A link at least shows you where it goes. A QR code shows you a pattern of squares. That gap is the whole scam.
"Quishing" is phishing through a QR code — the code stands in for a link you never get to read before your phone opens it.
Where they show up
- Stickers placed over the real code on a parking meter or EV charger
- A code in an email or PDF, which sails past filters that would flag a link
- Fake "verify your account" or "package held" notices with a code to scan
- Flyers, table tents, and posters in public places you'd assume are vetted
The one habit that defeats it
When your camera previews the QR code, it shows the destination URL for a second before you tap. Read it. If the address is a random string, a shortener, or not the site you expected, don't open it.
If you already scanned one and landed somewhere asking for a login or payment, run it through a Quick Check — Carmen reads the destination and tells you in seconds whether it matches known scam patterns.
Already entered something? Don't panic — get help and a real person will walk you through what to change and in what order.