Quishing
Quishing (QR code phishing) is a social engineering attack that uses malicious QR codes to direct victims to credential-harvesting sites or malware downloads.
Quishing — QR code phishing — uses QR codes to deliver malicious URLs. Because QR codes are opaque (you cannot read the destination before scanning), they bypass many of the visual checks people rely on to spot traditional phishing.
How it works
Attackers place malicious QR codes where they will be scanned without suspicion:
- Email attachments. A PDF invoice, parking notice, or MFA setup guide includes a QR code instead of a clickable link — which also evades email link-scanning filters.
- Physical placement. Stickers on parking meters, posters in office lobbies, or printed mailers with QR codes lead to credential-harvesting pages. Public spaces where QR codes are expected (restaurant menus, event registration) are common targets.
- Badge or lanyard codes. In high-security environments, attackers have placed fake QR codes on ID badge holders or access point signage.
When scanned, the QR code opens a URL in the phone's browser — typically a fake login page for Microsoft 365, Google Workspace, or a corporate VPN portal. Because the page opens on a mobile device, the shortened URL bar and lack of security extensions make the fake harder to identify.
How to defend against it
- Include QR code scenarios in simulations. NOUSEC supports quishing simulations across both digital (email-embedded) and physical (printed) delivery methods.
- Teach employees to preview QR destinations — most phone cameras show the URL before opening it. If the domain looks unfamiliar, do not proceed.
- Use email security solutions that can render and inspect QR codes embedded in attachments and images.
- Establish physical security controls to detect and remove unauthorized QR codes placed in office spaces.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo