QR Generator

June 1, 2026

QR Code Phishing: How "Quishing" Works and How to Avoid It

PhishingQuishingScamsCredential Theft

QR code phishing, or "quishing," is an emerging cybersecurity threat. Attackers embed malicious links in QR codes to steal login credentials, personal information, and payment data.

This guide explains how quishing works and how to defend against it.

What Is Quishing?

Quishing is a phishing attack that uses QR codes instead of traditional email links or attachments. The QR code leads to a fraudulent website designed to steal information.

Why Attackers Use QR Codes

ReasonExplanation
URL hiddenCannot see the destination before scanning
Trust factorQR codes appear legitimate
Bypasses email filtersImages in emails bypass text-based filters
Mobile targetingPhone screens show less URL detail

How Quishing Attacks Work

Attack Pattern

  1. Create: Attacker creates a fake website that looks legitimate
  2. Code: Attacker generates a QR code linking to the fake site
  3. Distribute: QR code is placed on posters, stickers, or in emails
  4. Trap: Victim scans the code and is directed to the fake site
  5. Harvest: Victim enters credentials, which are captured

Common Lures

LureExample
Account alert"Your account has been locked. Scan to verify."
Payment needed"Scan to pay your outstanding balance."
Exclusive offer"Scan for a special discount."
Package delivery"Scan to track your package."
Event access"Scan for event entry."

Real-World Quishing Examples

Parking Payment Scams

Attackers place QR code stickers on parking meters, linking to fake payment pages.

Email-Based Quishing

Emails containing QR code images with urgent messages:

Subject: Your Microsoft 365 password expires today

Scan the QR code below to verify your account and keep your email active.

[QR CODE IMAGE]

Microsoft Security Team

Fake 2FA Setup

Attackers send QR codes that appear to be for two-factor authentication setup but actually link to credential harvesting sites.

How to Detect Quishing

Visual Inspection

Red FlagWhat to Check
Unexpected QR codeDid you expect to see a QR code here?
Urgency in messageIs the message pressuring you to act quickly?
Generic greeting"Dear user" instead of your name
Poor designTypos, low-quality logos, odd formatting
Sticker overlayQR code on a sticker, not printed directly

Technical Inspection

ToolHow It Helps
URL previewPhone camera shows the URL before opening
QR scanner with previewApps that show the decoded URL
Link checkerPaste the URL into a link-checking service

Protecting Your Organization

Employee Training

Training TopicKey Message
QR code awarenessQR codes can lead anywhere
URL previewingAlways check the URL before opening
ReportingReport suspicious QR codes to IT
VerificationVerify QR codes with the source

Technical Controls

ControlImplementation
URL filteringBlock known malicious domains
Mobile device managementEnforce security policies on work phones
QR scanner policyApprove specific QR scanning apps
Multi-factor authenticationEven if credentials are stolen, MFA blocks access

Case Study: Office Building Quishing

Attackers placed fake QR code posters in an office building lobby claiming to offer "free coffee" to employees who scanned.

The attack: QR code led to a fake Microsoft 365 login page.

The result: 30+ employees entered their credentials before IT was alerted.

The fix: IT reset all affected passwords and implemented mandatory QR code security training.

What to Do If You Fall Victim

  1. Change passwords immediately on the affected account
  2. Enable MFA if not already enabled
  3. Contact IT/security team in your organization
  4. Monitor accounts for suspicious activity
  5. Report the attack to law enforcement

Creating Secure QR Codes for Your Business

Create secure QR codes — use dynamic QR codes with tracking to monitor for unusual activity.

Conclusion

Quishing is a growing threat, but awareness is the best defense. Always preview URLs before opening, verify QR code sources, and never enter credentials on a site you reached via an unsolicited QR code.

Create verified QR codes — generate QR codes with secure practices and monitoring for your business.


Was this article helpful?

Try Our QR Code Generator