Digital services and internet-connected devices are now an integral part of our daily activities, in both our professional and personal lives. This progressive digitization brings countless advantages, but also new challenges and pitfalls related to cybersecurity. In line with the national Cyber Sapere campaign promoted by the Ministry of University and Research (MUR), it is essential that every citizen and user learns to recognize and counter emerging cyber threats, among which the so-called QRishing stands out for its level of risk.
QR codes (Quick Response Code) represent the technological evolution of the traditional barcode. They allow for an immediate connection between the physical and digital worlds through a simple scan with a smartphone camera. Embedded within these two-dimensional codes can be links to websites, text, contact information, or media downloads.
Their widespread adoption has made them a standard tool for quick access to information (think of restaurant menus, transit tickets, or informational posters). Alongside static codes, there are dynamic QR codes, which allow the destination link to be updated over time without having to reprint the physical code itself. However, cybercriminals have intercepted and exploited this versatility. QRishing is a specific variant of phishing (the classic online scam conducted via email or text messages) that uses QR codes as the main vector to deceive the victim. In 2025, data indicates that 12% of all phishing attacks globally included a QR code. The deception leverages a biological limitation: unlike a text web address, the human eye cannot decipher or visually interpret a QR code before scanning it, completely concealing the true destination of the link.
Credential theft
Phishing sites mimic the login pages of banking, institutional, or work services for the sole purpose of stealing username and password combinations.
Malware
Scanning the code can initiate the background download and installation of spyware or Trojans on your phone, exposing private photos, messages, and accounts.
Financial fraud
By modifying the QR code link, scammers intercept payment flows (e.g., utility or fine payments), redirecting funds to third-party accounts.
Visually inspect the medium
Before scanning a QR code displayed in a public place (billboards, notices, parking meters), carefully check that a fake sticker has not been overlaid on top of the original code.
Check the URL preview
When framing a QR code, most smartphones display a notification with a preview of the web address. Carefully analyze the web address before clicking to open it: if the domain appears confusing, shortened, or unusual, abort the operation.
Avoid entering sensitive data
Banking institutions, public administrations, and essential service providers almost never use a QR code as the sole, unexpected, or mandatory channel to request banking details, passwords, or confidential information.
Critically evaluate the context
Be wary of QR codes sent via unsolicited emails, attached to messages from unknown senders, or lacking a clear and explicit description of their content.