Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Phishing

Quishing Explained: How QR Code Phishing Scams Work

Quishing uses malicious QR codes to trick you into visiting phishing sites or downloading malware. Learn how these scams work and how to protect yourself.

By · Published · 12 min read

A hand attempts to bring a blurry image on a surface into focus, suggesting an unclear view.

Quishing, or QR code phishing, is a cyberattack that uses malicious QR codes to deceive victims into revealing sensitive information or downloading malware. Unlike traditional phishing that relies on clickable links, quishing hides the malicious destination within a QR code image, effectively bypassing many email security filters. Users scan these codes with their smartphones, bridging the gap between a secure corporate environment and a less-protected personal device, where they are led to convincing but fraudulent websites.

What Exactly Is Quishing?

Quick Response (QR) codes are a type of two-dimensional barcode that can store various kinds of data, most commonly a URL. Their convenience has made them ubiquitous; we use them to view restaurant menus, make payments, connect to Wi-Fi, and access information on public displays. This widespread, legitimate use has created a level of trust and familiarity that attackers are now exploiting.

Quishing is simply the weaponization of these trusted black-and-white squares. The core objective is identical to any other form of phishing: to steal credentials, financial information, or personal data, or to deploy malware on a victim's device. The QR code is merely the delivery mechanism for the malicious payload, which is almost always a link to a website controlled by the attacker.

Attackers favor this method because it cleverly shifts the point of attack. Instead of a suspicious link that a user can hover over to inspect, they are presented with an opaque image. The decision to trust and scan the code falls entirely on human judgment, often performed in a hurry on a mobile device where URLs are harder to scrutinize.

How a Typical Quishing Attack Unfolds

While the specifics can vary, most quishing attacks follow a predictable, multi-stage process designed to move a victim from a state of curiosity to compromise.

1. Creating the Bait A threat actor generates a QR code that points to a malicious destination. This could be: - A phishing page designed to mimic a legitimate login portal (e.g., Microsoft 365, Google, a banking site). - A website that immediately initiates a malware download. - A payment form that sends money directly to the scammer. - A script that executes a crypto wallet drainer.

2. Setting the Lure The attacker distributes the malicious QR code. There are two primary vectors for this: digital and physical.

Digital Lures often arrive as emails. An attacker might send a message pretending to be from IT, HR, or a trusted service provider. The email will contain a QR code and an urgent call to action, such as "Your session has expired, scan to re-authenticate now" or "Action required to keep your account active." The QR code image is the key, as it's less likely to be flagged by email security scanners than a plain text URL.

Physical Lures involve placing malicious QR code stickers in public spaces. Scammers have been known to paste them over the legitimate codes on parking meters, bike rental stations, and restaurant tables. An unsuspecting person trying to pay for parking scans the fraudulent code and is taken to the scammer's payment page instead of the official city vendor's.

3. The Scan and Deception The victim scans the code with their smartphone. Most mobile operating systems will show a notification with a snippet of the URL, but attackers use clever tricks to make this appear legitimate. For example, a domain like `microsoft.com.security-update.xyz` might be truncated to just show `microsoft.com` in the preview pop-up. Trusting the context—the email from "IT" or the sticker on the parking meter—the user taps the notification.

4. The Trap Is Sprung The user's browser opens the malicious website. If the goal is credential theft, this page will be a pixel-perfect replica of a known login screen. Distracted or rushed, the user enters their username and password. The moment they hit "Log In," their credentials are sent directly to the attacker. In other scenarios, the site might host a drive-by download, installing spyware or other malware onto the phone without any further user interaction.

Why Is Quishing So Effective?

The rise of quishing isn't just a trend; it's a calculated tactic that exploits specific weaknesses in both technology and human psychology.

Bypassing Technical Defenses: Many traditional Secure Email Gateways (SEGs) are excellent at parsing text, analyzing URLs, and checking them against reputation databases. However, they are not always equipped with the Optical Character Recognition (OCR) or computer vision capabilities needed to "read" a QR code embedded within an image. This allows a malicious link to sail past security filters and land directly in an employee's inbox.

The Human Factor: After years of being encouraged to scan QR codes for everything from menus to medical forms, people have developed a habit of scanning first and thinking later. This conditioning has lowered our collective guard. We are more likely to be suspicious of a hyperlink in a strange message than a QR code, which feels more modern and official. For a refresher on classic signs of danger, it's worth reviewing how to spot a phishing email or text.

The Air-Gap Problem: Quishing masterfully exploits the divide between corporate and personal devices. An employee receives a quishing email on their company laptop, which is protected by corporate security software. They then pull out their personal smartphone—which may have minimal protection and no oversight from their employer's IT department—to scan the code. This action effectively bypasses the corporate security perimeter, opening a blind spot for security teams.

