While teenage pranksters seek cheap laughs on video feeds, threat actors track the exact same behavioral patterns. QR code phishing, widely dubbed "quishing," takes advantage of the fact that traditional email security filters and endpoint monitors cannot easily parse or block physical optical prompts. Instead of receiving a suspicious email with a flagged hyperlink, victims point their cameras directly at physical stickers, entirely bypassing gateway protections.
Security operations centers at major telecommunications firms documented a 587% surge in quishing incidents between late 2024 and 2026. Attackers intentionally design stickers that spoof legitimate public utility decals or municipal payment interfaces. Once scanned, the redirection does not send the user to an eighties music video. It presents a spoofed Google Workspace or Microsoft 365 login screen requesting instant verification to access a "free public Wi-Fi hotspot" or "claim a local parking discount."
Because the victim operates on a handheld touchscreen, spotting typographical errors in the address bar becomes significantly harder. Mobile Safari and Google Chrome truncate long URLs to preserve screen space, hiding suspicious subdomains beneath truncated security badges.