Why QR codes get used this way
Quishing is phishing through a QR code. Scanning moves you from a screen that your company's email filter or desktop browser might have checked to a phone where the web address is harder to read, which is part of why it works. Common versions include stickers placed over legitimate codes on parking meters and payment kiosks, and emails or letters that appear to come from a bank, a delivery company, or an employer's IT department. What was taken determines what comes next, whether that is card details, a banking login, a work password, or a payment you made directly on the fake page.
Containing the damage
If you entered card information, call the card issuer using the number on the card and ask to block it; charges a thief makes later with stolen details are generally treated as unauthorized. A payment you made on the fake page yourself may still be disputable with a credit card issuer, though that process differs from a fraud claim. If you entered a password, change it everywhere you reused it, starting with email, and turn on stronger sign-in protection. For a work account, report it to your IT or security team immediately rather than trying to fix it quietly, since employers usually need to act fast to cut off access. Keep a photo of the QR code and the web address it opened, if you can do so safely.
When it becomes a legal matter
Most individual quishing losses are handled through the bank and the standard reporting channels, and a lawyer is often unnecessary. Legal help becomes more relevant when a bank refuses to treat a loss as unauthorized, when identity theft follows, or when a business account was compromised and customer or employee data may have been exposed, which can trigger notification obligations. Businesses that display QR codes, such as parking operators or restaurants, may also face questions if tampered codes went unnoticed. A consultation focuses on what was entered, what has been reported, and which obligations or claims are actually in play.