QR-Code Phishing (Quishing)
Also known as: Quishing, QR phishing, QR code scam, Malicious QR code
A phishing variant that hides the malicious link inside a QR code, so the target's phone opens the lure and the email or print gateway never sees a URL to inspect.
Watch it in 60 seconds
How it works
Quishing is phishing in which the link is encoded as a QR code. The code arrives in an email, a PDF, a printed notice or a sticker placed over a legitimate one. Scanning it makes the phone open the encoded address, which leads to a fake sign-in page or a payment form.
The code works as a filter bypass. Mail gateways and link scanners look for URL text, and an image of a QR code has none. The scan also moves the victim from a managed laptop to a personal phone, which usually has weaker protection and no corporate logging.
The lure is the usual one: an expiring password, a shared document, a parking or delivery fee, a benefits enrolment. The code replaces the visible link, so the user cannot hover to preview the destination and has to trust the surrounding message.
Defence combines technical and human controls. Analysts decode a reported code in an isolated tool, judge the domain, and block it. Organisations add QR-aware email scanning, phishing-resistant MFA, and a habit of previewing a code's address before opening it.
Walk through it
- 1A reported QR code
- 2Decode without opening
- 3Judge the destination
- Scope who scanned it
- Contain and harden
An employee forwarded an email that contains only a QR code and a short message about an expiring benefits login. No link is visible, which is exactly why the gateway let it through. Read the context first, then decode the code safely.
Action required: re-enrol in benefits before Friday
From: HR Benefits <benefits@contoso-freight-hr.example>
To: d.driver@contoso-freight.example
Your benefits enrolment expires soon. Scan the code below with your phone to sign in.
[ QR code image attached, no text link ]
Spot it
- Inbound email whose body is mostly or only an image, with a QR code and little or no link text.
- Decoded address is a lookalike, a newly registered domain, or a URL-shortener or open redirector.
- Urgency around an account, document or fee paired with an instruction to scan with a phone.
- Mobile sign-in attempts or proxy hits to a newly seen domain shortly after the message was delivered.
- Physical sticker or poster placed over a legitimate QR code in a public or shared space.
Mail gateway
ts=2026-10-11T08:02:11Z from=benefits@contoso-freight-hr.example to=d.driver@contoso-freight.example spf=pass dkim=none dmarc=fail attachments=1 type=image/png urls=0 action=delivered
ts=2026-10-11T08:40:57Z event=user_report mailbox=phishing@contoso-freight.example message_id=7731Web proxy / mobile gateway
ts=2026-10-11T08:19:44Z user=d.driver device=mobile host=contoso-benefits-signin.example category=newly-registered action=allowedkqlMicrosoft 365 — image-only emails with no URLs and DMARC failure
EmailEvents
| where DeliveryAction == "Delivered"
| where DMARC == "fail"
| join kind=inner (EmailAttachmentInfo | where FileType in ("png","jpg","jpeg")) on NetworkMessageId
| join kind=leftanti (EmailUrlInfo) on NetworkMessageId
| project Timestamp, SenderFromAddress, RecipientEmailAddress, SubjectImage attachment with no extractable URL is the shape of a QR lure. Expect some benign newsletters; tune by sender reputation.
sigmaSigma — proxy hit to a domain decoded from a reported QR code
detection:
selection:
cs-host|endswith: 'contoso-benefits-signin.example'
condition: selection
level: highStop it
Use phishing-resistant MFA
FIDO2 or passkeys bind the sign-in to the genuine origin, so credentials typed into a lookalike page opened from a QR code cannot be replayed. This holds even when the user scans and is fooled.
Close the visibility gap on mobile
Add QR-aware scanning that decodes image codes at delivery, and extend web filtering and conditional access to phones that reach corporate apps. A code that opens on an unmanaged device should still fail to sign in to company services.
Teach the preview habit
Train users to read the address their phone shows before opening it, to distrust codes in unsolicited mail, and to report instead of scan. Treat stickers over printed codes as a physical-security matter as well.
Conditional access intent for sign-ins from unmanaged devices
Hardened
IF app = corporate-apps AND device = unmanaged
THEN require phishing-resistant MFA AND block token persistence
ELSE allow with standard policyExpressed as policy intent; translate to your identity provider's conditional access syntax.
- Decode image-based QR codes in the email gateway and apply URL reputation checks to the result.
- Flag emails whose only content is an image with a QR code, especially from first-contact senders.
- Enforce DMARC at reject on your own domains so lookalikes are the only option left to attackers.
- Apply web filtering or DNS protection on managed mobile devices and block newly registered domains.
- Give users a one-tap report option and a sanctioned decoder for codes they cannot trust.
If it already happened
Quarantine the message from every mailbox, block the decoded domain at DNS, proxy and gateway, and pull any printed or posted code that is part of the campaign.
Identify users who scanned or signed in, including from personal phones. Reset their credentials, revoke sessions and tokens, and review sign-ins and mailbox rules for abuse.
Verify accounts are clean, re-enrol MFA where needed, and request takedown of the lookalike domain from the registrar and host.
Add the decoded domain and lure pattern to detections, and use the real example in training. Track report rate for QR-based lures.
Check yourself
1. Why do QR-code phishing emails often get past URL-scanning email gateways?
2. A user reports an email containing only a QR code. What is the safest way for the analyst to examine it?
3. Which control most reliably stops a credential captured through a quishing page from being used against your sign-in?