Quishing is phishing carried out through a QR code. Someone points you at a malicious website using a code instead of a link, and because most QR codes are anonymous, you cannot tell where it leads until you scan it. It is a real risk, but it is worth being precise about where the risk actually lives: in random, anonymous codes anyone can generate and stick anywhere, not in a brand's code printed into its own packaging and resolving to its own domain.
That distinction matters, because the move to 2D barcodes on products has made some shoppers nervous that every code is now a trap. It is not. This guide explains how quishing works, why an accountable code like a GS1 Digital Link is built to avoid it, and how to tell a safe code from a suspicious one.
What is quishing?
The direct answer: quishing, a blend of "QR" and "phishing", is a scam where an attacker uses a QR code to send you to a fraudulent website or to trigger a harmful action. The code is just the delivery method. It works for the same reason phishing links work, because it hides the destination, and it is arguably worse because a printed square gives you no hover preview and no visible address to inspect before you commit.
Attackers like QR codes because they are cheap, they look official, and they can be placed in the physical world where people trust their surroundings: a parking meter, a restaurant table, a poster, a letter.
How a quishing scam actually works
A typical quishing attack has three moves. First, the attacker generates a QR code that points to a site they control, often a convincing clone of a real login or payment page. Second, they place that code where a victim expects a legitimate one, frequently as a sticker stuck on top of a genuine code. Third, the victim scans, lands on the fake page, and hands over a password or card details believing it is the real service.
The key enabler in almost every case is anonymity. The code carries no proof of who made it or where it should lead. Anyone can make one, and nothing about the symbol itself vouches for it.
Why a GS1 Digital Link code is different
A brand's GS1 Digital Link code is a different animal from a random sticker, because it is tied to an accountable chain. The identity in the code is licensed from GS1 by a real, registered company, and it resolves through a known address rather than a mystery URL. A fraudulent sticker cannot fake that chain. At best it can be a copy pointing somewhere it should not, which is exactly the same risk that already exists with a printed web address or a phone number on a package, and no worse.
In other words, the code printed into a product's artwork by its manufacturer, resolving to that manufacturer's own domain, sits at the safe end of the spectrum. The dangerous end is the anonymous sticker with no accountable owner. The transition to standardised, brand-owned codes pushes the whole ecosystem toward the safe end, not away from it.
How to spot a fake QR code
You do not need to fear every code. You need the same street sense you already use with links and phone numbers. The signals below separate a code you can trust from one you should not.
| Signal | Trustworthy code | Suspicious code |
|---|---|---|
| Placement | Printed into the product or material itself | A sticker stuck on top of another code |
| Location | On a product, in official materials | Taped to a lamppost, parking meter or random surface |
| Destination | Resolves to the brand's own domain | Odd domain, link shortener, misspelled name |
| Request | Shows information | Immediately asks for a password or payment |
| Context | Matches where you are and what you expect | Arrives unsolicited, by letter or email, with urgency |
If a code is a sticker layered over another code, or it lands you on a page demanding credentials, stop. That is the pattern to distrust.
What brands can do to protect their customers
Brands are not helpless here, and the choices that reduce quishing risk are the same choices that make a code more useful. Print the code directly into the artwork rather than applying it as a separate sticker, so tampering is harder and more visible. Resolve to your own domain so the destination is verifiable. Use an accountable, standards-based identity like GS1 Digital Link so the code is tied to your company rather than to an anonymous generator. For high-value goods, layer an authenticity check behind the scan so a shopper can confirm the product is genuine.
None of this is exotic. It is the difference between a code that only a scanner cares about and a code that a customer can trust, and it is covered in more depth in our pillar guide on whether QR codes on products are safe.
Want to publish codes that resolve to your own domain through an accountable chain? Create a free account and try it.
Frequently asked questions
What does quishing mean?
Quishing is phishing carried out through a QR code. An attacker uses a code, rather than a link, to send a victim to a fraudulent website or to prompt a harmful action. The code hides the destination, which is what makes the technique effective.
Are QR codes on products dangerous?
Not when they are part of an accountable system. The risk people worry about comes from anonymous codes anyone can print and stick anywhere. A code printed into a product's packaging by the brand, resolving to the brand's own domain, sits at the safe end of the spectrum. Be cautious of codes stuck on top of other codes or placed in random public locations.
How can I tell if a QR code is a scam?
Check placement, destination and intent. Distrust a code that is a sticker layered over another code, that resolves to an odd or misspelled domain or a link shortener, or that immediately asks for a password or payment. A trustworthy code is printed into the material itself and resolves to a domain that matches the brand.
Does GS1 Digital Link prevent quishing?
It does not make fraud impossible, but it removes the anonymity that quishing relies on. A GS1 Digital Link code is licensed to a registered company and resolves through a known address, so a fraudulent sticker cannot impersonate that accountable chain. It reduces the attack to the same copy risk that already exists with any printed address.





