Skip to content
Attacks

Quishing

Quishing (QR phishing) is a variant of phishing in which the attacker plants a malicious QR code that leads to a fake page harvesting login or payment credentials. The QR code bypasses many anti-spam filters, because email gateways do not decode images.

What is quishing?

Definition of quishing

Quishing (from QR + phishing) is a social engineering attack technique in which, instead of a classic link, the attacker plants a malicious QR code. After being scanned with a phone, the code redirects the victim to a fake page that impersonates a trusted service and harvests login credentials, payment card data, or installs malware.

Why is quishing so effective?

Quishing exploits several gaps at once:

  • It bypasses email filters — email security gateways scan text and links, but usually do not decode the image of a QR code, so the message gets through.
  • It moves the attack to a personal phone — by scanning the code, the victim leaves the protected corporate computer and lands on a mobile device, often without EDR protection.
  • It builds trust in the format — QR codes have become commonplace (menus, payments, parking meters), so users scan them reflexively.

Typical attack scenarios

  • Fake fines and payment demands with a QR code (e.g. stickers on parking meters).
  • Messages about an alleged parcel awaiting payment (courier, parcel locker).
  • Forged login QR codes in corporate panels and banking.
  • Fake promotions and surveys offering a reward after scanning.

How to defend against quishing?

  • Treat a QR code like a link — check the address of the page before entering data.
  • Do not log in to corporate services via QR codes from email or SMS messages.
  • Deploy phishing-resistant multi-factor authentication (FIDO2 / hardware keys).
  • Run security awareness training that covers the latest social engineering techniques.
  • Report suspicious codes to the security team.
  • Phishing — the parent category of social engineering attacks
  • Smishing — phishing via SMS
  • Vishing — voice phishing
  • BEC — business email compromise

Explore our services

  • Penetration testing — including controlled social engineering simulations
  • SOC 24/7 — detection and response to the consequences of successful attacks

Quishing shows that protecting email is not enough — what matters is team awareness and resilient authentication.

Tags:

quishing phishing QR social engineering credential theft

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist