QR 碼可能和可疑連結一樣危險——只是網址藏在圖裡。以下說明 quishing 如何運作,以及如何保護自己。

本指南以英文撰寫。上方標題與摘要已本地化。
Scanning a QR code feels as ordinary as tapping a link: menus, parking, badges, invoices. Attackers noticed. Quishing (QR + phishing) hides a malicious destination inside a QR image so victims open a fake login or payment page without ever seeing a blue underlined URL in email.
This guide explains how quishing works, why it slips past some defenses, who gets targeted, and practical habits that reduce your risk—without abandoning QR codes for legitimate uses.
Quishing is phishing delivered through a QR code image. The payload is still a URL (or similar). The trick is packaging: instead of a visible hyperlink, the destination sits inside modules your camera decodes.
Related family members:
| Name | Channel | Typical bait |
|---|---|---|
| Phishing | Email / web | Clickable text link |
| Smishing | SMS | Text with a link |
| Vishing | Voice call | Social engineering over the phone |
| Quishing | Email images, PDFs, stickers | QR that opens a hostile page |
Two common delivery patterns show up again and again:
The dangerous handoff is often laptop → personal phone. The email lands on a managed device; the scan happens on an unmanaged one.
Industry reports in recent years have described sharp growth in QR-bearing phishing mail and a strong bias toward credential theft. Exact percentages change by vendor and year—treat the trend as real even if a single statistic ages.
If you publish QR codes for a business, make the destination obvious in nearby text (“Official Wi‑Fi for Lobby Guests — make-a-qr.com sample”), keep HTTPS on pages you control, and avoid surprising people with login walls they did not expect. Generate static codes on Create when the URL is final, test with Decode, and print with high contrast.
The pattern is just data. Risk comes from hostile destinations and social engineering—the same as links, with worse visibility.
Not reliably. Always reveal the URL first. Sticker overlays and brand impersonation are easier to spot than a well-made fake image in email.
Train staff on quishing, restrict who can request “scan to reset” flows, improve mail filtering that inspects images where possible, and give people a safe decode path that shows the URL before navigation.