QR Code Phishing (Quishing)
Learn how quishing (QR code phishing) works, how malicious QR codes redirect users to fake login pages or trigger malware downloads, and how to protect yourself. Includes real-life examples, warning signs, and expert safeguarding tips.
Overview
What is quishing?
Quishing — a combination of "QR code" and "phishing" — is a form of cyber fraud in which a malicious QR code is used to redirect a victim to a fake login page, a malware download, or a fraudulent payment portal. To the naked eye, a malicious QR code is indistinguishable from a legitimate one: it is simply a pattern of black and white squares that a smartphone camera can read. The destination encoded within it, however, is chosen entirely by the attacker.
QR codes surged into everyday life during the COVID-19 pandemic — replacing physical menus, ticketing systems, and payment terminals — and that cultural normalisation is precisely what quishing exploits. We have been conditioned to scan QR codes without hesitation, in the same way that a decade ago we were conditioned to click links in emails. Attackers have simply redirected one of phishing's oldest techniques through a newer channel that most people have not yet learned to scrutinise.
Quishing is deployed across a wide range of environments: embedded in emails to bypass link-scanning security filters, printed on stickers placed over legitimate QR codes in restaurants, parking meters, and public transport, sent in physical postal mail, displayed in fraudulent advertisements, and even presented in video calls or presentations. In every case, the scan takes the victim somewhere the attacker controls.
Who is targeted: Anyone who uses a smartphone to scan QR codes in daily life — which, in many countries, now represents the majority of adults. Corporate employees receiving documents or emails with embedded QR codes are a growing specific target, particularly those in finance, HR, and IT roles.
Why it works: QR codes are opaque by design — you cannot read the destination URL the way you can hover over a hyperlink. The scan-to-destination step is instant and automatic, with no moment of visible inspection between action and consequence. This removes one of the most reliable defences people use against standard phishing: looking before you click.
Scale & Statistics
How common is this scam?
Quishing has grown from a niche technique into one of the fastest-rising phishing vectors, with several major security firms reporting it as one of the defining threat trends of 2023 and 2024.
- 587% increase in quishing attacks was recorded between August and September 2023 alone, according to Perception Point's threat intelligence data
- 1 in 5 phishing emails detected by Harmony Email & Collaboration in Q3 2023 contained a malicious QR code embedded in the message body or an attached document
- 22% of all QR code scams in 2024 impersonated Microsoft, making it the single most imitated brand in quishing campaigns globally, according to Abnormal Security
- $580,000 was lost by a single victim in a 2024 cryptocurrency quishing scam reported to the FBI — among dozens of documented high-value individual losses that year
- Parking meter fraud using fake QR code stickers was reported in over 30 US cities in 2023, with the FBI issuing a public warning specifically about physical quishing in public spaces
- 76% of security professionals in a 2024 SANS Institute survey reported that their organisation had encountered a quishing attempt in the previous 12 months
- Mobile devices — the primary tools for scanning QR codes — typically have weaker security controls than enterprise laptops and desktops, and do not route through corporate email filtering, significantly increasing exposure
Most affected sectors: financial services, healthcare, higher education, retail, and any organisation that regularly shares documents, invoices, or multi-factor authentication prompts via email.
Sources: Perception Point Threat Intelligence Report 2023; Abnormal Security Email Threat Report 2024; FBI Public Service Announcement on QR Code Fraud, January 2024; SANS Institute Security Awareness Report 2024; Hoxhunt Phishing Trends Report 2024
How It Works
How does it work?
Quishing attacks share the same underlying structure as email phishing — a deceptive lure, a malicious destination, and a credential or payment harvesting mechanism — but replace the clickable hyperlink with a scannable QR code, which allows them to bypass an entire category of technical defences.
-
A malicious destination is prepared — The attacker builds a convincing fake website: a credential-harvesting login page impersonating Microsoft 365, a bank, a parcel delivery service, or a corporate VPN portal. Alternatively, the destination triggers a direct malware or application download when the QR code is scanned.
-
The malicious URL is encoded into a QR code — A QR code encoding the attacker's URL is generated using any freely available QR code tool. The resulting image is visually identical to a legitimate QR code and contains no detectable markers of malicious intent.
