Quishing simulation
QR code phishing simulation
for the scan nobody checks.
KeenSec quishing simulation puts a QR code in a realistic email or document, such as a parking notice, a benefits update or a form to sign, and measures who scans it and goes on to sign in.
- Attack type
- QR code phishing
- Delivered in
- Email and documents
- Measures
- Scans and submissions
- Follow-up
- Just-in-time lesson on the phone
Sample lure
A QR code hides
the link people would check.
A link in an email can be hovered over. A QR code can’t.
One decision, one lesson.
- Reported: counted as a safe action
- Clicked, scanned or replied: a short lesson on the signs they missed
- Every decision lands in that person’s record
How it works
Code, scan,
lesson, result.
- 01
Create with AI Studio
Choose the pretext and where the code will appear.
- 02
Distribute the code
Send the QR lure by email, or inside a document, to the chosen group.
- 03
Teach on the phone
A scan opens a short, lesson on how to check a QR destination.
- 04
Track scans and sign-ins
Human Risk Analytics shows who scanned, who submitted and who reported the email.
Questions buyers ask
Frequently asked questions.
What is a quishing simulation?
It is a safe test that uses a QR code instead of a link. KeenSec measures who scans and who goes on to enter details, and teaches them on their phone.
Why run QR code phishing tests?
QR codes hide the destination and move people onto a phone, where they check less. A simulation shows how your people handle that.
Where can the QR code appear?
In an email or a document sent to the chosen group. AI Studio drafts the lure, and your team decides the pretext.
Let’s connect the dots
Scan-proof habits
start with a safe scan.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo