Check first, then open.
QRTrust checks every QR code against Europe's largest quishing database before you open it. Report suspicious codes directly – we take care of the follow-up.
How it works
Scan the code with your camera, upload a photo or paste the link. The link is not opened.
QRTrust compares the destination with its own quishing database and other phishing lists and follows redirects to the final page. The result appears within a few seconds.
Only open the link if the result is green. Report a suspicious code directly, optionally with a photo and location. We take care of everything else.
Traffic light
Our tip: Bookmark qrtrust.de or add it to your phone's home screen. That way the check is at hand when you are standing at a parking meter or charging station.
Follow-up
At QRTrust, a report does not end up in an inbox. We follow up on every confirmed case so that the fake code disappears and others are warned.
We capture the scam page with a screenshot, timestamp and technical data before it goes offline.
We inform the company whose name is being misused, such as the bank, the parking operator or the charging provider.
We work with the relevant authorities and provide the secured evidence for prosecution.
Confirmed cases are added to the quishing database and the quishing map. Every further scan of the code is then flagged as dangerous.
A fake letter led to a phishing site via a QR code. A supposed bank employee then persuaded the doctor by phone to approve 39 transfers.
Journalist Alberto Stegeman warned about QR code fraud on Dutch television. Four further incidents have been reported in the Netherlands and Belgium.
The notices carry a city logo, the correct number plate and a QR code for instant payment, police said. They are left on parked cars.
Background
Quishing is phishing via QR code. Fraudsters stick fake codes on parking meters and charging stations, print them on fake bank letters or parking tickets and send them by email. The code leads to a cloned page that asks for login or card details.
Unlike a link in an email, a QR code does not reveal where it leads. That is exactly what the perpetrators exploit.
FAQ
Made in Germany
Your data stays in Germany - guaranteed GDPR compliant.