\"Quishing\": scams with QR codes and links in SMS
The QR on the parking meter, on the restaurant menu or in the parcel SMS. Scammers use QR codes and shortened links to hide where they take you. Here's how to check them before tapping.
NoCall
Clear guides with steps for acting on suspicious calls and messages.
You scan a QR code and your phone opens a website directly. You haven't read any address, typed anything, or decided where to go: the QR decided for you. That convenience is exactly what quishing (QR + phishing) exploits: QR codes and shortened links that hide their destination to take you to fake websites that steal your data or money.
Quishing isn't a separate technique from smishing (like the fake DGT fine SMS): it's the same deception with the link better hidden. Where the fake DGT or parcel SMS still lets you see a suspicious domain if you look, the QR lets you see nothing until you've already scanned it.
Where fake QR codes show up
- Parking meters and parking zones. Stickers with a fake QR placed over the real QR of the council or the payment app. You scan, land on a website imitating parking payment and enter your card. It's the variant that has grown most in Spain.
- Restaurant menus and terraces. A QR stuck over the original. Here the goal is usually to get you to install a fake app or take you to a phishing website on any pretext.
- Fines and notices on the windscreen. Fake penalty notices with a QR "to pay with a discount". Same hook as the fake fine SMS, on paper.
- Parcels and deliveries. QR on stickers or in SMS ("scan to reschedule your delivery"), a variant of parcel fraud.
- Emails and SMS with QR. The message asks you to scan a QR instead of tapping a link, sometimes with the excuse of "two-step verification" or "security". It also serves to bypass antiphishing filters, which check links but not images.
- Cryptocurrencies and payments. QR codes supposedly containing a payment address or a "refund". Once the money is sent, there's no going back.
The rule: look at the destination before entering
With a normal link you can read the address before tapping. With a QR you can't, so you have to add that step manually:
- Scan, but don't enter yet. Most phones show the full URL before opening it. That's the moment to decide: read it fully, without rushing.
- Check the domain. It must be the service's official one, with no extra hyphens or odd extensions. If the parking-meter QR takes you to a domain that isn't the council's or the official app's, it's fake.
- If something doesn't add up, don't enter: go to the official channel yourself. Open the official parking, bank or shop app and do the task there. The same method as for verifying a call or SMS from your bank.
- Be wary of QR codes with urgency. "Scan now", "final notice", "your parcel is returned today". Urgency is the signature of fraud, in QR just as in SMS.
And a physical tip for QR codes stuck up in the street: check whether there's one sticker over another. If the parking-meter QR is on a sticker that looks added afterwards, or covers another code underneath, don't use it. Pay from the official app you have installed.
What to do if you already scanned and gave data
- You entered your card on the destination site: call your bank now, block the card and ask for a new one. Watch your charges over the coming weeks.
- You downloaded an app from the QR: uninstall it, run your phone's antivirus and review the permissions you gave it (SMS, accessibility and notifications are the dangerous ones).
- You only scanned and closed: almost certainly nothing happened. Scanning alone installs nothing and gives away no data; the risk starts when you interact with the website.
- Report it to the police with photos of the QR (if it was in the street, a photo of the sticker and its location) and screenshots of the website. The INCIBE helpline 017 gives free guidance.
- If the QR reached you by SMS or call, report the number in the spam numbers directory.
Quick questions
Can scanning a QR hack my phone? Scanning alone, no: the QR only contains text (usually a URL). The danger is in the website it takes you to and what you do there: entering data, downloading files or granting permissions. That's why the defence is checking the destination before entering.
Are shortened links (bit.ly and the like) the same thing? The same problem, yes: they hide the destination. Legitimate shorteners allow previewing (many with a "+" at the end of the URL), but the practical rule is the same: if you don't know where it leads and it urges you to tap, don't tap and go to the official channel yourself.
Can my bank send me a legitimate QR? Yes, for example to link the app or confirm operations... within processes that YOU started. A bank QR that arrives without you having asked for anything follows the general rule: don't use it and go into the official app yourself.
How do I protect an older person from this? With one sentence: "don't pay anything by scanning a street QR; use the app you already have". Parking meters are the most frequent point of contact. You'll find more advice in how to protect elderly people from phone scams.
The summary fits in one line: a QR is a link you can't read, so read it before entering. Scan, look at the URL, and if it isn't the official domain, close it and go to the official channel yourself. That second of pause dismantles quishing entirely.
Sources and review
Reviewed:
Numbering, carrier tools, and reporting procedures can change. Verify sensitive steps with the linked primary authority.
Article details
Editorial content reviewed by NoCall with practical context for spotting suspicious calls and messages.
Received a suspicious call?
Look up the number in NoCall before sharing data, calling back, or clicking any link.
Search a phone number or a company name (Iberdrola, Movistar and Vodafone...) to check if it has been reported as spam.
