Confirm what the QR code took you to

    Pin down which site you ended up on and what you typed before locking things down.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated June 2026 · 1 min read

    Quishing routes you to a fake page disguised by a QR code. The fix depends on whether you logged in, paid, or just browsed — get clear on that first.

    Common quishing patterns

      • Fake parking-fine sticker on a meter → fake payment page
      • QR code in an email pretending to be MFA setup → fake Microsoft / Google login
      • Restaurant menu sticker swapped → fake pay-at-table page
      • QR code on a courier slip → fake delivery-fee page

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Communications Security