Quishing: Phishing Hidden in QR Codes
An email filter can inspect every link in a message. It cannot inspect a QR code, because it sees an image. That single gap carries the whole vector, which by 2025 appeared in roughly one in eight phishing messages.
Quishing is not cleverer than ordinary phishing. It is simply invisible to the layer meant to stop it. The filter analyses text and links, and here there is not a single link to analyse. There is an image, and a person holding a phone.
What is quishing?
Quishing, from "QR" and "phishing", is an attack where the malicious link is encoded as a QR code instead of an ordinary hyperlink. The victim scans it with a phone and lands on a fake login page, or downloads an app they did not want.
The deception looks the same as in other types of phishing. Only the wrapper around the link changes. That small change is enough to bypass a good share of the email security controls companies have spent a decade buying.
Why it works
The effectiveness comes from several gaps stacking on top of each other:
- Anti-phishing filters analyse text and links, and a QR code is an image to them
- The user cannot see the destination before scanning, because the code reveals nothing
- Scanning moves the victim to a phone, usually personal and outside IT control
- On a small screen the address bar is truncated, so a swapped domain slips past easily
- QR codes became mundane in restaurants and car parks, so we scan them on reflex
- Most personal phones carry no enterprise-grade protection at all
How we know it is growing
In 2025 around 12% of all phishing messages contained a QR code. Roughly 68% of those attacks targeted mobile users, which is a design choice by the attacker rather than a coincidence. APWG had earlier tracked a fourfold rise in image-based phishing, and QR codes are its simplest form.
A separate pattern concerns leadership. Back in 2023, people in executive roles were receiving many times more QR phishing than the average employee. That is the same target-selection logic we describe under spear phishing and whaling.
How the attack works
Creating the pretext
The attacker produces a message or a printed item with a credible reason to scan. Account verification, an invoice to settle, an HR record update.
Scanning the code
The victim scans with their phone. The message got through the filter because the body contained no link. It contained an image.
The fake page
The phone opens a page closely imitating a login portal. The address is shortened or masked, and on a phone screen you only see the start of it anyway.
Account takeover
Entered credentials go straight to the attacker. Better kits capture the one-time code too and hijack the session, even though 2FA was switched on.
Where malicious codes appear
Quishing does not stop at email. It is often physical, and then no IT control will ever see it:
- PDF attachments posing as invoices or HR documents
- Emails with a code in place of a login button
- Stickers pasted over parking meters and charging stations
- Swapped codes in conference materials and on posters
- Fake registration forms and employee surveys
- Printouts left in the office or in a meeting room
How to spot the threat
The rule is simple. A QR code is a link from an unknown sender. Everything else follows from that:
- A QR code turns up in a matter involving login or payment
- A sticker looks pasted over the original marking
- After scanning, the address is shortened, unfamiliar or full of random characters
- The page asks for credentials even though the code was meant to open a document
- The message suggests scanning with a personal phone "for convenience"
- The sender explains the QR code by claiming technical problems with a link
KEY TAKEAWAYS
- 1QR codes bypass email filters, because to a security system they are just an image
- 2The attack moves to a phone, usually personal and beyond corporate protection
- 3The destination stays invisible until you scan, so the user acts blind
- 4The vector is often physical, and a sticker on a parking meter works as well as an email
- 5Check the address after scanning and before typing anything
How to protect your organisation
Defence means stretching security rules beyond the corporate laptop:
- Train the team to check the full address after scanning, before entering any data
- Deploy phishing-resistant authentication, meaning passkeys and hardware keys instead of SMS codes
- Include QR codes in your phishing simulation programme alongside email and SMS
- Apply the same policies to phones with access to company data as to workstations
- Establish a rule that logging into company systems never starts with a QR code
- Check physical codes in the office and report stickers of unknown origin
- Monitor accounts around the clock, for example through SOC-as-a-Service, because a hijacked session shows up in behaviour rather than at login
- Data on the other social-engineering vectors is in our Social Engineering Report 2026
Conclusion
Quishing shows how fast attackers route around a control that handles the previous vector well. Filters learned to analyse links, so the link left the message body and moved into an image. Another filter will not change much here. What changes things is the reflex of checking the address, whatever it arrived inside.
A QR code is a link you cannot see before you click it. That alone is reason enough to slow down.
Find out how many employees scan the code
We run quishing simulations alongside classic phishing and smishing, including codes placed physically around the office. The result shows a real scan rate rather than what people said in training.