“Quishing” – phishing via QR codes – has quickly become a favorite tool for cybercriminals. Here is what businesses need to know to close this security gap.

Familiarity often breeds negligence. In cybersecurity, it breeds something even worse: complacency. That is exactly the situation with QR codes. Once a novelty found only on product packaging, they are now on restaurant menus, parking meters, street lamps, and increasingly inside corporate emails. The danger is that QR codes are a perfect way to hide malicious links. They bypass traditional email security filters and shift the user’s activity from a protected corporate computer to a personal smartphone – a device with far fewer safeguards.
Attackers are constantly innovating. Their quishing techniques evolve, each one designed to trick unsuspecting employees. Here is what you need to know to protect your organization.
Why Is Quishing So Dangerous?
A QR code (Quick Response code) is a two-dimensional barcode that can store URLs, payment details, contact information, and more. It helps users move quickly from point A to point B – usually a website or app. For attackers, these codes are attractive for several reasons.
First, QR codes are everywhere. The pandemic-driven demand for contactless interactions made scanning a code a routine daily habit. People are far more likely to pull out their phone to scan a code today than they were just a few years ago.
Second, QR codes fit perfectly into phishing scenarios. Instead of a malicious link or attachment, an attacker simply inserts a QR code. Generating one takes seconds – many modern phishing toolkits already include a QR code generator. The most dangerous aspect, however, is that the QR code moves the victim from a relatively secure corporate environment to a largely uncontrolled mobile device, bypassing enterprise-grade security.
Third, quishing is stealthy. The target URL is embedded in a visual pattern, not displayed as readable text. This allows attackers to hide malicious addresses so that some traditional email filters cannot extract or scan them. To make detection even harder, codes are often embedded inside PDF or JPEG attachments. As a result, these emails are more likely to land in an employee’s inbox. Once there, it is difficult to tell a real message from a fake one: there is little text to check for typos or grammar mistakes, and the link itself is invisible to the human eye.
The Social Engineering Factor
When a quishing attack uses a trusted brand – like a fake DocuSign email or a Microsoft security alert – it employs the same social engineering tricks as classic phishing. A recognizable brand convinces the victim it is safe to proceed. Attackers often create a sense of urgency, embedding malicious QR codes in notifications that urge the user to “secure your account” or “complete authentication immediately.”
Attackers Are Constantly Improving
As with any cyber threat, attackers refine their methods to maximize impact. Quishing is no longer just about installing malware or stealing credentials. It is now used to harvest multi-factor authentication (MFA) tokens as well. Security researchers have documented the following attack scenarios:
Bypassing app store protections: Direct app downloads where malware is disguised as legitimate software.
Redirecting to legitimate apps: Instead of a phishing website, the user is sent directly to a real app (social media, payment app, etc.). This can be used for:
Account takeover: Tricking the victim into authenticating, which actually grants the attacker access.
Financial fraud: Sending the victim to a payment app with pre-filled recipient details.
Contact and calendar poisoning: Malicious meeting links or new contacts are embedded into business apps, redirecting users to phishing sites when clicked.
Malicious Wi-Fi: The victim is automatically connected to a fake access point controlled by the attacker.
Using URL shorteners: Long malicious addresses are converted into short links and embedded into QR codes, making them harder to detect.
Even state-sponsored APT groups use quishing. An FBI notification from January 2026 stated that the North Korean group Kimsuky has been targeting think tanks, academic institutions, and government agencies in the US and other countries. They embedded QR codes into targeted phishing emails, claiming the codes would lead to surveys, registration pages, or secure document repositories.
Fortunately, a well-balanced combination of people, processes, and technology can significantly reduce quishing risks.
Start with your people. Include quishing awareness in your security training program. Run simulated quishing exercises. Encourage employees not to scan QR codes from unsolicited emails and to report any suspicious messages. If an employee believes an email is from a trusted source, they should verify by contacting the sender using contact details obtained separately – not from the suspicious email.
Next, implement technical defenses:
Use a reliable email security solution from a trusted provider to minimize the number of quishing emails reaching users’ inboxes.
Deploy mobile device security to block access to malicious websites and other threats on employee phones.
Implement phishing-resistant MFA for all sensitive accounts. Even if users are tricked, attackers will not be able to gain a foothold in corporate systems.
Use Mobile Device Management (MDM) tools to ensure all devices comply with corporate security policies.
Reduce your attack surface. Apply the principle of least privilege and just-in-time access. Keep all mobile operating systems and corporate software – including security tools – up to date.
Monitor continuously for suspicious activity and regularly practice incident response plans for the worst-case scenario.
Familiarity as a Security Tool
QR codes have moved from a novelty to a standard part of corporate life. The same has happened with quishing. Familiarity should not lead to complacency. Just as employees have learned to be wary of traditional email and SMS phishing, they can be trained to spot the signs of a quishing attack. Under the right conditions, familiarity can actually work in favor of security.
Read the original and other articles at
https://advisor-bm.com/resources#Quishing #QRCodePhishing #CyberSecurity #PhishingAttack #EmailSecurity #MobileSecurity #MFA #InfoSec #CyberThreats #BusinessSecurity