• Latest
  • Trending
Media outlets consider influencers law pointless

Manipulated QR codes and quishing

27. February 2026
BGH considers Uber Black to be anti-competitive

Distance learning, coaching and synchronous online formats

2. March 2026
AI agents as autonomous contractual partners?

AI agents as autonomous contractual partners?

26. February 2026
Platform cooperatives as a financing and business model

AI training data as an asset: accounting, IP strategy and exit factor

25. February 2026
Streaming setup, influencers and contract law

Influencers: when marketing suddenly becomes commercial agency law

18. February 2026
Insolvency administrator and access to tax office data?

NRW audits influencers – and suddenly normal rules apply?

12. February 2026
iStock 1405433207 scaled

Legal pitfalls in revenue-based financing for start-ups

12. February 2026
Streaming setup, influencers and contract law

Streaming setup, influencers and contract law

9. February 2026
Platform cooperatives as a financing and business model

Platform cooperatives as a financing and business model

8. February 2026
Frankfurt district court a.M. softens influencer jurisdiction

VAT on donations, gifts and “support” from influencers?

5. February 2026
Chamber Court on obligations to injuntture in the case of acts of third parties

Jurisdiction in the contract: one word too many, one word too few

4. February 2026
New info on the status of the State Media Treaty

Customer hotline and support in SaaS

2. February 2026
BGH considers Uber Black to be anti-competitive

BGH: FRAND objection fails due to lack of willingness to license

28. January 2026
marianregel

InformationCheck.de is live: side project for source-based classification of social media claims

22. January 2026
DPMA

Paid mods, fan guidelines and EULA: when monetization is possible

21. January 2026
Is an 8 year old allowed to be an Esport player?

LOI, term sheet, MoU, often binding for startups?

20. January 2026
What actually is an IP? In the games, music and film industry!

Freelancer paid, but still not getting rights?

19. January 2026
Affiliate links for streamers and influencers

Comparison sites as an SEO trick

16. January 2026
Reverse vesting

Vesting, good leavers, bad leavers – why a lack of regulations costs startups dearly

15. January 2026
ai generated g63ed67bf8 1280

AI guideline for agencies and external service providers

14. January 2026
AI-generated music in films, games and on streaming platforms

AI-generated music in films, games and on streaming platforms

13. January 2026
  • Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Kurzberatung
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

Manipulated QR codes and quishing

27. February 2026
in Other
Reading Time: 5 mins read
0 0
A A
0
bqrsmevl 400x400

QR codes have long been part of everyday life: they make it easier to open websites, pay by smartphone or access digital content. This convenience is also a structural risk. Criminals use manipulated QR codes to steal data, access data or authorize bank transactions – a phenomenon that now has its own name: quishing (a combination of “QR” and “phishing”). Quishing leads to considerable financial losses, particularly in the area of classified ad platforms and private transactions.

Content Hide
1. How does quishing work technically and psychologically?
2. Typical attack scenarios – especially with classified ads
3. Two-factor authentication (2FA): Protection mechanism with limits
4. Prevention strategies: security beyond technical mechanisms
5. Legal classification: reimbursement, liability and gross negligence
6. What to do if you are affected?
7. Conclusion
7.1. Author: Marian Härtel

This article explains how manipulated QR codes and quishing work, why conventional protection mechanisms such as two-factor authentication (2FA) are not always sufficient, what legal problems arise from this and how those affected can effectively protect themselves and act in a legally correct manner.

How does quishing work technically and psychologically?

A QR code is technically nothing more than a coded URL. As soon as a smartphone scans it, a link is opened – without the target address being visible beforehand. Attackers take advantage of this behavior by generating QR codes that link to deceptively real, fake websites. After scanning, victims often uncritically open a page that appears authentic and enter access data, TAN codes or personal information. In many cases, the perpetrators go one step further and use social engineering: they create pressure situations (“release payment, otherwise the offer will expire”) to force a 2FA confirmation.

In classic phishing, manipulated emails with links are sent. In quishing, on the other hand, the “link” is already distributed as a QR code – via messengers, advertising portals, printed flyers, stickers in public places or direct correspondence. As a result, quishing attacks take place in situations in which users subjectively assess the source as “safe”, e.g. in chats with supposed buyers/sellers or via personal messages.

