QR codes were designed to be unreadable by humans. That is the whole point of them, and it is also the entire reason they have become one of the fastest-growing delivery methods for phishing. When you tap a link in an email you can at least glance at the address first. When you point a camera at a black-and-white square you are trusting whatever comes back, and by the time the page loads you are already there.
This tool closes that gap. Drop in a picture of the code and Scanify reads it the same way your phone's camera would, except it shows you the address instead of opening it, and then runs that address through a safety check.
What "quishing" actually is
Quishing is phishing delivered by QR code. The attacker's goal is unchanged: get you onto a page that looks like a login screen, a payment form or a parcel-tracking site, and harvest whatever you type. The QR code is simply a better envelope than a link, for three reasons.
- It hides the address. No amount of care lets you inspect a QR code by eye. Security advice built around "check the link before you click" collapses.
- It moves you onto your phone. Phones show truncated addresses in a small bar, have smaller screens for spotting a fake layout, and are more likely to have a saved password ready to autofill.
- It survives filters. An email security gateway can rewrite and scan a link. A QR code is an image, and plenty of gateways still pass images through untouched.
Where malicious QR codes show up
Physical stickers over real codes
The most common physical attack is also the cheapest: print a sticker and put it on top of a legitimate code. Parking meters, electric vehicle chargers, restaurant table tents, charity collection posters and public transport ticket machines have all been hit. The victim believes they are paying for parking; they are handing card details to a stranger.
Fake parcel and delivery notices
A card through the door says a delivery failed and a small redelivery fee is due. The QR code leads to a convincing clone of a courier's site. The fee is trivial, which is the point: the real target is the card number, and often a follow-up call pretending to be your bank.
Email attachments and invoices
In a corporate inbox, quishing usually arrives as a PDF or an image claiming your account needs multi-factor re-enrolment. The QR code leads to a lookalike Microsoft or Google sign-in page. Because the user scans with a personal phone, the company's managed-device protections never apply.
Crypto and "free" giveaways
QR codes are the native format for wallet addresses, which makes them ideal for theft. A code on a poster, a livestream overlay or a replying social account sends funds to an attacker's wallet, and the transaction cannot be reversed.
What Scanify checks once it has the link
Decoding the QR code only tells you the address. The address then gets the same free checks Scanify runs on any link:
- Redirect tracing. Scam QR codes almost always point at a shortener or a throwaway redirector first. Scanify follows the chain and shows you every hop and the final landing page.
- Domain age. Phishing domains are usually days old. A real bank's domain is decades old. This single signal catches a large share of fakes.
- Google Safe Browsing. If the destination is already on Google's blocklist, you get told immediately.
- Certificate inspection. Whether the site has valid TLS, who issued it and whether it matches the hostname. A padlock is not safety, but a mismatch is a strong warning.
- Hostname heuristics. Brand names in the wrong position, digits standing in for letters, credential-bait words such as "verify" or "secure" glued onto a domain.
How to handle a QR code safely, with or without this tool
- Feel the sticker. On anything physical, run a finger over the code. A sticker applied over printed material has an edge you can feel. If it peels, do not scan it.
- Prefer typing. If the code is meant to take you to a company you already deal with, open their app or type the address yourself. You lose ten seconds and the entire attack surface.
- Use your camera's preview. Most phone cameras show the address in a banner before opening it. Read it. If it is a shortener, do not tap.
- Never enter credentials from a QR-code journey. Legitimate organisations do not use printed codes as the entry point to a login or payment flow.
- Check first when money is involved. Anything that ends in a payment, a wallet transfer or a "small fee" deserves a scan through this page before you go near it.
If you already scanned one
Scanning alone rarely does damage; the harm comes from what you do on the page afterwards. If you only looked, close the tab and move on. If you typed anything, act quickly.
- Change the password for the service that was imitated, going to the real site directly rather than through any link.
- Turn on two-factor authentication if it was not on already.
- If card details were entered, call your bank and freeze the card. Do not wait to see whether a charge appears.
- If it was a work account, tell your IT or security team the same day. They can revoke sessions you cannot.
- Report it. In the United States, reportfraud.ftc.gov. In the United Kingdom, report@phishing.gov.uk.
Your privacy on this page
The image never leaves your device. Decoding happens in your browser using a QR library loaded from a public CDN, and only the decoded address is sent to Scanify for checking. Nothing about the picture itself, including any part of the photo around the code, is transmitted or stored.