The QR That Opens a Website and the QR That Pays
Two different scams are circulating under the same name. In one, the QR Code hides a link and leads to a fake site. In the other, the QR is a payment and the payee has been swapped. The figure that made headlines measures only the first — and the defense against one is useless against the other.

▸In this article
Between September 15 and 17, the tech press reported that QR Code phishing had "surged 460% in Brazil." Days earlier, Procon-SP had warned about something else entirely: Pix QR Codes swapped inside online stores. On social media, the two stories merged into one — the "QR Code scam." They are not the same. And anyone who conflates them walks away with the wrong advice for whichever scam actually hits them.
One name for two things
Quishing is phishing in which the link travels inside a QR Code. The definition comes from ESET itself, in its global threat report for the first half of 2026: embedding a malicious URL inside a QR Code to steer the victim to a fake site. What the company measures, as we will see, is the version that arrives by email. The target is a password, card data, access to an account. The QR is merely the envelope — it lets the link slip past filters that read text, and it moves the victim onto a phone, where there is less protection.
The other scam involves no link and no fake site. The QR is a Pix payment, legitimate in form, with the wrong payee in its content. The victim opens their bank's genuine app, scans the code, confirms, and the money goes to someone else's account.
What the number measures
Three sources have circulated this year. They measure broadly similar things, and none of them measures payments.
ESET's global report. The detection the company labels QRCode/Phishing is a layer of its email scanner: it finds the QR inside the message or attachment, decodes the URL, and tests it. In the first half of 2026, roughly 11% of detected phishing emails used a QR Code, averaging 100,000 detections per month and peaking in April. The list of most-affected countries opens with the United States (19%) and Spain (17%). Brazil does not appear on it. And the category's trend chart begins in September 2025 — the series is less than a year old.
ESET Brazil's press release. That is where the "460%" comes from: the growth in detections in the country between January and February 2026. The same release states that two categories combined, QRCode/Phishing and QRCode/URL, accounted for 7.2% of phishing detections in Brazil over the half-year, and that PDF files were the vehicle for 52% of the phishing detected. The figures are attributed to Jonathan Ramos, a security researcher at the company. We could not locate any ESET publication of its own carrying this data: the text ran, word for word, across several news portals, with no link to the source.
Microsoft. In its first-quarter email threat roundup, published on April 30, the company counted 7.6 million QR Code phishing attacks in January and 18.7 million in March, a 146% increase. A PDF attachment was the vehicle in 65% to 70% of cases, and the dominant objective was credential theft via fake login pages.
Set side by side, the numbers call for three caveats.
First: 460% is a one-month change, published without the baseline. Microsoft, which measures a similar phenomenon, publishes the absolute figure for each month; the Brazilian release gives only the percentage. In a series with only a few months of history, any jump over a weak month yields an enormous percentage.
Second: the number is from the start of the year. The headline is from September; the spike runs from January to February. In its next roundup, dated July 23, Microsoft records that volume fell for three consecutive months after the March peak, closing June at 8.3 million. What is now circulating as a wave describes last summer.
Third: 7.2% and 11% are not the same calculation. One is Brazil, two categories, measured against phishing detections; the other is global, measured against phishing emails. Neither updates the other.
And here is the point that matters to anyone paying a bill: all three yardsticks measure email. None mentions Pix, and none measures payment QRs. The Brazilian release notes, in passing, that the QR Code has become part of the "payments routine" — and it is in that passing remark that the reader adds up what the sources never added up.
A Pix QR is not a link
The difference between the two scams starts with what each QR carries, and that is set out in the Manual de Padrões para Iniciação do Pix, version 2.10.0, one of the documents that make up the Regulamento do Pix.
In a static QR, the manual states, "all the data required to initiate the payment (settings) are entirely contained within the QR Code itself": the payee's Pix key, which is mandatory, and, if the issuer chooses, an amount, an identifier, and a free-text field. There is no address to visit.
The dynamic QR "is configured with a URL that is accessed at the moment it is read" — but it is not a URL for a browser. It carries no protocol prefix, it points to an address belonging to the payee's PSP, and access occurs, in the manual's words, "after validations, including the valid domain authorized by the payee's PSP for generating QR Codes, exclusively via HTTPS." The party making that request is the payer's banking app, and what comes back is the charge data, not a page.
In plain terms: a Pix QR only makes sense to a banking app. And what appears after the scan is not a website — it is the payment confirmation screen.
Two defenses that are not interchangeable
| Quishing | Swapped payment QR | |
|---|---|---|
| What the QR carries | a link for the browser | the data for a Pix transfer |
| Where the scam happens | on a fake site | inside the bank's genuine app |
| What is lost | password, card, access | the amount paid |
| Where to look | the page address, before typing anything | the payee's name and CPF or CNPJ, before confirming |
| Who mandates that defense | no one: it is a habit | the Banco Central |
The last row is what changes the game. With Pix, the verification screen is not a courtesy from the bank. The Manual de Requisitos Mínimos para a Experiência do Usuário, version 7.3, requires that, before confirmation, "the paying user must be shown the DICT data on the receiving user" — DICT being the Pix key directory — namely, "Name, CPF (masked) / CNPJ (unmasked) and the amount read from the QR Code (if any)." It adds that the payer "may cancel the payment, but may not edit data read from the QR Code." The amount comes from the code; the name and tax ID come from the key's registration in the directory. The code can be tampered with, but the name the app displays is that of the account holder who will receive the money, not a label written by whoever generated the QR.
That defense has a limit, which we covered in our analysis of the swapped QR at checkout: in an online store, the legitimate payee is usually the payment provider rather than the merchant, and the name on the screen tells you little. But it is the defense that exists, and it has nothing to do with website addresses.
Swapping the two is pointless. "Check the address" protects no one paying via Pix: there is no address. "Check the payee" protects no one who typed a password into a fake page: there is no payee.
Where the two meet
There are two intersections, and that is where the confusion costs money.
The first is the "duplicate copy" email — a boleto, an invoice, a tax receipt — with a PDF attached. It is the vehicle that both ESET and Microsoft identify as dominant in phishing. If the QR inside that PDF is a genuine Pix generated by the fraudster, the delivery is phishing and the payment is Pix. The phishing defense fails, because there is no site to be suspicious of. The Pix defense works: the name on the confirmation screen is not that of the company supposedly billing you.
The second is the fake page that charges via Pix. The QR in the email leads to a cloned site, and the site displays a Pix code for payment. Here both checks apply, in sequence: the address first; the payee after.
Neither intersection carries a figure in the sources we reviewed. They appear here as a consequence of the two mechanisms, not as a measured trend.
The rule worth taking away: a QR Code that, when read by the camera, opens a page asking for a password, card data, or offering a "pay here" button is not a Pix QR. A Pix by QR Code is scanned and confirmed inside the banking app — and there, the screen that matters is the one showing who will receive the money. If the money is already gone, the route is the Mecanismo Especial de Devolução, requested from your own bank.
What the law calls each one
The electronic fraud offense under art. 171, § 2º-A, of the Código Penal — four to eight years' imprisonment — has existed since Lei nº 14.155 of 2021, and that year's text already covers the first scam. It punishes fraud "committed using information supplied by the victim or by a third party induced into error by means of social networks, telephone contacts, the sending of fraudulent electronic mail," or an analogous means. In quishing, that is exactly what happens: the victim, deceived by an email, supplies the password or the card.
In the swapped payment QR, the victim supplies no information at all: they pay. Fitting it under § 2º-A remains possible — via the wording added to the paragraph by Lei nº 15.397 of 2026, "duplication of an electronic device or internet application," via the closing clause "any other analogous fraudulent means," or via the fraudulent email that delivered the code — but the fit is no longer automatic. The difference matters because, outside § 2º-A, what remains is the caput, carrying a sentence of one to five years. This is a reading of the statutory text, not an assertion of how a given case would be charged, which depends on the specific facts and on who analyzes them.
Where funds have been transferred, as with Pix, jurisdiction lies with the victim's place of domicile, under art. 70, § 4º, of the Código de Processo Penal.
In one line
A QR Code may hide a link or it may be a payment. For the first, check the address; for the second, check who is receiving — and be suspicious of any "Pix" that asks to be paid outside the banking app.
Sources
The numbers
- ESET, Threat Report H1 2026, section "Stop before you scan: QR code phishing on the rise," pp. 14-15
- Microsoft Threat Intelligence, "Email threat landscape: Q1 2026 trends and insights", April 30, 2026
- Microsoft Threat Intelligence, "Email threat landscape: Q2 2026 trends and insights", July 23, 2026
- ESET Brazil press release, as reported by TI Inside on September 15, 2026, and by Inforchannel on September 16, 2026
The Pix rules
- Manual de Padrões para Iniciação do Pix, version 2.10.0, sections 2.4.1, 2.4.2 and 2.5.2
- Manual de Requisitos Mínimos para a Experiência do Usuário, version 7.3
Criminal law
About the author

Robert F.
request a secure channelRobert F. is the founder of CyberX, a digital intelligence operation applied to investigation, based in Brazil with cross-border reach.
He works in OSINT, on-chain tracing and antifraud for legal teams, corporate compliance, banking antifraud and public authorities.
In CyberX publications we write about what can be said in public — fraud and scam typologies, digital threats, on-chain tracing, regulation, and what separates an investigation from a database lookup. Never about a case we work on, clients, matters under judicial secrecy, or operational detail that would compromise an investigation in progress — ours or anyone else's. A third party's case enters through the public official act, and through what it teaches, not through what it exposed.
Related reading
CyberX works in digital intelligence applied to investigation — OSINT, on-chain tracing, and fraud prevention. This content is informational and does not constitute legal advice.
how we write →Source: https://cyberx.to/en/analysis/the-qr-that-opens-a-website-and-the-qr-that-pays
Retrieved on