← All terms

Quishing

Quishing (QR code phishing) is a social engineering attack that uses malicious QR codes to direct victims to credential-harvesting sites or malware downloads.

Quishing — QR code phishing — uses QR codes to deliver malicious URLs. Because QR codes are opaque (you cannot read the destination before scanning), they bypass many of the visual checks people rely on to spot traditional phishing.

How it works

Attackers place malicious QR codes where they will be scanned without suspicion:

  • Email attachments. A PDF invoice, parking notice, or MFA setup guide includes a QR code instead of a clickable link — which also evades email link-scanning filters.
  • Physical placement. Stickers on parking meters, posters in office lobbies, or printed mailers with QR codes lead to credential-harvesting pages. Public spaces where QR codes are expected (restaurant menus, event registration) are common targets.
  • Badge or lanyard codes. In high-security environments, attackers have placed fake QR codes on ID badge holders or access point signage.

When scanned, the QR code opens a URL in the phone's browser — typically a fake login page for Microsoft 365, Google Workspace, or a corporate VPN portal. Because the page opens on a mobile device, the shortened URL bar and lack of security extensions make the fake harder to identify.

How to defend against it

  • Include QR code scenarios in simulations. NOUSEC supports quishing simulations across both digital (email-embedded) and physical (printed) delivery methods.
  • Teach employees to preview QR destinations — most phone cameras show the URL before opening it. If the domain looks unfamiliar, do not proceed.
  • Use email security solutions that can render and inspect QR codes embedded in attachments and images.
  • Establish physical security controls to detect and remove unauthorized QR codes placed in office spaces.
Full guide
Read the deep dive on this attack →

Related terms

PhishingPhishing is a social engineering attack that uses fraudulent emails, websites, or messages to trick people into revealing sensitive information or installing malware.SmishingSmishing (SMS phishing) is a social engineering attack that uses text messages to trick recipients into clicking malicious links or sharing sensitive information.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo