Quishing simulation

QR code phishing simulation
for the scan nobody checks.

KeenSec quishing simulation puts a QR code in a realistic email or document, such as a parking notice, a benefits update or a form to sign, and measures who scans it and goes on to sign in.

Attack type
QR code phishing
Delivered in
Email and documents
Measures
Scans and submissions
Follow-up
Just-in-time lesson on the phone

Sample lure

A QR code hides
the link people would check.

A link in an email can be hovered over. A QR code can’t.

WHAT HAPPENS NEXT

One decision, one lesson.

  • Reported: counted as a safe action
  • Clicked, scanned or replied: a short lesson on the signs they missed
  • Every decision lands in that person’s record

How it works

Code, scan,
lesson, result.

  1. 01

    Create with AI Studio

    Choose the pretext and where the code will appear.

  2. 02

    Distribute the code

    Send the QR lure by email, or inside a document, to the chosen group.

  3. 03

    Teach on the phone

    A scan opens a short, lesson on how to check a QR destination.

  4. 04

    Track scans and sign-ins

    Human Risk Analytics shows who scanned, who submitted and who reported the email.

Questions buyers ask

Frequently asked questions.

What is a quishing simulation?

It is a safe test that uses a QR code instead of a link. KeenSec measures who scans and who goes on to enter details, and teaches them on their phone.

Why run QR code phishing tests?

QR codes hide the destination and move people onto a phone, where they check less. A simulation shows how your people handle that.

Where can the QR code appear?

In an email or a document sent to the chosen group. AI Studio drafts the lure, and your team decides the pretext.

Let’s connect the dots

Scan-proof habits
start with a safe scan.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo