Maybe you checked where it went first. Maybe you never got round to it: the camera is faster than the thought. Both are completely normal, and that is exactly why quishing works.
This code came from the Confident IT email signature and brought you here. Nothing else happens: no tracking, no form, no login. Think of it as a free practice run.
Phishing, hidden inside a little square.
Quishing is phishing by QR code. Instead of a link in an email you get a square. You scan it, and your phone opens a page that looks like your bank, your parcel service or your employer. It is a copy, built to capture your login or your card details.
The trick is in what a QR code does not show. With an ordinary link you can usually see where you are going before you click. With a QR code you see a pattern. You find out the destination only after your phone has already opened it.
So this is not a question of paying attention. A QR code hides its destination by design, not because you failed to look properly. Anyone who says they would never fall for it simply has not seen a convincing one yet.
Rarely in some shady corner of the internet. Usually just out on the street, or in your post.
A sticker over the real code on a parking meter or charging point. The sign is genuine, the code is not.
A letter that looks like it came from the government or your bank, with a code to "confirm your file".
A QR code in the email itself. Filters read images less well than text, so it gets through more easily.
A poster by the coffee machine about "the new pension scheme". In an office, nobody distrusts a poster.
Five habits that remove most of the trouble.
Your phone shows you the link before it opens it. Look at the part just before the first slash. That is the real domain. confident-it.be.secure-login.net is not Confident IT.
At a machine or a poster: run your thumb over the code. If a sticker has been placed over the original, you will notice straight away.
Is it about paying, logging in, or your national registry number? Leave the code alone and go straight to the site or app you already know.
"Only 24 hours left", "the fine doubles", "your account will be blocked". Time pressure is not a detail, it is the tool. It is there to stop you thinking.
No bank, government service or parcel company will ever ask you to confirm your details through a QR code.
Do not panic, but do not lose time either.
Change the password for the service that was imitated, and for every other place you use that same password. If it involved bank details, call Card Stop on 078 170 170 and notify your bank. You can report it to the police and via safeonweb.be. Suspicious messages can be forwarded to verdacht@safeonweb.be.
The Belgian police, with examples you actually come across here. In Dutch.
A technical explanation of how the attack works. In English.
Tackling phishing and quishing inside your business starts with knowing how your people react to it.