QR codes look harmless
and that makes them dangerous
You have just done exactly what cybercriminals want you to do – scanned a QR code without being absolutely certain that the page was safe. Check the URL of this page, where you found a tip about what to do.
But do not worry! This time you reached a micro-training where we will show you how to protect yourself from quishing.


But imagine if…
- Instead of the micro-training, a fake login page for a trusted company (such as Microsoft 365) would have opened.
- You might have entered your business credentials, such as your username and password, without suspecting anything.
- That is how a cybercriminal would gain access to your email, systems and data.
This is quishing – and it is becoming a popular attack vector.
QR-code phishing is increasingly used by scammers to steal data: it grew from 1.4% to 12.4% of all attacks (Egress 2024). Up to 25% of phishing emails already contain a QR code (MDDR 2024).

Why is QR Code Phishing so effective?
What should you check before scanning a QR code?
Context of the QR code you received
Before scanning a QR code, ask yourself a few key questions. Where did the code come from? Did you find it in an email, on a poster, on a sticker in a public space? Were you expecting this message? Is this communication typical for your organization or institution?
URL security
Most modern phones show a link preview before opening it. This is your most important line of defense. Carefully check the address to which the QR code wants to redirect you. Pay attention to link shorteners. Addresses such as bit.ly should immediately raise your suspicion.
Physical signs of tampering
If you find a QR code in physical form – for example, as a sticker on a paper document or poster – look closely at how it was made. Does the sticker peel off easily, or have a different color or texture from the rest of the document? If anything looks different, a scammer may have placed the QR code there.
What to remember when scanning a QR code
- Use your phone camera – QR-scanning apps may automatically open links without your consent. After scanning a QR code with your camera, look for the small icon that lets you preview the full URL before clicking.
- Do not log in on a page opened from a QR code – always use the official app or a saved bookmark.
- If the page asks for data such as a username, password, card details or a national ID number, close it and contact your IT team.
What if you have already entered data on a suspicious page?
Immediately change your password in all company systems. Report the incident to IT or security. Enable multi-factor authentication (MFA) if you have not already done so. Also monitor activity such as login history, active sessions and settings changes. If you see an unknown location, nighttime activity or unknown devices, sign out of all sessions, change the password again and report it to IT.

Think before you scan a QR code
That is exactly why cybercriminals use them to steal data. Before scanning a QR code or clicking a link, remember to stay cautious. This helps keep you and your organization safe.
