Skip to content

Guide

Quishing: how to spot fake QR codes

A QR code does not reveal where it leads until you scan it. That is exactly what fraudsters exploit in quishing, a word made up of QR code and phishing. The good news: one look at the address exposes almost every fake.

Last updated:

How the scam works

The code leads to a page that looks like the one run by your bank, the car park operator or the charging point provider. There you are asked to log in or pay by card. The details end up with the fraudsters, and the thing you actually wanted, a parking ticket or a charge for your car, never arrives.

There are three reasons it works:

  • A QR code doesn’t show where it leads. You can read a link in an email, but not a pattern.
  • On a phone, the address bar is short. A long, suspicious domain is only half visible there.
  • Codes on machines, signs and letterheads look official. If you just want a parking ticket quickly, you don’t check for long.

The most common scams

Germany’s consumer advice centres (Verbraucherzentralen) collect the cases on their Phishing-Radar. These keep turning up:

  • Codes stuck over on parking machines. In February 2025 a 76-year-old man in Munich scanned the code on a parking ticket machine and entered his credit card details. Instead of a parking ticket, he got the confirmation for a gym subscription. The police then found more tampered codes in the city centre, as the Bavarian police report. In Munich, parking fees can’t be paid by QR code at all.
  • Charging points. A sticker over the real code leads to a replica payment page.
  • Fake parking fines. Tucked under the windscreen wiper is a penalty notice with a QR code for easy payment. Some cities really do offer this, and that is exactly what the forgers exploit.
  • Letters from your supposed bank. A letter on genuine-looking letterhead asks you to “update” your online banking or set up a security procedure again, conveniently by QR code.
  • Emails and posters. Supposed prize draws, blocked accounts, parcel notifications. Fake posters have already appeared on buses and trains, promising a Deutschlandticket, Germany’s nationwide travel pass, as a prize.

How to check a code before you open it

  1. Read the address first, then tap. The camera app on iPhone and Android shows the destination before opening it. What matters is the part directly before the first single slash: parking.example.com/pay belongs to example.com, whereas example.com-pay.net/parking belongs to com-pay.net. A hyphen in the right place is all the deception needs.
  2. Look out for stickers. If the code is on a second sticker, the edges are uneven, it bubbles or it doesn’t match the rest of the sign, leave it alone.
  3. Check the context. Does the operator offer payment by QR code at all? If in doubt, pay at the machine or through the official app that you downloaded yourself from the App Store or Play Store.
  4. No login details via a code. If a code leads to a login page, for your bank, a payment service or your email account, say, close it. Log in through the app or at an address you type in yourself.
  5. Check with the sender. For letters, call the number you already have, from your bank card for example. The number in the letter can be just as fake as the code.
  6. Don’t pay parking fines by code. If you are unsure, ask the local public order office (Ordnungsamt) or take the notice to the police. A genuine fine can also be paid by bank transfer.

Incidentally, you don’t need a separate scanner app. The camera on iPhone and Android reads QR codes out of the box. Some free scanner apps in the stores mostly show adverts or push you towards a subscription.

If it has already happened

  • Call your bank straight away, or have your cards blocked through the German card-blocking hotline 116 116, and with many banks your online banking access too. The faster you act, the better the chance of stopping a payment.
  • Change your password if you entered login details. That goes for the affected account and for every other one where you use the same password.
  • Report it to the police. You can do that at any police station, and also through the online police station that every German state runs.
  • Keep evidence: a photo of the code and its surroundings, the letter, screenshots of the page. After that, keep an eye on your bank statements for the next few weeks.

If you put up codes yourself

If you display QR codes in public, you can make things harder for forgers and easier for your customers:

  • Print the address legibly next to it. “Goes to example.com/menu” under the code lets people compare it with the preview on their phone. A code that has been stuck over then stands out immediately.
  • Your own domain rather than someone else’s short address. A code that redirects through a QR provider’s server looks exactly like a fraudster’s in the preview. Why an address on your own domain is the better choice for other reasons too is explained in the article on dynamic QR codes.
  • Check your notices regularly. Is anything stuck on the code? Behind glass or acrylic it cannot be swapped out, and a sticker on the pane is easier to spot. Make it anti-glare, though, or the reflection will stop it scanning.
  • Transfer codes on invoices. Here the banking app shows the payee and IBAN before you approve. Since October 2025, banks in the euro area also check whether name and IBAN match, and warn when they don’t. But that only protects people who actually read the warning. There is more on this on the page about the QR code for bank transfers.

No reason to avoid QR codes

A QR code is just another way of writing a link. The same scams run by text message, email and messaging apps. The difference is that with a code, it takes one more step to see the destination. Get into the habit of reading the address before you tap, and you will unmask almost any fake in two seconds.

Advertisement

More from the guide