QR Code Phishing (“Quishing”): The Attack Hiding in Plain Sight

What Makes Quishing Different From Regular Phishing

A traditional phishing email contains a malicious link somewhere in the text or an attachment. Email security gateways have gotten reasonably good at catching these. They scan link text, check domain reputation, and flag suspicious attachments before anything reaches an inbox.

A QR code sidesteps all of that. The malicious URL isn’t written anywhere a scanner can easily parse it. It’s encoded as a pattern of black and white squares embedded in an image. Most secure email gateways were built to analyze text and metadata, not to decode the contents of a picture and evaluate the link hidden inside it.

There’s a second layer that makes quishing particularly effective: the scan almost always happens on a personal device. An employee opens the email on their work laptop, sees a QR code, and instinctively reaches for their phone to scan it. That phone is often outside the reach of corporate security controls. No endpoint protection, no DNS filtering, no browser isolation. The attacker has quietly moved the victim off the monitored network and onto one where almost nothing is watching.

Why the Primary Keyword Phrase Matters Here

QR code phishing works because it exploits the trust gap between what looks familiar and what’s actually safe. People have been trained for years to be cautious about clicking links in emails. Far fewer have been trained to be cautious about scanning a code with their camera. It feels more like using a tool than clicking a hyperlink, and that small psychological difference is enough to lower a person’s guard.

Attackers know this. They also know that QR codes are now genuinely common in legitimate business contexts, which makes the whole thing harder to flag as suspicious on sight.

Where These Attacks Show Up

Quishing campaigns tend to follow a handful of familiar patterns, and understanding them helps a security team know what to watch for.

Fake multi-factor authentication prompts. An email claims a user’s MFA method needs to be reconfigured or re-verified. It includes a QR code branded to look like it came from Microsoft, Okta, or another identity provider. Scanning it leads to a convincing but fake login page designed to harvest credentials and session tokens.

Parking and delivery scams. Fraudulent QR codes placed on parking meters, delivery notices, or “missed package” slips redirect victims to fake payment portals. This started as a consumer-focused scam but has moved into corporate mailrooms and shared office spaces.

Fake invoice or document review requests. An email arrives looking like it’s from finance or a vendor, asking someone to scan a code to “review and approve” an invoice or contract. The QR code leads to a spoofed document portal that requests login credentials.

Physical posters and signage. Attackers print and place QR codes in shared spaces like break rooms, elevators, or building lobbies, often disguised as internal notices, wellness surveys, or IT announcements.

A Realistic Scenario

Picture a mid-sized company that just switched HR platforms. Employees are told to expect emails about updating their benefits information.

Three weeks into the rollout, an email arrives that looks like it came from the new HR system. The subject line references “Benefits Enrollment Verification Required.” The email includes the new platform’s actual logo, correct formatting, and a QR code with a caption instructing employees to scan it on their phone to confirm their enrollment before a stated deadline.

The email passes through the secure email gateway without issue. There’s no suspicious link in the body, no attachment, nothing that trips a filter. An employee, aware of the ongoing HR transition and expecting exactly this kind of communication, scans the code on their personal phone during a lunch break.

The page that loads looks like the HR platform’s login screen. It asks for a username and password, then prompts for an MFA code “to complete verification.” The employee enters both. Behind the scenes, the attacker captures the credentials and the session token in real time, giving them access to the actual HR platform, which in this case also stores direct deposit and personal tax information.

Nothing about this attack required custom malware. It required a plausible pretext, decent timing, and a QR code that no automated tool in the email chain was built to inspect.

Why Standard Defenses Fall Short

Most organizations already have layered email security: spam filters, link scanning, sandboxing for attachments, and DMARC/SPF/DKIM enforcement. These tools remain valuable, but quishing was specifically designed to move around them, not through them.

Link scanning tools generally look at URLs present as text or embedded as hyperlinks. A QR code is neither. It’s a raster image that must be decoded before there’s even a URL to evaluate. Some newer secure email gateways have started adding QR decoding as a feature, but adoption is uneven, and attackers adjust their techniques (using redirect chains, URL shorteners, or codes that only resolve after several hops) specifically to stay ahead of these detections.

