"Quishing" is the latest evolution of online fraud, a method that uses QR code technology to trick users into stealing their personal and financial data. It's a new variant of phishing, but with a different attack method.
Quishing is based on the fraudulent use of QR Codes, two-dimensional barcodes that allow quick access to websites simply by scanning them with a smartphone. While these codes are normally used for everyday functions, such as consulting a restaurant menu or accessing an official website, the danger lurks when these QR Codes lead to deceptive sites.
Once the user scans the fraudulent code, they are directed to a fraudulent web page, where they are asked to enter personal or banking information, or to download files that hide malware. Among the most reported cases, there is the replacement of original QR Codes on parking payment columns with counterfeit codes, or the sending of deceptive emails requesting urgent payments, such as alleged fines, via fake QR Codes.
It's essential to verify the authenticity of QR codes before scanning them, especially if found in public places or received via email. While codes are rarely dangerous in restaurants or other controlled environments, it's always good practice to exercise caution.
It is also important to pay attention to grammatical errors or suspicious details in communications containing QR Codes, as they may be signs of a scam. Experts recommend using protection tools such as antivirus and firewalls to protect your devices, and remind you of the golden rule: never disclose your personal or financial data unless you are sure of the security of the transaction.