-
The QR code is embedded in a lure — The code is placed into a phishing email, a printed sticker, a fraudulent document, a PDF attachment, a physical letter, or a digital advertisement. In corporate attacks, it is frequently embedded in a document that appears to require the recipient to scan the code to verify their identity, complete a multi-factor authentication step, or access a shared file.
-
The victim scans the code — Using their smartphone camera or a QR code reader app, the victim scans the code in the belief that it leads to a legitimate destination. Because the URL is encoded within the image — not visible as text — there is no opportunity to inspect it before the scan initiates navigation.
-
The victim is taken to the malicious destination — The smartphone browser opens the attacker's page. If it is a credential-harvesting site, the victim is presented with a convincing login form and enters their username, password, and potentially a one-time passcode. If the destination delivers malware, a download is triggered — often disguised as an app or document update.
-
Credentials are captured or the device is compromised — Login details entered on the fake page are harvested in real time. In MFA bypass variants, the attacker uses the captured one-time passcode immediately — within the seconds it remains valid — to access the victim's real account before the code expires.
Platforms and tools commonly used: Free QR code generators, phishing-as-a-service kits with built-in QR code functionality, printed sticker overlays for physical deployment, email delivery platforms, and adversary-in-the-middle (AiTM) proxies for real-time MFA interception.
Recent variations in 2024–2025:
- AiTM quishing — the fake page acts as a transparent proxy, forwarding the victim's credentials and MFA tokens to the real site in real time, allowing the attacker to hijack an authenticated session even when MFA is enabled
- Physical quishing in public spaces — stickers printed with malicious QR codes are placed over legitimate codes on parking meters, restaurant tables, EV charging stations, and public noticeboards; the physical context makes the code appear entirely trustworthy
- Email security bypass — because QR codes are images, not hyperlinks, they are not scanned by URL-filtering tools in most corporate email gateways; attackers embed QR codes in PDFs or image attachments specifically to exploit this gap
- Conditional quishing — the malicious URL delivers different content depending on the device, location, or time of the scan; victims on mobile devices are shown the fake login page while security researchers scanning from desktop environments are redirected to a benign site, evading detection
Psychological Tactics
What psychological tactics are used?
Quishing succeeds by combining the psychological mechanisms of standard phishing with the unique opacity of QR codes — a medium that offers no visible information about its destination before the user has already committed to the action.
| Tactic | How it is used |
|---|---|
| Conditioned trust in QR codes | Years of legitimate QR code use — menus, tickets, payments, NHS check-ins — have normalised the act of scanning without verification. Quishing inherits that conditioned compliance. |
| Opacity and irreversibility | Unlike a hyperlink, a QR code reveals no destination before it is scanned. By the time the victim sees the URL, they have already navigated to it. The moment of visible inspection that protects against link-based phishing is removed entirely. |
| Urgency | "Scan to verify your identity before your account is suspended." "Scan now to complete your delivery." Familiar urgency framing accelerates scanning without reflection. |
| Authority and impersonation | QR codes presented in the context of a corporate IT communication, an official government letter, or a bank notification carry the implied authority of those institutions. The code itself adds a veneer of technical sophistication that makes the lure feel more official. |
| Physical legitimacy | A QR code printed on a sticker and applied to a physical object — a parking meter, a restaurant table — benefits from the assumption that physical placement implies official authorisation. Most people do not consider that a sticker could be fraudulent. |
| MFA complacency | Users who have been trained to complete MFA steps by scanning a QR code — a common legitimate workflow — are primed to scan without scrutiny when an attacker presents a fraudulent MFA prompt using the same format. |
The defining vulnerability quishing exploits is the assumption of safety by format. We have learned to be suspicious of email links — but we have not yet learned to be suspicious of QR codes. That lag between the adoption of a new technology and the public's security awareness of its risks is the window quishing attacks through.
Real-Life Example
A real-life case
Case: Major US energy company targeted in large-scale quishing campaign; over 1,000 employees receive malicious QR code emails impersonating Microsoft (2023)
In May 2023, Abnormal Security identified and reported a significant quishing campaign targeting a large US-based energy company. Attackers sent over 1,000 emails to employees across the organisation, each containing a malicious QR code embedded in the message body. The emails were designed to impersonate Microsoft security notifications, informing recipients that their account required re-verification and asking them to scan the QR code to complete a multi-factor authentication update.
