The danger of quishing was highlighted at a recent anti-fraud convention in Singapore. Photo Credit: Adobe Stock/deagreez
Attendees are more scan-happy than ever before with QR codes a ubiquitous part of events today. This has made events a target of ‘quishing’, or QR code phishing that tricks users into giving scammers sensitive personal information.
The danger of quishing was highlighted at a recent anti-fraud convention in Singapore, where attendees were presented with a fake QR code that promised to help them skip the queue, demonstrating how easily attackers can exploit convenience.
What does quishing look like?
Event experts say that QR codes can lead attendees to rogue microsites mimicking the organiser brand, with fake speaker or sponsor listing, said Lorela Chia, managing director of GR8 Dreams. There may also be deep-link phishing disguised as feedback forms.
Phishers can attack from many fronts. Beyond QR codes, malicious links may reach eventgoers disguised as event updates, through fake emails or texts asking attendees to ‘confirm details’ or ‘download schedules’, added Atika Rosli, chief executive at Beyond Events.
The moment someone enters your event, they’re not just stepping into a room, they’re entering your system. And systems have responsibilities.
Lorela Chia, managing director of GR8 Dreams
Cyber duty
It is not just phishing for personal information that threatens eventgoers – but also malicious links that insidiously install malware compromising devices.
The implications are especially heavy for B2B events. “At high-level B2B or policy-driven conferences, the data circulating aren’t just names and emails – it’s cross-border contacts, trade interests, sometimes even pre-commercial insights,” Chia remarked.
This means business event organisers must hold themselves to even greater cybersecurity duties and responsibilities. They should not approach events with “the same tools and assumptions used for consumer expos or lifestyle events”, Chia urged.
“We need to be more deliberate. The moment someone enters your event, they’re not just stepping into a room, they’re entering your system. And systems have responsibilities,” she added.
As attendees tend to underestimate digital risks, event organisers are urged to put up visible reminders to scan QR codes on official signage or apps.Quash the quishers
Brett Han, managing director at iCube Events, noted that education and signage are key to quish prevention, as attendees tend to underestimate digital risks.
“Put up visible reminders such as ‘only scan QR codes on official signage or in our apps’ while pre-event briefings can significantly reduce exposure,” he said.
“Encourage attendees to scan QR codes only through the event’s official mobile app or ensure physical codes are branded, tamper-evident and displayed in controlled spaces, where event staff are monitoring.”
It is important that organisers centralise communication channels to ensure all official updates, links and QR codes are distributed via a single, verified app portal, or event website. As Han pointed out, consistency will help reduce the chance that attendees are misled by fakes.
Echoing the importance of revising event SOP with new anti-quishing roles, Chia said: “Organisers must evolve from just managing programme flow to designing for trust.
“That means using branded, verifiable QR codes linked to your primary domain and training floor staff to redirect attendees to official scan points.”
Encourage attendees to scan QR codes only through the event’s official mobile app or ensure physical codes are branded, tamper-evident and displayed in controlled spaces, where event staff are monitoring.
Brett Han, managing director, iCube Events
Inside matters
Besides preventing attendees from giving out information to bad actors, internally, Chia advised organisers to improve their own governance of data.
She cautioned against collecting data “just in case – only what you can account for”. Organisers may also offer a ‘Data Use Statement’ at registration that sets a new baseline of transparency.”
Rosli added that organisers may also enforce two-factor authentication for staff managing attendee information, while Chia cautioned against using unmoderated public Wi-Fi that makes it easy for hackers to harvest credentials.
QR culture to blame?
Do the benefits of digital tools outweigh the risks? Yes, says Rosli, when security measures are visible and clear – QR codes save time, cut down on paper waste, and improve the event experience.
Han added that QR codes streamline check-in, enable contactless interactions, and make it easier to share content or connect attendees. For event and conference organisers, they lower printing costs and provide valuable data on engagement.
“I don’t think people will stop scanning but I do believe we’re entering an era where attendees will become more discerning: asking questions, looking for trust signals, and avoiding platforms that feel ambiguous or unsafe,” Chia said.
Rather than abandoning QR codes, the focus should be on building trust through visible safeguards.
“Attendees are generally comfortable using digital tools if they are aware that organisers have taken precautions – much like credit card use, where fraud exists but security measures and guarantees make people continue to use them,” Han explained.
This article was first published in the October-December 2025 issue of M&C Asia as the “Scan or scam?” feature. Click here to read more from this issue.