Glossary
What is quishing?
Quishing (QR code phishing) is a phishing attack that hides a malicious link inside a QR code.
- Also known as
- QR code phishing, QR phishing
- Channel
- QR codes in emails, documents and physical spaces
- Typical goal
- Credentials or payments via a phone
- Related term
- Credential harvesting
How it works
A square of pixels
hides the link.
- 01
Place the code
The QR code appears in an email about MFA or payroll, a shared PDF, or a sticker on a real sign.
- 02
Move to the phone
Scanning shifts the action to a personal device, away from desktop security tools.
- 03
Show a familiar page
The phone opens a copied login or payment page that’s hard to inspect on a small screen.
- 04
Collect
Credentials, card details or a direct payment go to the attacker.
Simulated examples
Two codes
worth a second look.
Parking payment has moved
Card machines are out of service. Scan to pay for parking and avoid a fine.
- Sticker placed over or beside a real sign
- Threat of a fine
- Asks for card details on a web page
Questions buyers ask
Frequently asked questions.
Why is it called quishing?
It combines “QR” and “phishing”. The phishing link is encoded in a QR code instead of written as text.
Why is quishing hard to detect?
The link is an image, which some filters don’t read, and scanning moves the activity to a phone that may not have work security tools.
Is it safe to scan QR codes at all?
Many are legitimate. The risk comes from unexpected codes that ask you to sign in or pay. Preview the address and use official apps for anything sensitive.
Let’s connect the dots
See the human risk.
Change what happens next.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo