Glossary

What is quishing?

Quishing (QR code phishing) is a phishing attack that hides a malicious link inside a QR code.

Also known as
QR code phishing, QR phishing
Channel
QR codes in emails, documents and physical spaces
Typical goal
Credentials or payments via a phone
Related term
Credential harvesting

How it works

A square of pixels
hides the link.

  1. 01

    Place the code

    The QR code appears in an email about MFA or payroll, a shared PDF, or a sticker on a real sign.

  2. 02

    Move to the phone

    Scanning shifts the action to a personal device, away from desktop security tools.

  3. 03

    Show a familiar page

    The phone opens a copied login or payment page that’s hard to inspect on a small screen.

  4. 04

    Collect

    Credentials, card details or a direct payment go to the attacker.

Simulated examples

Two codes
worth a second look.

Simulated example
Printed notice

Parking payment has moved

Card machines are out of service. Scan to pay for parking and avoid a fine.

  • Sticker placed over or beside a real sign
  • Threat of a fine
  • Asks for card details on a web page

Questions buyers ask

Frequently asked questions.

Why is it called quishing?

It combines “QR” and “phishing”. The phishing link is encoded in a QR code instead of written as text.

Why is quishing hard to detect?

The link is an image, which some filters don’t read, and scanning moves the activity to a phone that may not have work security tools.

Is it safe to scan QR codes at all?

Many are legitimate. The risk comes from unexpected codes that ask you to sign in or pay. Preview the address and use official apps for anything sensitive.

Let’s connect the dots

See the human risk.
Change what happens next.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo