Works with physical codes and digital ones — parking meters, menus, packages, texts, emails, and flyers.
🔒 Content you paste is never stored, logged, or shared. It is processed server-side and discarded immediately after your result is returned. If a scanned page asked for a login or payment: treat it as hostile, close it, and change any password you entered from a clean browser. This tool informs your decision — it does not guarantee outcomes.
The Attack Patterns
How quishing actually works.
The QR code isn't the scam — it's the delivery vehicle. These are the patterns the AI checks your encounter against.
A fraudulent code stuck over the real one on parking meters, EV chargers, menus, and posters. Raised edges or misalignment around a code are worth a look before every scan.
Unpaid tolls, package redelivery, account alerts — arriving with a QR code or link you never asked for. Unsolicited codes carry the same risk as unsolicited links: total.
Scanning leads straight to a "sign in" for your bank, Microsoft, or Amazon. Real codes on legitimate materials rarely demand credentials first — phishing pages always do.
Parking or charging codes leading to unfamiliar payment processors instead of the city's or vendor's official app. Your card details are the entire objective.
Shorteners and lookalike domains (rnicrosoft-secure.com) hide the destination. Most phone cameras preview the URL before opening — the habit of reading it is the defense.
A mystery delivery with "scan to see who sent you a gift." Brushing-adjacent quishing that trades curiosity for credentials or card numbers.
Examples
Three scans, checked.
The same trick in a parking lot, a text thread, and an inbox.
A parking meter's QR code leads to "quickpay-parking.net" asking for your plate and card. The city's parking app is mentioned nowhere, and the sticker sits slightly crooked over another code.
Physical overlay quishing — cheap stickers, printed by the hundred, harvesting cards all day in busy lots. Cities take payment through their named apps and official sites; an unfamiliar processor at a meter is a scam by default.
"FasTrak: Our records show an unpaid toll of $6.49. To avoid a $50 late fee, settle today," with a QR code — and the linked page is a convincing DMV-styled form requesting card and license details.
Unpaid-toll smishing is one of the highest-volume scams in the country, and the QR variant dodges link-scanning filters. Tolling agencies bill by mail and through accounts you log into directly — never by QR-coded text. The $50 late fee is the pressure; the form is the harvest.
A work email from "IT Security," correctly branded, says your multi-factor authentication expires today — "scan with your phone to re-enroll." The code opens a flawless Microsoft 365 login that accepts your password and then asks you to approve an MFA prompt.
Enterprise quishing: the QR moves the attack from your protected work laptop to your unfiltered phone, and approving that prompt hands the attacker a live session. Anything time-boxed about MFA arriving by email deserves a call to real IT first. If you approved a prompt — report it to IT immediately; minutes matter.
Common Questions
About QR code scams.
More Scamanot Tools