Typical attack scenarios – especially with classified ads

The risk is particularly pronounced in classified ad trading and other peer-to-peer transactions. Several factors come into play here:

  • First, a seemingly serious contact is established, for example in a chat on a popular platform.
  • The alleged buyer or seller sends a QR code claiming that this is the official payment link, a shipping label or a verification process.
  • The victim scans and is taken to a deceptively genuine login page that mimics the login to a payment service, for example.
  • After entering access data or confirming a transaction, data is transferred to the perpetrators or payment is unintentionally authorized.

Another special criminal logic can be observed in the context of classified ads: The QR code is used to create a supposed legitimacy (“This is the secure payment page”), although there is no direct connection to the actual platform. This often results not only in financial losses, but also in identity fraud and account takeovers.

Two-factor authentication (2FA): Protection mechanism with limits

Two-factor authentication is often referred to in legal and security advice. 2FA is intended to ensure that access is only possible with two independent proofs, such as a password and an additional code or a push confirmation.

In principle, 2FA reduces the risk that a stolen password is enough to gain unauthorized access to an account. In practice, however, there are two weak points:

  1. Social aspect: If the user is prompted to approve the transaction using a fake credential, they are consciously and actively confirming the transaction, albeit under deception. The 2FA mechanism is thus not “circumvented”: It is carried out by the victim themselves.
  2. Technical characteristics of 2FA: Phishing tolerance differs depending on the type of second factor:
    • With SMS-TAN or time-based app codes, the generated code can be entered directly into a fake page.
    • Push confirmations in banking apps are particularly tricky: they appear on the legitimate device and are often confirmed without the user fully understanding the consequences.

Only 2FA methods with cryptographic binding to the legitimate domain (e.g. security keys according to the FIDO standard) significantly reduce this risk. However, these are not yet supported by many services across the board.

Prevention strategies: security beyond technical mechanisms

Technical protective measures are important, but not sufficient. Legal advice and cybercrime prevention therefore rely on a combination of technology, awareness and process rules:

  • QR codes should always be treated as external links. If possible, the target URL should be checked before opening, e.g. by means of a preview or by using a QR scanner that enables a URL preview.
  • When making money transactions, it is a duty of care to only initiate payments via the official sites or apps of the payment service or platform in question.
  • Confirming a 2FA request should not be a knee-jerk reaction, but should always be done by checking the specific purpose, the transaction details and the context.
  • “Off-platform” links should always be avoided. Reputable providers offer their own protected workflows.
  • In public spaces, sticking on manipulated QR codes (so-called “overstickers”) can operate. Indications such as visible overstickers, crooked placement or stickers affixed afterwards are warning signals.

These measures not only have a technical effect, but are also legally relevant. In any liability or reimbursement proceedings, the extent to which the person concerned was able to recognize the typical warning signals or whether they breached their duty of care will be examined.

Legal classification: reimbursement, liability and gross negligence

If an unauthorized payment flow occurs, the legal basis is primarily to be found in payment services and banking law, in particular in Sections 675u et seq. BGB (GERMAN CIVIL CODE). The claim for reimbursement of unauthorized payments is generally based on Section 675u BGB. The refund regulation stipulates that the payment service provider must refund the amount without delay if the payment was not authorized by the payer.

At the same time, Section 675v BGB allows the payment service provider to reduce or refuse liability in the event of gross negligence on the part of the customer. Whether behavior is to be classified as grossly negligent depends on the specific individual case. The sparse case law in this area regularly emphasizes that obvious security breaches or ignoring warnings constitute a grossly negligent breach of duty.

This means for those affected: Even if technical manipulations are present, the question in the event of a dispute is not decided solely on the existence of deception, but on whether the security breach was objectively recognizable and whether the person concerned violated the usual standards of care. Careful documentation of the incident and the person’s own actions is crucial here.

What to do if you are affected?

In the event of an actual or suspected quishing attack, a structured approach is recommended:

  1. Stop transaction immediately: Suspend payment transactions, change access data, update relevant passwords.
  2. Inform bank/payment service provider: Arrange for accounts and cards to be blocked.
  3. Apply for reimbursement and provide legally binding documentation: Timely written declaration to the payment service provider, with evidence if necessary.
  4. Press charges: file a criminal complaint with the police for fraud or phishing/quishing; secure evidence.
  5. Communication with the platform: Inform providers of classified ads/web services to prevent further damage.

