apps: Use official QR scanning apps that warn about suspicious links.
-
Avoid Auto-Actions: Don’t allow QR codes to automatically download files or apps.
-
Preview Links: Some mobile browsers show a link preview before redirecting — always check it.
-
Use Antivirus Software: Mobile security apps can warn about suspicious links or downloads.
How to Report QR Code Scams:
If you fall victim or detect a scam attempt:
-
File a complaint at cybercrime.gov.in
-
Report the QR code to the platform or business involved
-
Alert others through social media to prevent further fraud
QR code scams are silent, quick, and effective — which makes them dangerous. But with awareness and a cautious eye, you can avoid becoming a target.