Common Quishing Scams to Watch For

Attackers are constantly innovating, but several quishing campaigns have become disturbingly common. Recognizing these patterns is a key part of your defense.

Corporate Credential Theft This is arguably the most prevalent form of quishing. The lure is an email claiming to be from IT or a major software vendor like Microsoft or Google. It often mentions a password reset, an MFA update, or a security alert that requires immediate action. The QR code leads to a fake login page. Once the employee's credentials are stolen, attackers can access corporate data, emails, and internal systems. In some cases, this initial access is used to deploy further attacks, such as installing [remote admin tools for persistent access](/posts/phishing-rmm-tools-msp360-screenconnect).

Public Payment and Parking Scams As mentioned earlier, scammers are active in the physical world. They target locations where people expect to make a payment via QR code. Victims who scan the fraudulent code are directed to a phishing site where their credit card information is stolen. These attacks are effective because they prey on people in a hurry who are performing a routine task.

Cryptocurrency Wallet Drainers In the crypto space, QR codes are commonly used to share wallet addresses. Scammers abuse this by using QR codes in social media posts or Discord chats to promote fake airdrops, NFT mints, or access to decentralized finance (DeFi) platforms. When a user scans the code and connects their crypto wallet to the malicious site, they are prompted to sign a transaction. This transaction doesn't send them a new token; instead, it grants the scammer's smart contract permission to drain all assets from their wallet. Knowing [how to revoke token approvals on your crypto wallet](/posts/revoke-token-approvals-crypto-wallet) is a critical skill for anyone active in this space.

Malicious Wi-Fi and Configuration Profiles Flyers in airports, hotels, or cafes might offer free Wi-Fi access via a QR code. Scanning it could do one of two things: either connect you to a malicious hotspot controlled by an attacker (enabling a man-in-the-middle attack) or prompt you to install a "configuration profile" on your device. This profile could redirect your internet traffic through the attacker's servers, allowing them to intercept sensitive data.

How to Protect Yourself from Quishing Attacks

Defense against quishing requires a combination of technological awareness and healthy skepticism. Whether you're an individual or part of a large organization, these practices can significantly reduce your risk.

  • Question the Context: Always be suspicious of QR codes in unexpected emails. Ask yourself: would my IT department really ask me to do this? Is it normal for my bank to send a QR code for login? When in doubt, ignore the code and navigate to the official website manually.
  • Inspect Physical QR Codes: Before you scan a code in public, check for signs of tampering. Is it a sticker placed over another code? Does it look professionally printed or is it a cheap label? If anything seems off, don't scan it.
  • Preview URLs Before Opening: Most modern smartphones show you the destination URL before you open the link. Take a moment to read it carefully. Look for typos, strange domains, or long, garbled addresses. If it's a shortened URL (like bit.ly), be extra cautious as the final destination is hidden.
  • Avoid Entering Credentials After a Scan: As a rule of thumb, never enter a password, financial data, or other sensitive information on a website you arrived at via a QR code. If a service legitimately requires you to log in, close the browser and open the official app or type the website address in yourself.
  • Use Multi-Factor Authentication (MFA): While some quishing attacks are designed to steal MFA codes, a strong, non-phishable form of MFA (like a hardware security key) can still protect you even if your password is stolen.
  • Corporate Training: For businesses, the number one defense is education. Run regular security awareness training and phishing simulations that specifically include quishing tactics to teach employees how to recognize and report these threats.

What to Do If You've Scanned a Malicious Code

If you suspect you've scanned a malicious QR code and fallen for a scam, it's crucial to act quickly to minimize the damage.

  1. Disconnect Your Device: Immediately turn off your device's Wi-Fi and cellular data to stop any potential communication between malware and the attacker's server.
  2. Change Compromised Passwords: If you entered login credentials, go to the legitimate service *from a different, trusted device* and change your password immediately. If you reuse that password elsewhere, change it there too.
  3. Scan for Malware: Run a full scan using a reputable mobile antivirus application to detect and remove any malicious software that may have been installed.
  4. Report the Incident: If this happened on a work device or involved a work account, notify your IT or security department right away. They need to know about the potential breach to protect the wider organization. As an individual, you can report phishing sites to Google Safe Browsing and the Anti-Phishing Working Group (APWG).
  5. Monitor Your Accounts: Keep a close eye on your bank statements, email accounts, and other online profiles for any unauthorized activity. Understanding what to do after your data is exposed in a breach provides a comprehensive guide for monitoring and securing your identity. By taking these immediate steps, you can contain the threat and begin the process of recovery.

Read next