QR phishing has multiplied in recent years. Learn the six common plays and keep a one-tap link checker on hand - stop scanning on luck.
The QRDIV quishing guide catalogs six common QR code phishing patterns - overlay stickers, fake parking payment codes, flashy lure codes, shortened redirect links, fake public WiFi portals and email-borne codes - and pairs them with a local URL safety check plus a browser bookmarklet. Every check runs locally in your browser; nothing is uploaded.
01
Six common quishing plays
Every QR scam boils down to making you scan a code you should not. Pause when you meet any of these.
Overlay stickersA fake code pasted over the real one on menus, posters or shared equipment. Feel for sticker edges - never scan one that is peeling.
Fake parking payment codesStickers on meters or posts lead to lookalike payment pages that harvest card numbers. Pay via the official app or signage, never a roadside sticker.
Flashy lure codesPrize-draw and giveaway pitches paired with colorful fancy codes to lower your guard. The prettier the code, the harder you should look at the destination.
Short links and redirectsThe scan reveals a shortened or multi-hop link hiding the real destination. Expand and verify it with a link check before opening.
Fake public WiFi portalsScan-to-connect WiFi that pops a "login" asking for your phone number, verification codes or card details. Never enter sensitive data into public portals.
Codes in emailPhishing emails swap links for QR codes to slip past link scanners - the original quishing scenario. Any "scan to verify your account" email is almost certainly phishing.
02
Quick link check
Unsure about a decoded link? Paste it here and the local engine applies eight rules for a first verdict.
Checks run locally in your browser and the link is never uploaded; verdicts are advisory - use your judgment.
03
Put the checker in your bookmarks bar
Drag the button below into your bookmarks bar. On any page, click it, paste a suspicious link, and our safety check opens instantly.
Desktop: drag the button above straight into the bookmarks bar.
Mobile: copy the bookmarklet code, create any bookmark, then replace its URL with the pasted code.
To use: click the bookmark, paste the suspicious link, and the safety check page opens automatically.
The bookmarklet does exactly one thing: carries the link you type to our check page. It never reads or uploads anything from the current page.
FAQ
Frequently asked questions
A blend of "QR code" and "phishing": fake QR codes that steer you to phishing sites to steal credentials or card details, or trick you into payments. Because humans cannot read a code by eye and codes slip past email link scanners, it has become one of the fastest-growing phishing vectors.