Quishing hides a malicious link inside a QR code instead of a clickable URL — as in fake parking-meter stickers in Cheltenham and Orlando, and a spoofed Microsoft MFA-setup code that harvested employee credentials — which lets it slip past email link-scanners and puts the burden of spotting the scam on whichever phone camera opens it. It shows up on physical stickers over legitimate codes as often as it does inside email, which is what makes it distinct from ordinary phishing.
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
QUScammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters.
QULevelBlue's MDR SOC documented a real client quishing case in which a PDF impersonating a Microsoft MFA-setup notice, hiding a malicious QR code.
QUHornetsecurity documented a QR-phishing (quishing) email sent to a single employee at a US-based MSP that spoofed an MFA-reactivation notice with a QR.
QUThe FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters and phishing emails/texts using QR codes.
QUThe FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that, when scanned.
QUBetween September 15 and October 13, 2021, attackers sent nearly 200 emails disguised as missed-voicemail notifications with embedded QR codes that routed.
The UK council car park quishing scams in Cheltenham, Swindon, and Somerset, and the Orlando downtown ParkMobile QR parking meter sticker scam, both placed a fraudulent QR sticker directly over a legitimate parking code in a public space.
The LevelBlue MTDR SOC case involving a fake Microsoft MFA-setup QR code, the Hornetsecurity QRishing attack on a US-based MSP, and the Abnormal Security "missed voicemail" QR campaign all embedded a malicious QR code in a business email to harvest employee login credentials.
The FTC consumer alert on QR code scams and the joint FBI, USPIS, and FTC "Brushing 2.0" quishing package-scam advisory both document a wave of fraudulent QR codes attached to unsolicited packages and delivery notices.