ISEC7 Digital Workplace Blog

Everyday Security Risks: QR Codes and Quishing

Written by Remi Keusseyan | Dec 8, 2020, 7:30:00 AM

Reviewed and updated in October 2026.

This is the first post in our Everyday Security Risks series about the risks we take every day when using our mobile devices. We start with something many of us used more than ever during the pandemic: QR codes.

What a QR code can do

QR codes were introduced in 1994 by Denso Wave, a Toyota group company, to track parts in car manufacturing. They are an evolution of the traditional barcode found on almost any product, from canned goods to cereal boxes. QR codes store far more information and are more resistant to physical damage, which made them popular in other sectors for all sorts of tasks, such as product and time tracking.

A single QR code can hold up to 7,089 digits or 4,296 alphanumeric characters. That is enough for a link to a website, or for data that triggers an action on the phone: adding a contact to the address book, starting a phone call, sending a text message or email, posting to social media or adding a Wi-Fi network.

The benefits are obvious. Scanning a QR code is much easier than typing a long URL. During the pandemic, many restaurants replaced printed menus with a QR code, often a sticker on the table, that customers scan with their phones to open the online menu. It is also cheaper, easier and faster for restaurants to update their offering without reprinting menus.

The risk: you cannot see what is inside

There is a trade-off. People cannot read or interpret the data in a QR code without scanning it first. That is potentially dangerous, because we do not see what is inside the box until we have opened it. In the immortal words of Forrest Gump: "You never know what you're gonna get!"

Most QR codes are harmless, but some are built to make a device connect to a Wi-Fi network or to open a shortened URL that eventually redirects to an unsafe website. In 2018, for example, a bug in the QR code reader of Apple iOS 11 could be used to trick users into visiting a malicious website. QR codes can also add contacts, start a phone call or send a text message or email, which can expose your email address, phone number or other identifiers that attackers later use for phishing.

This has become a common scam. The FBI warned in January 2022 that criminals tamper with QR codes, for example by placing their own stickers over legitimate ones, to redirect victims to malicious sites that steal login and payment data. The US Federal Trade Commission issued a similar warning in December 2023, including QR codes sent by email or text message. Security researchers now call this kind of phishing "quishing".

The iOS 11 bug was fixed long ago, but it is a reminder that nothing is 100% safe. Any system is only as strong as its weakest link, and that link tends to be the end user: taking unnecessary risks out of a lack of awareness, or simply wanting instant gratification and clicking on anything to get it.

What should you do?

The safest option is not to scan the QR code at the restaurant at all and to look up the menu on the restaurant's website instead. That is slower and less convenient, and we are only human: in the end, we tend to take the easier path. So before you scan any QR code, ask yourself:

  • Where is the QR code? A sticker on the table, with or without the restaurant's logo? A loose piece of paper? A sticker that looks like it was placed over another one?
  • Did the staff point you to a specific QR code?
  • What is the code trying to open? Current camera apps on iOS and Android show the link before opening it. Check the domain, and be wary of shortened URLs.

A malicious QR code can lead to something as minor as an unsavory website or, in a more complex scheme, be one step in stealing your identity or payment details.

What about the enterprise?

This post takes a consumer view, but what can IT administrators do to protect employees' devices, and ultimately the corporate infrastructure and company data, from this risk?

Disabling QR code scanning, or the camera altogether, through a UEM solution and IT policy is the safest option, especially on work-only devices in regulated environments. In most cases, however, it does not scale. It is counterproductive, especially in BYOD programs, and can damage user acceptance of your whole digital workplace strategy.

A smarter move is a Mobile Threat Defense (MTD) solution. It monitors devices, detects threats such as phishing links and malicious apps, and responds in real time, so devices stay secure and compliant. Combine it with regular security awareness training, because the user is still the one who decides whether to scan.

The series continues with Everyday Security Risks: Universal Serial Bus (USB) and Everyday Security Risks: Wi-Fi.

ISEC7 integrates and operates mobile threat defense from its partners Lookout and Zimperium in your existing UEM landscape; learn more about our endpoint security services and trainings. Contact us with any questions.