Quishing
Quishing (QR phishing) is a variant of phishing in which the attacker plants a malicious QR code that leads to a fake page harvesting login or payment credentials. The QR code bypasses many anti-spam filters, because email gateways do not decode images.
What is quishing?
Definition of quishing
Quishing (from QR + phishing) is a social engineering attack technique in which, instead of a classic link, the attacker plants a malicious QR code. After being scanned with a phone, the code redirects the victim to a fake page that impersonates a trusted service and harvests login credentials, payment card data, or installs malware.
Why is quishing so effective?
Quishing exploits several gaps at once:
- It bypasses email filters — email security gateways scan text and links, but usually do not decode the image of a QR code, so the message gets through.
- It moves the attack to a personal phone — by scanning the code, the victim leaves the protected corporate computer and lands on a mobile device, often without EDR protection.
- It builds trust in the format — QR codes have become commonplace (menus, payments, parking meters), so users scan them reflexively.
Typical attack scenarios
- Fake fines and payment demands with a QR code (e.g. stickers on parking meters).
- Messages about an alleged parcel awaiting payment (courier, parcel locker).
- Forged login QR codes in corporate panels and banking.
- Fake promotions and surveys offering a reward after scanning.
How to defend against quishing?
- Treat a QR code like a link — check the address of the page before entering data.
- Do not log in to corporate services via QR codes from email or SMS messages.
- Deploy phishing-resistant multi-factor authentication (FIDO2 / hardware keys).
- Run security awareness training that covers the latest social engineering techniques.
- Report suspicious codes to the security team.
Related terms
- Phishing — the parent category of social engineering attacks
- Smishing — phishing via SMS
- Vishing — voice phishing
- BEC — business email compromise
Explore our services
- Penetration testing — including controlled social engineering simulations
- SOC 24/7 — detection and response to the consequences of successful attacks
Quishing shows that protecting email is not enough — what matters is team awareness and resilient authentication.