Information Security

Learn about the scam that uses your phone's camera to steal data

Understand how Quishing works, a scam that uses QR Codes to steal personal and financial data. Learn what security measures to adopt to avoid risks

10/13/2025

Leonardo Fróes

The QR Code has consolidated itself as one of the most practical tools of modern digital life. Present on restaurant menus, transportation hubs, contactless payments, and even in marketing campaigns, it has become part of daily life. But its popularity has also attracted scammers.

A new type of fraud, known as Quishing, combines QR Code technology with phishing tactics to deceive users and steal personal and financial data.

Below, we explain what Quishing is, how it works, the main risks involved, and what measures can help prevent a simple camera scan from turning into a major security problem.

What is Quishing and why it is a concern

The term Quishing combines "QR Code" and "phishing" and describes a digital fraud that has been gaining ground worldwide. In this scam, criminals create or tamper with QR Codes to trick the victim into accessing fake websites, downloading malicious applications, or entering personal and financial data into fraudulent forms.

The big trap of Quishing lies in the appearance of legitimacy of the QR Code. Since the hidden link only appears after the code is scanned, the user has no way of verifying beforehand where they are being directed. This feature gives scammers a significant advantage, since many people automatically trust the technology and do not suspect the risks.

Unlike other better-known digital scams, such as suspicious links in emails or messages, Quishing exploits precisely the convenience that made QR Codes so popular. What should be a shortcut to simplify daily tasks, pay bills, access menus, or download applications, ends up becoming a quick path to data theft, banking information cloning, and malware installation.

The explosion of QR Code usage

The pandemic accelerated the digitization of daily habits, and QR Codes quickly became part of the routine. Restaurants replaced physical menus with digital versions, businesses began using them in promotions, and the financial system popularized instant payments via PIX with just a scan. In a short time, this simple and practical resource came to be seen as synonymous with convenience.

However, this mass adoption happened without proper concern for cybersecurity. Unlike traditional links, which can be inspected before clicking, QR Codes hide the destination address until the moment of scanning. This detail opened up space for criminals, who began to exploit user trust.

The numbers confirm the scale of the problem: 73% of people scan QR Codes without verifying their source, and more than 26 million have already been directed to malicious websites this way. In other words, the more natural the habit of "pointing the camera and clicking" becomes, the greater the vulnerability to scams like Quishing.

Most common Quishing techniques

Although the Quishing scam can take different forms, the logic is always the same: using the QR Code as bait to lead the victim to an environment controlled by the criminal. From there, personal data, banking credentials, or even the device itself are at risk.

Among the most frequent practices are:

  • Fake emails and messages: sent via SMS, WhatsApp, or email, they mimic official communications from banks, digital wallets, and delivery services, redirecting to fake login pages.

  • Tampered codes in public places: stickers are pasted over legitimate QR Codes in restaurants, parking lots, or transportation kiosks, steering the user to fraudulent websites.

  • Fraudulent packages and documents: they arrive at the victim's address accompanied by QR Codes that install malware or direct them to data collection forms.

  • Man-in-the-Middle attack: redirects the user through a data capture page before taking them to the real website, making the fraud less noticeable.

The success of these techniques relies on two factors: users' overconfidence in QR Codes and the difficulty of verifying where they actually point before scanning. This combination creates fertile ground for cybercriminals.

Consequences for victims

Quishing usually causes losses that go beyond the amount lost at the time of the fraud. Here are the most common consequences and why they can drag on for months or years:

  • Personal information theft: data such as name, address, phone number, and email can be collected and used for identity theft, creating accounts in the victim's name, or social engineering.

  • Financial compromise: banking credentials, card numbers, and passwords can be captured and used for transfers, online purchases, or account withdrawals. In many cases, transactions are only detected after financial loss has already occurred.

  • Device infection: the QR can lead to the download of malware, ranging from keyloggers and spyware that monitor activity to ransomware that encrypts files and demands a ransom. This affects both privacy and the continued use of the device.

  • Secondary fraud and data resale: obtained information can be sold on the dark web or used in subsequent scams (for example, fake payment requests to the victim's contacts), multiplying the damage.

  • Personal and operational impact: in addition to economic damage, there is time and cost with recovery (blocking cards, restoring backups, bank customer service), emotional stress, and loss of trust in digital services.

Quishing is rarely a one-time issue; it can trigger a cycle of losses. Therefore, when identifying a possible scam, it is crucial to act fast: notify banks and providers, change passwords, scan devices with antivirus, and report the incident to the police to increase chances of containment and recovery.

How to protect yourself from Quishing

Prevention is always the best way when it comes to digital scams, and Quishing is no exception. Following good security practices can drastically reduce the risk of falling into traps involving QR Codes. Among the main recommendations from experts are:

Verify the source of the QR Code before scanning: avoid codes received by email, messages, or social media from unknown senders. Always confirm if the code is legitimate, especially in payments or promotions.

Check if the code has not been tampered with in public places: criminals can paste stickers with fake QR Codes over legitimate codes in restaurants, transport hubs, or self-service kiosks. A close look can prevent unpleasant surprises.

Be suspicious of exaggerated offers or promotions: if a code promises irresistible discounts or prizes, it is important to treat it with caution. Scammers often use tempting incentives to induce quick clicks.

Check the URL after scanning: the site must start with https:// and correspond exactly to the institution or service you know. Any discrepancy or strange address should be considered suspicious.

Use secure scanning apps: some QR Code readers offer warnings about malicious links even before opening the browser, playing the role of an extra layer of protection.

Keep antivirus updated: having the latest security software on your phone helps identify and block malware that may be installed by malicious codes.

Avoid providing personal information on unknown sites: never enter banking details, passwords, or sensitive information on pages accessed via QR Code whose sender or origin you cannot confirm.

By following these simple practices, you can enjoy the convenience of QR Codes without giving up digital security. Continuous care and attention are the best defenses against Quishing.

Real cases draw attention

Digital security authorities, such as the FBI, have been drawing attention to the rise of Quishing scams, highlighting that they can affect both consumers and small businesses. Among the most common cases are:

Packages with fake QR Codes: delivered to homes, directing users to malicious websites that collect personal data or install malware.

Online sellers deceived: buyers send QR Codes supposedly for payment, but which lead to fake pages, such as PayPal clones, compromising transactions.

These examples show that Quishing is not limited to a specific audience. Consumers, entrepreneurs, and even companies can be targets, reinforcing the need for caution and digital education.

Why Quishing grows so fast

Experts point out that the growth of Quishing is directly related to the reduced effectiveness of traditional email phishing attacks. As companies implement stricter filters and advanced security protocols, criminals must find new ways to deceive users.

The QR Code emerged as an ideal tool for this: fast, practical, and seemingly harmless, it conveys a sense of trust.

In addition, the fact that the link destination is only revealed after scanning creates a perfect opportunity for malicious redirects, fraudulent app installations, and personal data theft, making Quishing a growing threat in the digital environment.

Increased attention in the era of QR Codes

Quishing is a warning that, in the digital environment, no technology is completely secure without user awareness. The practicality of QR Codes is here to stay, but it requires mindful checking habits before pointing the phone camera.

In addition to tools, it is necessary to invest in digital literacy; after all, educating users about risks, teaching good security practices, and promoting awareness about fraud is as important as the technology itself.

With information, attention, and protective tools, it is possible to enjoy digital conveniences without becoming a victim of criminals who turn convenience into an opportunity for fraud.

Shall we talk?

Select a date on our calendar and speak directly with one of our technology experts.

Shall we talk?

Select a date on our calendar and speak directly with one of our technology experts.

Shall we talk?

Select a date on our calendar and speak directly with one of our technology experts.

Shall we talk?

Select a date on our calendar and speak directly with one of our technology experts.

All Rights Reserved - CodeBit

São Paulo - SP

(11) 3014-2103

171 Paulista Ave, 4th floor, Bela Vista, São Paulo - SP

Franca - SP

(11) 3014-2103

5860 Emílio Paludeto Ave.
Vila Hípica, Franca - SP

Orlando - FL

+1 (980) 890-0026

7345 W Sand Lake Rd Ste 210 Office 2546

All Rights Reserved - CodeBit

São Paulo - SP

(11) 3014-2103

171 Paulista Ave, 4th floor, Bela Vista, São Paulo - SP

Franca - SP

(11) 3014-2103

5860 Emílio Paludeto Ave.
Vila Hípica, Franca - SP

Orlando - FL

+1 (980) 890-0026

7345 W Sand Lake Rd Ste 210 Office 2546

All Rights Reserved - CodeBit

São Paulo - SP

(11) 3014-2103

171 Paulista Ave, 4th floor, Bela Vista, São Paulo - SP

Franca - SP

(11) 3014-2103

5860 Emílio Paludeto Ave.
Vila Hípica, Franca - SP

Orlando - FL

+1 (980) 890-0026

7345 W Sand Lake Rd Ste 210 Office 2546