Quishing hides a malicious link inside a QR code instead of a clickable URL, which lets it slip past email link-scanners and puts the burden of spotting the scam on whoever's phone camera opens it. It shows up on physical stickers over legitimate codes as often as it does inside email, which is what makes it distinct from ordinary phishing.
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset, tricking drivers into paying "parking fees" on cloned sites that harvested full card details or signed them up for hidden subscriptions.
QUScammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters, redirecting drivers who scanned them to a phishing site that harvested personal and payment information.
QULevelBlue's MDR SOC documented a real client quishing case in which a PDF impersonating a Microsoft MFA-setup notice, hiding a malicious QR code, drove multiple employees to a fake Microsoft login page that harvested several employees' credentials before the attack was fully remediated with no confirmed data loss.
QUHornetsecurity documented a QR-phishing (quishing) email sent to a single employee at a US-based MSP that spoofed an MFA-reactivation notice with a QR code leading, via a .ru-hosted fake "security scan" page behind Cloudflare, to a freshly registered Microsoft 365 credential-harvesting login page; Hornetsecurity's write-up documents this technical chain but does not confirm the employee scanned the code or that any downstream step actually occurred.
QUThe FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters and phishing emails/texts using QR codes to steal credentials or install malware.
QUThe FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that, when scanned, send recipients to phishing sites or malware instead of the promised gift-sender reveal or return instructions.
QUBetween September 15 and October 13, 2021, attackers sent nearly 200 emails disguised as missed-voicemail notifications with embedded QR codes that routed victims to a Microsoft-credential phishing page hosted on a legitimate enterprise survey service, using compromised Outlook accounts to bypass secure email gateways entirely, one of the earliest vendor-documented "quishing" campaigns.