This procedure not only serves to limit damage, but can also be of decisive importance in the context of later legal disputes.

Conclusion

The combination of visual credibility, mobile convenience orientation and lack of URL transparency makes manipulated QR codes and quishing a real threat – especially in contexts where transactions take place between private individuals. Traditional security mechanisms such as two-factor authentication are important, but they are no substitute for critical examination, conscious action and demanding rules of conduct.

In case of doubt, it is advisable to only process transactions via official workflows and not to scan in the event of ambiguities, but to act directly via the app or browser. In an emergency, those affected should act quickly in order to protect legal claims and professionally clarify potential liability issues.

 

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Weitere spannende Blogposts

LG Munich: Data protection consent on dating platform

LG Munich: Data protection consent on dating platform
7. November 2022

The Munich Regional Court has once again impressively shown why anything other than standard data protection declarations should only be...

Read moreDetails

Geoblocking Regulation and Purchase on Account

Online shops: Attention to advertising with EIA
26. March 2019

Whether online services, apps, SaaS providers, hosting providers, online stores or other companies that offer services or products over the...

Read moreDetails

Renate Künast is successful at the Court of Appeal

30. March 2020

In response to Renate Künast's appeal, the Berlin Court of Appeal issued a ruling on 11 March 2020 that partially...

Read moreDetails

ECJ overturns Privacy Shield: review contracts!

District Court Frankfurt a.M. on the right to be forgotten
7. November 2022

The General Data Protection Regulation(GDPR) stipulates that personal data may in principle only be transferred to a third country if...

Read moreDetails

Legal aspects of crowdfunding and alternative forms of financing for start-ups

Legal aspects of crowdfunding and alternative forms of financing for start-ups
10. October 2024

Crowdfunding and other alternative forms of financing have become important instruments for start-ups to raise capital in recent years. These...

Read moreDetails

Unauthorized discarding of returns soon prohibited?

Unauthorized discarding of returns soon prohibited?
7. November 2022

At the suggestion of Federal Environment Minister Svenja Schulze, the Federal Cabinet today launched the draft bill to amend the...

Read moreDetails

Taking on investors in a startup: timing, risks and legal framework

Taking on investors in a startup: timing, risks and legal framework
28. March 2025

Sooner or later, almost every growth-oriented company comes to the point where substantial external financing is required - be it...

Read moreDetails

Attention: Risk of discrimination with gender information on websites

151b5dca2f9aac11ac0b0c97ff33a2a6
24. September 2024

As a provider of online services, SaaS solutions or other websites, it is important to observe the legal requirements with...

Read moreDetails

Q&A: Legal issues for game developers

judge plays videogames in his spare time
7. November 2022

In addition to e-sports teams/gamers, streamers and influencers, I also continue to advise game developers on the review and drafting...

Read moreDetails
BGH considers Uber Black to be anti-competitive
Law and Esport

Distance learning, coaching and synchronous online formats

2. March 2026

The Distance Learning Protection Act (FernUSG) has been experiencing a renaissance for some time now. What for decades was considered...

Read moreDetails
Media outlets consider influencers law pointless

Manipulated QR codes and quishing

27. February 2026
AI agents as autonomous contractual partners?

AI agents as autonomous contractual partners?

26. February 2026
Platform cooperatives as a financing and business model

AI training data as an asset: accounting, IP strategy and exit factor

25. February 2026
Streaming setup, influencers and contract law

Influencers: when marketing suddenly becomes commercial agency law

18. February 2026

Podcastfolge

AI in law: opportunities, risks and regulation – the IT Media Law Podcast Episode 3

AI in law: opportunities, risks and regulation – the IT Media Law Podcast Episode 3

24. September 2024

Welcome to the third episode of our podcast "IT Media Law"! In this episode, we delve into the fascinating world...

Read moreDetails
092def0649c76ad70f0883df970929cb

Influencers and gaming: legal challenges in the digital entertainment world

26. September 2024
d5ab3414c7c4a7a5040c3c3c60451c44

The metaverse – legal challenges in virtual worlds

26. September 2024
8ffe8f2a4228de20d20238899b3d922e

Web3, blockchain and law – a critical review

26. September 2024
8315f1ef298eb54dfeed2f5e55c8b9da 1

First test episode of the ITMediaLaw Podcast

26. August 2024

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung