QR codes have crept in everywhere: in restaurants to view the menu, on parking meters to pay, on parcels to track a delivery. This convenience has a downside, one the Swiss authorities refer to with a slightly barbaric word: quishing. A contraction of “QR” and “phishing”, quishing consists of tricking a victim into scanning a QR code that directs them to a fake website, in order to extract personal data or money from them.

The National Cyber Security Centre (NCSC, the federal authority responsible for cybersecurity) documented several variants of this scam during the first half of 2026. Here is how they work, and how to avoid falling for them.

The fake delivery notice scam

In its week 24 review (mid-June 2026), the NCSC describes a particularly polished scam. Criminals drop fake missed-delivery notices into letterboxes, imitating the official yellow notices of Swiss Post. The document invites the recipient to scan a QR code in order to reschedule a supposedly missed delivery.

The code leads to a highly convincing fake Swiss Post website. After choosing a delivery slot, the victim is asked to provide personal details (name, date of birth, address, email, telephone number). Finally, the site requests bank card details for supposed processing fees of a few francs (between 2.10 and 3.99 francs in the cases observed). The amount is deliberately trivial so as not to arouse suspicion, but the real goal is to capture the card data and the victim’s full identity.

Parking meters and charging stations: the physical trap

Quishing does not only travel through the letterbox. Another technique consists of sticking a fake QR code over a genuine one, on a public fixture. RTS has reported cases targeting electric car drivers: fake stickers placed on charging stations redirect the motorist to a fake payment site. The same method has been observed on parking meters, where the fake code demands payment of a fine or a parking fee by credit card.

One Swiss tourist was even targeted twice while travelling abroad, with fraudulent purchase attempts that were fortunately blocked. This detail matters: once your bank details have been captured, they can be used well beyond the amount announced.

How to spot and avoid the trap

The NCSC’s recommendations come down to a few simple reflexes.

Be wary of QR codes appearing on unexpected physical documents or on easily accessible public fixtures. Before confirming anything, check the web address that opens after the scan: an address that does not exactly match the official site should put you on alert. When in doubt, do not use the code: go directly to the provider’s official website or app, and enter the tracking or reference number yourself.

Remember, too, that Swiss Post does not charge a fee for a standard delivery attempt. Any payment request of this kind is a warning sign. And if you have shared your card details, have the card blocked without delay.

What this means for an SME

This topic goes beyond the private sphere. Your employees scan QR codes every day, including on devices that access company systems. An employee tricked at home may use the same passwords at the office, or click on a link received at their professional address. Moreover, if your own company uses QR codes (on invoices, communication materials, posters), criminals can imitate them and divert your customers by impersonating you, which puts your reputation at risk.

Regularly raising your teams’ awareness is therefore an effective first line of defence, and you can put it in place yourself. But it covers only part of the problem. Knowing which of your processes (payments, invoices, customer communication) are genuinely exposed to this kind of impersonation, and how to protect them, requires looking at your organisation in detail.

In conclusion

Quishing illustrates an underlying trend: the most effective attacks do not rely on a technical feat, but on trust and habit. A familiar logo, a routine gesture, and the trap snaps shut. Informing and training your people remains within your reach, and it is essential. To go further and secure your internal processes for the long term, an assessment tailored to your company makes it possible to pinpoint exactly where your blind spots lie, and how to close them.