Quishing campaigns have moved from email attachments to physical stickers. Understanding the multi-hop redirect chain — and how to decode it locally — is the best defence.
A QR code is opaque to email security gateways, web proxies, and content filters. By the time a user's phone decodes the pattern and opens a URL, no corporate security layer has seen the destination. That's the core reason quishing (QR phishing) has grown so fast — it sidesteps an entire category of infrastructure that organisations have spent years building and tuning.
The shift from email links to physical stickers is deliberate. A malicious URL in an email body can be blocked by a proxy, scanned by a sandbox, or spotted in a hover preview. A sticker on a parking meter offers none of those opportunities. The user scans it with a personal phone, often on a cellular connection that bypasses the corporate network entirely.
Parking meters. Attackers print fake QR payment stickers and place them over or next to legitimate ones. Users expect to be redirected to a payment portal, and a convincing fake site that mirrors the look of the local authority's payment page collects card details before showing a fake success screen. These campaigns are well-documented in the US (San Francisco, Dallas), UK, and Germany.
Restaurant table cards. The "scan to view the menu" convention has made QR codes invisible friction. A sticker placed on a table card redirects to a credential-harvesting page before bouncing the user to the real menu (a transparent iframe, or just a screenshot). Most users never notice.
EV chargers. Charge point operators use QR codes to initiate payment sessions. Spoofed stickers capture card details or OAuth tokens at the moment of highest distraction — when the driver is standing in a car park, phone in hand, trying to start a charge quickly.
The URL encoded in a malicious QR code is almost never the final destination. Attackers use multiple redirect hops to:
A typical chain looks like:
QR encodes: https://bit.ly/3xABCDE → 302 to: https://analytics.campaigntracker.net/r/abc123 → 302 to: https://secure-accounts-verify.com/uk/parkin → FINAL: credential harvesting page
The first two URLs are reputable domains (link shortener, analytics service) that would pass most reputation checks. The final hop is a disposable domain registered days before the campaign.
The safest approach is to decode a QR code's content without opening the URL. Purpose-built tools can read the raw bytes from a QR image and display the encoded string before any network request is made. This is how you evaluate whether a QR code is safe:
pay-ment.co.uk
parklng.app
servIce.com
Reputable charge point networks, parking operators, and restaurants encode direct URLs with their own domain — no shorteners, no redirect chains. If a QR code in a public space routes you through a link shortener before a payment page, stop and report the sticker.
Physical QR campaign stickers are easy to remove and replace. If you notice a sticker on top of another sticker, or a sticker that looks freshly applied on aged equipment, don't scan it.
The next generation of quishing attacks are already in circulation. Attackers have started encoding URLs that use Unicode right-to-left override characters in the domain — visually rendering as one string but resolving as another. Others use Punycode internationalized domain names that appear identical to English brand names in most font renderings.
The browser address bar remains the last line of defence, but most mobile browsers collapse the URL bar after navigation begins. By the time a user thinks to verify the domain, they're already on the page.