started · updated
Cybercriminals use QR code phishing to target banking data
Cybercriminals are increasingly using a technique known as ‘quishing’—phishing via QR codes—to steal banking credentials, credit card information, and facilitate fraudulent payments. Because the destination URL is hidden within the code, users often do not see the actual web address until after scanning, making it harder to detect malicious links compared to text-based URLs.
Scammers often redirect victims to fraudulent websites that mimic banks, payment gateways, shipping companies, or government agencies. Aleš Černý, head of retail risk management at Air Bank, notes that QR codes often inspire more trust than standard links, despite having similar security risks.
To mitigate risks, experts recommend inspecting the destination URL for typos, unusual domain extensions, or suspicious wording immediately after scanning. Users should also be wary of QR codes in public spaces, such as parking meters or restaurant menus, as criminals may place stickers over legitimate codes. If a site requests sensitive information like login credentials or security codes, it is safer to close the browser and use an official application instead.