Mobile device management also has limits. Even organizations with strong MDM policies on corporate phones usually have far less visibility into personal devices, and personal devices are precisely where most of these scans happen.

What Security Teams Can Practically Do

There’s no single fix for quishing, but a layered response brings the risk down significantly.

1. Update email security policies to inspect image content. Work with your email security vendor to confirm whether QR codes embedded in messages are decoded and evaluated. If the current platform doesn’t support this, it’s worth raising as a gap during the next vendor review.

2. Extend phishing awareness training to cover QR codes specifically. Most security awareness programs still focus heavily on hyperlinks and attachments. Training needs to explicitly address QR codes: what a suspicious one might look like, why scanning on a personal phone matters, and what to do instead.

3. Establish a “scan with caution” habit, not a blanket ban. Telling employees to never scan a QR code isn’t realistic and won’t stick. A more practical rule: before scanning anything from an email, check who sent it and whether the request makes sense. If it involves logging in or entering credentials, navigate to the service directly instead of through the code.

4. Run simulated quishing exercises. Just as phishing simulations train employees to spot suspicious email links, simulated QR code campaigns build the same muscle memory for this specific format. Seeing a realistic example in a safe, controlled setting is far more effective than a slide describing the concept.

5. Monitor for credential exposure after suspected incidents. If a quishing attempt is suspected or confirmed, treat it like any other credential compromise event. Force password resets, review session activity, and check whether harvested credentials have surfaced anywhere they shouldn’t have.

6. Set clear physical signage policies. For attacks using printed QR codes in offices or public spaces, establish a policy that legitimate internal communications never rely on standalone posters with QR codes and no other verification method. Encourage employees to report unfamiliar codes posted in shared spaces.

7. Review MFA methods for phishing resistance. Where possible, move toward MFA methods that are harder to phish, such as hardware security keys or platform-based authentication, rather than relying solely on codes that can be relayed through a fake login page.

A Quick Checklist for Employees

Security teams can distribute a short, practical list like this one as part of ongoing awareness efforts:

  • Before scanning, check the sender and the context. Does this message make sense given what you know?
  • Never enter login credentials or MFA codes on a page reached through a scanned QR code.
  • If a code claims to be from IT, HR, or finance, verify through a separate known channel first.
  • Prefer navigating directly to a known website over scanning a code, especially for anything involving an account login.
  • Report suspicious codes, whether in email or printed in a physical space, to the security team.

None of these steps require special technical skill. They just require the same instinct people are (hopefully) already applying to suspicious links, redirected to a newer format.

Where Cruxroot Fits Into the Picture

Quishing is a good example of why security awareness training needs to evolve alongside attacker techniques rather than stay fixed on the threats of a few years ago. Cruxroot’s phishing simulation platform includes QR code based scenarios, so employees encounter realistic quishing attempts in a controlled environment before they see one for real. The gamified training format helps the lesson stick, turning a one-time slide deck into something employees actually remember when a QR code shows up in their inbox.

Dark web monitoring adds another layer of coverage. If credentials harvested through a quishing attack, or any other method, end up circulating on dark web marketplaces or forums, Cruxroot flags the exposure so security teams can act before those credentials are used for further compromise. Combined with phishing simulations that reflect current attacker tactics and training that keeps employees engaged rather than checked out, the goal is straightforward: close the gap between what attackers are actually doing and what your organization is actually prepared for.

Final Thoughts

Quishing isn’t a dramatic new category of threat. It’s a familiar tactic, credential theft through a fake login page, wearing a format that most existing defenses weren’t built to catch. That’s exactly what makes it worth taking seriously.

The organizations that handle this well aren’t the ones with the most expensive tools. They’re the ones that keep their training current, treat awareness as an ongoing process rather than a once-a-year checkbox, and give employees practical habits they can actually use. QR codes aren’t going away, and neither is the attention attackers are paying to them. Staying a step ahead means updating the playbook before the next version of this attack shows up in someone’s inbox.