Key facts (TL;DR)

Quishing (QR code phishing) is a scam in which criminals use malicious QR codes to steal credentials, TANs, payment data or money. Industry data show cases rose by over 600 % worldwide in 2026 — in Germany, documented incidents mainly involved parking meters, EV chargers, fake bank letters, mailbox stickers and windshield flyers. Authorities advise scanning QR codes only with a URL preview, or having the destination URL checked against phishing databases before the page opens.

Quishing: QR Codes as an Attack Vector

Quishing (a portmanteau of "QR code" and "phishing") is a form of phishing in which criminals use malicious QR codes as the attack vector. Where classic phishing relies on email or fake websites, quishing carries the malicious link inside a machine-readable QR code — printed, stuck on, or embedded as an image in an email.

Security authorities attribute the rise to the fact that QR codes are not human-readable. The black-and-white matrix gives no indication of where it leads — the destination only becomes visible once the smartphone has opened the URL. Spam filters and mail gateways cannot inspect the code either, because it is an image. Attackers exploit this double blind spot.

Definition: Quishing

Quishing is a phishing method in which attackers use manipulated or malicious QR codes to lure victims to fake websites, steal personal data, or distribute malware.

How a Quishing Attack Unfolds

A typical quishing attack proceeds in several steps:

  1. The attacker creates a malicious QR code leading to a fake website (for example, a copy of a bank's login page)
  2. The QR code is distributed through various channels: emails, fake parking tickets, flyers, social media, or stickers pasted over genuine QR codes
  3. The victim scans the QR code with a smartphone without recognizing the manipulation
  4. The victim lands on the fake website and enters sensitive data (passwords, credit card details, personal information) or unknowingly downloads malware

Documented Quishing Examples from Germany

QR Codes on Parking Meters

Perpetrators paste QR codes over those on parking meters. The links lead to imitation 'easy park' pages that request credit card data. According to police, the pasted-over codes are often hard to detect.

Phishing Emails with ADAC Logo

Emails carrying the ADAC logo contain QR codes leading to fake member pages designed to collect personal data and bank details.

Rheinbahn Deutschland-Ticket Scam

Fake posters in buses and trams advertised a supposedly free Deutschland-Ticket. The QR code led to pages that requested personal data.

Fake Bank Letters

Letters in Commerzbank design requested an alleged photoTAN activation via QR code. The target was online banking credentials.

EV Charging Station Scam

At electric charging stations, perpetrators pasted over the payment QR codes. The links led to phishing sites instead of the operator's payment page.

Fake Parking Fines

Fraudulent parking fines placed on vehicles contained QR codes leading to fake payment pages.

Warning Signs of Quishing

  • Unexpected QR codes in emails, particularly in the name of banks, Microsoft or Google
  • QR codes on parking meters or in public places that appear pasted over
  • Prompts creating time pressure ('Your account will be locked', 'Last chance')
  • QR codes from unknown senders on social media
  • URLs after scanning that look suspicious or do not match the expected company

Protection Against Quishing: Recommendations

  • Have Destination URLs Checked Before Opening: Specialized checker apps compare a QR code's destination URL against threat databases before it opens and warn of known phishing sites.
  • Use Apps with URL Preview: Scan QR codes only with apps that display the target address before opening the page. This makes suspicious links visible.
  • Pay Attention to Punctuation in URLs: 'example.com/123' is legitimate, whereas 'example.com-123.com' leads to a completely different, potentially fraudulent website.
  • Do Not Scan Pasted-Over QR Codes: QR codes on parking meters, charging stations or in public places that appear pasted over should not be scanned.
  • Check Letters and Emails Critically: For suspicious letters, for example from a bank, it is advisable to contact the institution via an independently researched phone number, not via details given in the letter.
  • What to Do in Case of Fraud: If you are affected, inform the police and your bank. In Germany, cards and online banking can be blocked via the hotline 116 116.

Quishing in Enterprises

For businesses, security firms consider quishing a significant risk, as employees are often the weakest link in the security chain. A single scanned malicious QR code can:

• Compromise company data • Bring ransomware into the network • Steal access credentials for critical systems • Cause compliance violations (GDPR, NIS2)

Conclusion

Quishing is a growing threat that uses QR codes as an attack vector. Because the code's destination is not visible before scanning, the method is considered difficult to detect.

Authorities recommend a combination of awareness, caution towards unexpected codes, and technical verification of the destination URL before a page is opened.

Check QR Codes Before Opening

QRTrust compares a QR code's destination URL in real time against multiple threat databases and warns of known phishing sites.

Try QRTrust for Free

Sources

This article is partially based on information from Verbraucherzentrale NRW:

Quishing: Fake QR Codes in Emails, Letters, Public Transport and Road Traffic

Quishing statistics 2026: figures for Germany and worldwide

Figures from the BSI threat report, police statistics and industry reports (as of Q1 2026) show a marked increase in quishing:

+614 %

more quishing attempts worldwide (Q1 2026 vs. Q1 2025, Keepnet)

18 M

detected quishing attacks in Q1 2026 alone (FBI / industry data)

12 %

of all phishing payloads contain a QR code in 2026 (2021: 0.8 %)

> €1 M

average loss per quishing incident in enterprises (Keepnet 2026)

83 %

of smartphone users scan QR codes without URL verification

40+

documented quishing case series in German cities since mid-2025

Quishing, phishing, smishing and vishing compared

The phishing family comprises four main variants. They differ in the channel used — the goal is the same in each case: stealing data or money.

VariantChannelTypical example 2026Detectability
PhishingEmailFake bank email with login linkMedium — spam filters help
SmishingSMS / messengerDHL SMS with tracking linkDifficult — barely any mobile filters
VishingPhone / VoIPCall from 'Microsoft support'Difficult — no technical filter
QuishingQR code (print/digital)Sticker on a parking meter or bank letterParticularly difficult — URL is invisible

Quishing in Germany: documented cases 2025–2026

The following cases are documented. Each entry links to a full report with sources, police and BSI references, and protection advice:

Frequently asked questions about quishing (FAQ)

What does quishing mean?+

Quishing is a portmanteau of 'QR code' and 'phishing'. It describes phishing attacks in which criminals use malicious QR codes to lure victims to fake websites, steal credentials or TANs, or distribute malware.

How dangerous is quishing in 2026?+

According to industry data, quishing attempts rose by more than 600 % worldwide in the first quarter of 2026. Police and the BSI have documented dozens of case series in Germany — including in Berlin, Dortmund and Tauberbischofsheim. In enterprises, the average loss per incident exceeds one million euros, according to Keepnet.

How do I recognise a quishing attack?+

Typical warning signs are: a QR code where there was none before (pasted over); an unexpected letter with a QR code from a bank, authority or insurer; time pressure ('act immediately') after scanning; and URLs that do not match the expected provider (typo domains, foreign top-level domains, raw IP addresses).

What is the difference between phishing and quishing?+

Phishing uses classic channels such as email or fake websites. Quishing carries the phishing link inside a QR code. The key difference: spam filters and mail gateways cannot inspect the code because it is an image — and humans cannot see the destination URL before scanning either.

Are QR codes inherently insecure?+

No. QR codes themselves are considered a safe technology. Scanning becomes risky when the destination URL is not verified before the page opens. Checker apps compare the link against current phishing databases such as PhishTank or Google Safe Browsing and reduce the risk.

How exactly do I protect myself against quishing?+

Six measures: 1) Use a scanner app with URL preview and do not open links automatically. 2) Watch for typo domains (e.g. 'spark-asse.de' instead of 'sparkasse.de'). 3) Ignore QR codes from banks or authorities — they communicate via other channels. 4) Do not scan pasted-over QR codes. 5) For letter quishing, contact the institution via an independently researched number. 6) Use a specialised checker app.

I scanned a suspicious QR code — what do I do?+

As long as no data was entered, the risk is low. Otherwise: change affected passwords immediately, have your online banking blocked via the German hotline 116 116, call your bank via the official service number and file a police report. Document the incident with screenshots.

Where do I report quishing attacks?+

In Germany: to the Verbraucherzentrale (consumer association), the police (online reporting site of the relevant state), the BSI (via the BSI reporting office or the Alliance for Cybersecurity), and for bank quishing directly to the affected bank (e.g. phishing@deutsche-bank.de).

Is there enterprise quishing protection?+

Yes. Experts recommend combining three layers: 1) Awareness training with quishing and phishing simulations. 2) Technical QR-code checking on company smartphones and in mail gateways. 3) Incident report templates for NIS-2-compliant reports to the BSI.

Which QR codes are forged most often in 2026?+

Common lures in Germany: 1) Parking meters ('Easy Park' clones). 2) EV charging stations (payment pages). 3) Bank letters (TAN / photoTAN updates). 4) DHL and parcel-service stickers. 5) Fake parking fines on car windshields. 6) Restaurant menus. 7) WhatsApp Web pairing (Ghost Pairing).

Is quishing a crime?+

Yes. In Germany, quishing is a criminal offence under §263 StGB (fraud), §202a StGB (data espionage) and §263a StGB (computer fraud) — depending on the offence, with up to five years in prison. Distributing fake QR codes also falls under §269 StGB (forgery of data) and §202c StGB (preparation of espionage).

What does QRTrust do against quishing?+

QRTrust scans QR codes and compares the destination URL in real time against PhishTank (1 M+ phishing URLs), Google Safe Browsing, an AI-based classifier and a URL redirect resolver. Sites classified as suspicious are blocked before they open. According to the provider, the app is GDPR-compliant, runs on EU servers and is free for private users.