Blog
Guide 2026-07-14 7 min read

Quishing: Phishing Hidden in QR Codes

An email filter can inspect every link in a message. It cannot inspect a QR code, because it sees an image. That single gap carries the whole vector, which by 2025 appeared in roughly one in eight phishing messages.

Quishing is not cleverer than ordinary phishing. It is simply invisible to the layer meant to stop it. The filter analyses text and links, and here there is not a single link to analyse. There is an image, and a person holding a phone.

What is quishing?

Quishing, from "QR" and "phishing", is an attack where the malicious link is encoded as a QR code instead of an ordinary hyperlink. The victim scans it with a phone and lands on a fake login page, or downloads an app they did not want.

The deception looks the same as in other types of phishing. Only the wrapper around the link changes. That small change is enough to bypass a good share of the email security controls companies have spent a decade buying.

Why it works

The effectiveness comes from several gaps stacking on top of each other:

  • Anti-phishing filters analyse text and links, and a QR code is an image to them
  • The user cannot see the destination before scanning, because the code reveals nothing
  • Scanning moves the victim to a phone, usually personal and outside IT control
  • On a small screen the address bar is truncated, so a swapped domain slips past easily
  • QR codes became mundane in restaurants and car parks, so we scan them on reflex
  • Most personal phones carry no enterprise-grade protection at all

How we know it is growing

In 2025 around 12% of all phishing messages contained a QR code. Roughly 68% of those attacks targeted mobile users, which is a design choice by the attacker rather than a coincidence. APWG had earlier tracked a fourfold rise in image-based phishing, and QR codes are its simplest form.

A separate pattern concerns leadership. Back in 2023, people in executive roles were receiving many times more QR phishing than the average employee. That is the same target-selection logic we describe under spear phishing and whaling.

How the attack works

Phase 1

Creating the pretext

The attacker produces a message or a printed item with a credible reason to scan. Account verification, an invoice to settle, an HR record update.

Phase 2

Scanning the code

The victim scans with their phone. The message got through the filter because the body contained no link. It contained an image.

Phase 3

The fake page

The phone opens a page closely imitating a login portal. The address is shortened or masked, and on a phone screen you only see the start of it anyway.

Phase 4

Account takeover

Entered credentials go straight to the attacker. Better kits capture the one-time code too and hijack the session, even though 2FA was switched on.

Where malicious codes appear

Quishing does not stop at email. It is often physical, and then no IT control will ever see it:

  • PDF attachments posing as invoices or HR documents
  • Emails with a code in place of a login button
  • Stickers pasted over parking meters and charging stations
  • Swapped codes in conference materials and on posters
  • Fake registration forms and employee surveys
  • Printouts left in the office or in a meeting room

How to spot the threat

The rule is simple. A QR code is a link from an unknown sender. Everything else follows from that:

  • A QR code turns up in a matter involving login or payment
  • A sticker looks pasted over the original marking
  • After scanning, the address is shortened, unfamiliar or full of random characters
  • The page asks for credentials even though the code was meant to open a document
  • The message suggests scanning with a personal phone "for convenience"
  • The sender explains the QR code by claiming technical problems with a link

KEY TAKEAWAYS

  • 1
    QR codes bypass email filters, because to a security system they are just an image
  • 2
    The attack moves to a phone, usually personal and beyond corporate protection
  • 3
    The destination stays invisible until you scan, so the user acts blind
  • 4
    The vector is often physical, and a sticker on a parking meter works as well as an email
  • 5
    Check the address after scanning and before typing anything

How to protect your organisation

Defence means stretching security rules beyond the corporate laptop:

  • Train the team to check the full address after scanning, before entering any data
  • Deploy phishing-resistant authentication, meaning passkeys and hardware keys instead of SMS codes
  • Include QR codes in your phishing simulation programme alongside email and SMS
  • Apply the same policies to phones with access to company data as to workstations
  • Establish a rule that logging into company systems never starts with a QR code
  • Check physical codes in the office and report stickers of unknown origin
  • Monitor accounts around the clock, for example through SOC-as-a-Service, because a hijacked session shows up in behaviour rather than at login
  • Data on the other social-engineering vectors is in our Social Engineering Report 2026

Conclusion

Quishing shows how fast attackers route around a control that handles the previous vector well. Filters learned to analyse links, so the link left the message body and moved into an image. Another filter will not change much here. What changes things is the reflex of checking the address, whatever it arrived inside.

A QR code is a link you cannot see before you click it. That alone is reason enough to slow down.

Find out how many employees scan the code

We run quishing simulations alongside classic phishing and smishing, including codes placed physically around the office. The result shows a real scan rate rather than what people said in training.

See how we test

SECURE YOUR
FUTURE TODAY

Cyber threats don't sleep, and neither do we. Whether you need an immediate response to a breach or a long-term strategic security partner, ZeroLayer is ready.

Book a 30-minute call

Pick a time that works for you and talk directly to our security team.