This code was safe

You just scanned a QR code.

Maybe you checked where it went first. Maybe you never got round to it: the camera is faster than the thought. Both are completely normal, and that is exactly why quishing works.

This code came from the Confident IT email signature and brought you here. Nothing else happens: no tracking, no form, no login. Think of it as a free practice run.

What is quishing?

Phishing, hidden inside a little square.

Quishing is phishing by QR code. Instead of a link in an email you get a square. You scan it, and your phone opens a page that looks like your bank, your parcel service or your employer. It is a copy, built to capture your login or your card details.

The trick is in what a QR code does not show. With an ordinary link you can usually see where you are going before you click. With a QR code you see a pattern. You find out the destination only after your phone has already opened it.

So this is not a question of paying attention. A QR code hides its destination by design, not because you failed to look properly. Anyone who says they would never fall for it simply has not seen a convincing one yet.

Where do you run into it?

Rarely in some shady corner of the internet. Usually just out on the street, or in your post.

On the street

A sticker over the real code on a parking meter or charging point. The sign is genuine, the code is not.

In the post

A letter that looks like it came from the government or your bank, with a code to "confirm your file".

In your inbox

A QR code in the email itself. Filters read images less well than text, so it gets through more easily.

At work

A poster by the coffee machine about "the new pension scheme". In an office, nobody distrusts a poster.

What do you look for next time?

Five habits that remove most of the trouble.

01

Read the address in the preview

Your phone shows you the link before it opens it. Look at the part just before the first slash. That is the real domain. confident-it.be.secure-login.net is not Confident IT.

02

Feel whether the sticker lifts

At a machine or a poster: run your thumb over the code. If a sticker has been placed over the original, you will notice straight away.

03

Type the address yourself instead

Is it about paying, logging in, or your national registry number? Leave the code alone and go straight to the site or app you already know.

04

Distrust urgency

"Only 24 hours left", "the fine doubles", "your account will be blocked". Time pressure is not a detail, it is the tool. It is there to stop you thinking.

05

Never enter a code someone sent you

No bank, government service or parcel company will ever ask you to confirm your details through a QR code.

Scanned it and filled something in?

Do not panic, but do not lose time either.

Change the password for the service that was imitated, and for every other place you use that same password. If it involved bank details, call Card Stop on 078 170 170 and notify your bank. You can report it to the police and via safeonweb.be. Suspicious messages can be forwarded to verdacht@safeonweb.be.

Further reading

Politie.be | Quishing: fraud via QR codes

The Belgian police, with examples you actually come across here. In Dutch.

Read the article

Cloudflare | What is quishing?

A technical explanation of how the attack works. In English.

Read the article

Want to test your team on this?

Tackling phishing and quishing inside your business starts with knowing how your people react to it.