The QR codes directed victims to a convincing fake Microsoft 365 login page, built to harvest both credentials and MFA tokens in real time using an adversary-in-the-middle proxy. Because the emails contained no hyperlinks — only an embedded image — they bypassed the organisation's email URL-scanning security gateway entirely, reaching employee inboxes undetected.
The energy company was the largest single target in the campaign, but Abnormal Security reported that the same infrastructure was simultaneously used against organisations in insurance, financial services, manufacturing, and technology sectors. Approximately 29% of the malicious emails in the campaign were delivered to victims via mobile devices — the primary channel for QR code scanning — where corporate security controls are typically less stringent.
The outcome: The campaign was identified and reported before the full scope of credential compromise could be assessed. The case was widely cited by security researchers as a watershed moment for quishing — demonstrating that QR code attacks had moved from isolated incidents to coordinated, large-scale campaigns capable of defeating enterprise email security infrastructure. Microsoft, CISA, and the FBI all issued updated guidance on QR code fraud in the months following its disclosure.
Source: Abnormal Security Threat Intelligence Blog, "Large-Scale Quishing Attack Targets Energy Company," August 2023 — abnormalsecurity.com; FBI Public Service Announcement on Malicious QR Codes, January 2024 — ic3.gov
Red Flags to Watch
Red flags to watch for
- An email, document, or message asks you to scan a QR code to verify your identity, complete a security update, or access a file — particularly if the request is unexpected or creates a sense of urgency
- The QR code is embedded in a PDF attachment or image file within an email rather than appearing as a hyperlink — a deliberate technique to bypass email security scanning tools
- A physical QR code sticker appears to have been applied over an existing printed code, or the sticker looks newer, shinier, or slightly misaligned compared to the surrounding material
- After scanning, your browser navigates to a URL that does not match the domain of the organisation you expected — check the address bar carefully before entering any information
- The page you land on after scanning asks for login credentials, a one-time passcode, payment card details, or personal information — particularly if the visual design looks slightly off compared to the real site
- The QR code arrives in a physical letter claiming to be from a government agency, bank, or utility provider, asking you to scan it to make a payment or verify your account
- A QR code is presented in a public space — parking meter, EV charging point, restaurant table — where you cannot confirm it is part of the official installation and not a sticker overlay
- The QR code initiates an unexpected app download or asks for device permissions after scanning
How to Identify
How to identify a quishing attempt
Ask yourself before scanning:
- Did I request or expect this QR code, or has it appeared without context in an email, document, or physical location?
- Can I verify this request through a separate channel — by navigating to the organisation's website directly or calling their official number — without using the QR code?
- After scanning, does the URL in my browser's address bar exactly match the real, verified domain of the organisation the code claims to represent?
Verification steps:
- Preview the URL before proceeding — most smartphone cameras and QR reader apps display the destination URL before navigating; always read it carefully and compare it against the real organisation's domain
- If the URL uses a link shortener (bit.ly, tinyurl, or similar), expand it first using a service such as CheckShortURL before visiting the destination
- Paste the destination URL into VirusTotal or Google Safe Browsing to check whether it has been flagged as malicious
- If you scanned a physical QR code in a public space, physically inspect the code before acting on the destination — look for sticker overlays, misalignment, or differences in print quality compared to surrounding official materials
- Never enter login credentials, MFA codes, or payment details on a page reached via a QR code unless you have independently verified the destination URL is genuine
- For workplace QR codes in emails or documents, confirm the request directly with the apparent sender via phone or a separately composed email before scanning
Legitimate vs fraudulent — how to tell:
| Legitimate QR code | Quishing QR code |
|---|---|
| Destination URL clearly matches the known, verified domain of the organisation | URL uses a lookalike domain, a link shortener, or an unrelated domain |
| The request to scan is expected and consistent with a process you initiated | Arrives unexpectedly, often with urgency or a security-related justification |
| Physical codes are part of the official installation — no sticker overlay or misalignment | Physical sticker appears applied over an existing code or looks inconsistent with surrounding materials |
| No request for credentials, MFA tokens, or payment details immediately after scanning | Immediately presents a login page, payment form, or MFA prompt |
