Social Engineering Examples

Quishing Examples: Real QR Code Phishing Attacks

Quishing hides a malicious link inside a QR code instead of a clickable URL — as in fake parking-meter stickers in Cheltenham and Orlando, and a spoofed Microsoft MFA-setup code that harvested employee credentials — which lets it slip past email link-scanners and puts the burden of spotting the scam on whichever phone camera opens it. It shows up on physical stickers over legitimate codes as often as it does inside email, which is what makes it distinct from ordinary phishing.


7 Cases
QU
Confirmed

UK Council Car Park QR Code ("Quishing") Scams - Cheltenham, Swindon & Somerset

Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.

Incident 2024Read →
QU
Confirmed

Orlando Downtown ParkMobile QR Parking Meter Sticker Scam (2025)

Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters.

Incident 2025Read →
QU
Confirmed

LevelBlue MTDR SOC "Quishing" Case Study - Fake Microsoft MFA-Setup QR Code Harvests Employee Credentials (2023)

LevelBlue's MDR SOC documented a real client quishing case in which a PDF impersonating a Microsoft MFA-setup notice, hiding a malicious QR code.

Incident 2023Read →
QU
Confirmed

Hornetsecurity QRishing Attack on US-Based MSP (2023)

Hornetsecurity documented a QR-phishing (quishing) email sent to a single employee at a US-based MSP that spoofed an MFA-reactivation notice with a QR.

Incident 2023Read →
QU
Confirmed

FTC Consumer Alert: QR Code Scams (Quishing)

The FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters and phishing emails/texts using QR codes.

Incident 2023Read →
QU
Confirmed

FBI/USPIS/FTC "Brushing 2.0" Quishing Package Scam Advisories (2025)

The FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that, when scanned.

Incident 2025Read →
QU
Confirmed

Abnormal Security "Missed Voicemail" QR Quishing Campaign (2021)

Between September 15 and October 13, 2021, attackers sent nearly 200 emails disguised as missed-voicemail notifications with embedded QR codes that routed.

Incident 2021Read →

Physical and Parking QR Scams

The UK council car park quishing scams in Cheltenham, Swindon, and Somerset, and the Orlando downtown ParkMobile QR parking meter sticker scam, both placed a fraudulent QR sticker directly over a legitimate parking code in a public space.

Corporate Credential Harvesting

The LevelBlue MTDR SOC case involving a fake Microsoft MFA-setup QR code, the Hornetsecurity QRishing attack on a US-based MSP, and the Abnormal Security "missed voicemail" QR campaign all embedded a malicious QR code in a business email to harvest employee login credentials.

Government Advisories and Package Scams

The FTC consumer alert on QR code scams and the joint FBI, USPIS, and FTC "Brushing 2.0" quishing package-scam advisory both document a wave of fraudulent QR codes attached to unsolicited packages and delivery notices.

Explore more

Browse the rest of the library