Assets, actors and realistic attack paths
Malicious QR codes, sometimes called quishing, are physical or digital codes that direct the scanner to a fraudulent destination rather than the intended one. The attack works because a QR code conceals its target URL. A visitor scanning what appears to be a legitimate parking payment code, exhibit label, or Wi-Fi access point cannot inspect the address before the browser opens.

The mechanics are straightforward. An attacker prints a QR code that encodes a URL pointing to a credential-harvesting page, a malware download, or a spoofed login screen. That printed sticker is then placed over a genuine code in a public space, or a completely fake sign is erected. Because the code is physical and sits within a trusted environment — a museum wall, a council car park, a retail till point — people scan without suspicion.
For organisations deploying QR codes as part of a proximity or indoor experience strategy, the threat operates on two levels. First, your own codes could be tampered with on-site, damaging visitor trust and potentially exposing those visitors to fraud. Second, the growing public awareness of QR-based phishing may reduce scan rates across the board, undermining the usability of your legitimate deployment.
The National Cyber Security Centre has noted the rise in QR-based phishing attempts targeting UK consumers, particularly through fake payment pages and delivery notification scams. While much of this activity happens through emailed QR images, the physical variant is directly relevant to any venue placing codes in public reach.
How Quishing Differs from Other QR Risks
General QR security risks — such as codes linking to expired pages, broken URLs, or unintended content after a CMS migration — are operational errors. Phishing is deliberate and adversarial. The attacker's goal is to capture credentials, payment details, or device access. This distinction matters because the mitigation approaches differ: operational risks are solved through content management discipline, whereas phishing requires physical security, monitoring, and visitor communication.
Hardening tags, accounts and destinations
Tampering in Physical Spaces
The most direct scenario for venue operators is sticker overlay. A genuine QR code on an exhibit panel, a table-ordering card, or a wayfinding sign is covered with a near-identical malicious sticker. In a busy retail environment or a large museum, this can go unnoticed for days or weeks. The attacker does not need to breach your systems; they need only physical access to the code and a few seconds to apply the overlay.
Fake infrastructure is a related approach. An attacker places a convincing but entirely fabricated sign in a car park directing drivers to a fraudulent payment page. The venue had no QR code there to begin with, but visitors assume the sign is official because of its placement and design.
Dynamic QR Codes as a Partial Mitigation
Dynamic QR codes — where the printed code points to a redirect service that you control — offer a useful advantage. If you discover that a code has been tampered with, you can change the destination URL on the redirect server immediately without reprinting. More importantly, a dynamic QR service can log scan counts and, depending on the provider, flag unusual patterns such as a sudden spike in scans followed by zero engagement on the landing page, which might indicate traffic is being intercepted or the redirect has been altered.
However, dynamic QR is not a complete defence. The redirect service itself becomes a target: if an attacker gains access to your QR management account, they can change every code's destination at once. The security of your dynamic QR platform — its authentication, access controls, and audit logging — is now part of your physical deployment's security posture.
Reputational Impact on Venues
If a visitor is defrauded after scanning a code on your premises, the complaint will almost certainly be directed at your organisation regardless of whether you placed the original code or an attacker overlaid it. For museums, retail chains, and event organisers, this creates a duty-of-care argument for regular physical inspection of codes, clear labelling, and prompt response when tampering is reported.
Supply Chain and Printed Materials
QR codes printed by third parties — on point-of-sale displays, event lanyards, promotional posters sourced from external agencies — introduce another vector. If the agency's systems are compromised, or if a malicious URL is inserted during the design or print production stage, every distributed copy carries the fraudulent link. Verifying the encoded URL of any printed QR code before bulk distribution is a basic but frequently skipped control.
Audit points and recovery readiness
Assuming Physical Placement Equals Trustworthiness
The most persistent mistake is believing that because a QR code sits on your wall or counter, visitors will treat it as safe. Public awareness of quishing is growing, and an increasing number of people now hesitate before scanning codes in public spaces. Assuming blind trust is a planning error that leads to underinvestment in both physical security and visitor communication.
Failing to Establish a Visual Baseline
If you do not have a record of what each QR code looks like, where it is placed, and what URL it encodes, you cannot reliably detect tampering. Staff tasked with checking codes need a reference — a photograph, a floor-plan map, or an inventory record — to compare against. Without this, a slightly different sticker on an exhibit panel is unlikely to be spotted during a routine walk-through.
Relying Solely on Static Codes for Sensitive Functions
Static QR codes that encode a direct payment URL or a login page offer no recovery option if compromised. For any function involving payment, authentication, or personal data entry, a dynamic QR redirect with logging and the ability to disable the code remotely is a more resilient choice. This does not eliminate the phishing risk but it reduces the window of exposure and provides an audit trail.
Not Communicating With Visitors
Venues often deploy QR codes without telling visitors what to expect after scanning. A simple, consistent label — such as "This code opens [venue name] official guide at [short domain]" — gives visitors a reference point. If the resulting page does not match that description, they have a clear signal that something is wrong. This low-cost measure is one of the most effective defences against quishing in physical spaces.
Key Checks for Operational Teams
- Verify encoded URLs before printing. Scan every QR code from the production proof with a device that shows the destination URL before opening it. Do not trust that the design file is correct.
- Photograph and inventory every deployed code. Record the location, the expected URL, the date installed, and a photograph. Store this where frontline staff can access it during checks.
- Inspect codes on a regular schedule. The frequency depends on footfall and accessibility. A museum gallery with public access during opening hours may need daily checks; a staff-only area may need less frequent review.
- Use tamper-evident placement where feasible. Codes placed under clear acrylic, embedded in laminated panels, or positioned out of easy reach are harder to overlay. This is not foolproof but raises the effort required.
- Monitor dynamic QR analytics for anomalies. A sudden change in scan volume, geographic origin, or a drop-off between scan and page load can indicate tampering or a redirect compromise.
- Have a response plan. If a malicious code is discovered, staff need a clear procedure: remove the code, log the incident, check adjacent codes, and decide whether to notify visitors who may have scanned it. Waiting to figure this out after discovery delays containment.
Limitations to Accept
You cannot prevent an attacker from placing a fraudulent QR code near your venue or on public infrastructure you do not control. A fake parking sign on a council-owned car park, for example, is outside a retailer's or event organiser's authority. What you can control is the security of your own codes, the clarity of your labelling, and the speed of your response when issues are reported. Accepting this boundary prevents wasted effort on unachievable guarantees and focuses resources on the controls that genuinely reduce risk.