| Consistent with the real organisation's known communication style and channels | May appear in an unusual format — a PDF attachment, a physical letter, or an unsolicited email |
How to Protect
How to protect yourself
Preventive habits:
- Treat QR codes with the same level of scrutiny you apply to links in emails — always preview the destination URL before navigating and verify it matches the real organisation's domain
- Use a QR code reader app that displays the full destination URL before opening it, giving you a moment of inspection before committing to the navigation
- Never enter credentials or payment information on a page you reached via a QR code without first confirming the URL independently — navigate directly to the site in a separate browser tab to compare
- For corporate environments, configure email security gateways to scan images and PDF attachments for embedded QR codes — several enterprise security platforms now offer this capability specifically in response to the rise of quishing
- Apply FIDO2-compliant hardware security keys or passkeys for employee authentication where possible — these are tied to the legitimate domain and cannot be intercepted by an adversary-in-the-middle proxy, rendering AiTM quishing ineffective
- In public spaces, physically inspect QR codes before scanning — particularly on parking meters, charging stations, and restaurant tables — and report any codes that appear to have been tampered with
If you have already been targeted:
- If you entered credentials on a page reached via a QR code, change your password immediately from a separate, trusted device
- Revoke any active sessions on the affected account — most platforms offer a "sign out of all devices" option in account security settings
- Contact your bank immediately if you entered any payment card or banking details
- Report the incident to your IT or security team — particularly if the QR code arrived via a work email or document, as the campaign may be targeting others in your organisation
- Report the malicious QR code to your national cybercrime authority and, where possible, to the platform or organisation being impersonated so they can alert other users
- If the QR code was on a physical object in a public space, report it to the venue, local authority, or organisation responsible for that location so the fraudulent code can be removed
Useful tools:
| Tool | What it does | Cost |
|---|---|---|
| VirusTotal | Scans destination URLs extracted from QR codes for known malware and phishing indicators | Free |
| Google Safe Browsing | Checks whether a URL is flagged as a dangerous or deceptive site | Free |
| CheckShortURL | Expands shortened URLs to reveal the true destination before visiting | Free |
| Kaspersky QR Scanner | QR reader app that automatically checks destination URLs for phishing and malware indicators before navigating | Free |
Video Lesson
Watch: Quishing explained
A clear, accessible explanation of how quishing attacks work, why QR codes are an effective vehicle for bypassing email security controls, how malicious codes are deployed in both digital and physical environments, and the practical steps individuals and organisations can take to identify and avoid QR code phishing. Suitable for viewers with no prior cybersecurity knowledge.
Further Reading
Further reading
Official resources
- FBI Internet Crime Complaint Center (IC3) — Public service announcement on malicious QR codes, including guidance for individuals and businesses → ic3.gov
- CISA (Cybersecurity & Infrastructure Security Agency) — Guidance on QR code fraud and the broader phishing threat landscape → cisa.gov/phishing
- NCSC (National Cyber Security Centre, UK) — Advice on spotting and avoiding QR code scams in personal and professional contexts → ncsc.gov.uk
- FTC (US Federal Trade Commission) — Consumer guidance on QR code scams including parking meter fraud and email-based quishing → consumer.ftc.gov
Research & reports
- Abnormal Security — "Email Threat Report 2024" — includes detailed analysis of large-scale quishing campaigns, AiTM proxy techniques, and the energy sector attack case study → abnormalsecurity.com/resources
- Perception Point — "Annual Cyber Security Trends Report 2024" — documents the 587% surge in quishing and its emergence as a primary enterprise email threat → perception-point.io/resources
- Hoxhunt — "Phishing Trends Report 2024" — covers QR code phishing alongside evolving user susceptibility data across global organisations → hoxhunt.com/resources
Investigative coverage
- Bleeping Computer — Ongoing reporting on quishing campaigns, physical QR code sticker fraud, and enterprise-targeted attacks → bleepingcomputer.com
- KrebsOnSecurity — Analysis of adversary-in-the-middle quishing infrastructure and the technical mechanics of real-time MFA bypass → krebsonsecurity.com
Related articles on this platform
- Phishing Email — fraudulent emails impersonating trusted organisations to steal credentials
- Clone Phishing — legitimate emails duplicated with malicious links or attachments replacing the originals
- Smishing (SMS Phishing) — fraudulent text messages with malicious links, often claiming package delivery issues
- Whaling Attack — phishing specifically targeting CEOs and senior executives for large financial transfers