Most phishing defenses were built around one assumption: the malicious link is text, and text can be scanned. Secure email gateways parse URLs, check them against threat intelligence feeds, and flag or rewrite the ones that look wrong. QR code phishing — "quishing" — breaks that assumption entirely. The destination is encoded inside an image, and most email security tools still don't unpack what's hidden in a picture the way they unpack a hyperlink.
Reported quishing incidents have risen sharply over the past two years as attackers noticed the gap and started exploiting it deliberately, not incidentally. It's a simple trick, and that's exactly why it works.
Why a QR code beats filters that catch normal phishing links
A traditional phishing email contains a URL that a secure email gateway can inspect: check it against known-bad domain lists, sandbox it, or rewrite it through a proxy. A QR code is just pixels to that same scanner. Unless the platform specifically decodes embedded images and evaluates the resulting URL, the malicious link travels through completely unexamined.
It also defeats the human instinct that email training spent years building. Employees have been taught to hover over links and check the destination before clicking. You can't hover over a QR code. Scanning it happens on a phone, often outside whatever web filtering or endpoint protection is running on the corporate laptop, and the destination isn't visible until after the phone's camera has already resolved it.
Where quishing actually shows up
Fake MFA or account-security emails
An email claiming a password or multi-factor authentication method needs to be reconfigured, with a QR code presented as the "secure" way to do it. It plays on the fact that scanning a code to set up an authenticator app is a completely normal, expected action — which is exactly why it's an effective disguise.
Fraudulent invoices and delivery notices
PDF or image-based invoices with a QR code instead of a payment link, aimed at accounts payable staff. Because the rest of the document can look like a legitimate vendor invoice, the QR code reads as just another payment option rather than the actual attack.
Physical tampering in the real world
Attackers have printed fraudulent QR code stickers and placed them over legitimate ones on parking meters, restaurant menus, and public posters. This matters for businesses too: any QR code your company displays publicly — on signage, packaging, or printed marketing — can potentially be physically covered by a malicious sticker directing customers or staff somewhere else entirely.
Conference and event follow-ups
Fake "here's the slide deck" or "scan to connect" codes distributed after industry events, when recipients are primed to expect exactly that kind of follow-up from people they just met.
Why the phone matters more than the filter
The mobile device doing the scanning is frequently outside the protections that would catch the same attack on a desktop. A personal or work phone may not have the same DNS filtering, endpoint detection, or browser isolation as a managed laptop, and a link opened through a QR scanner often bypasses the browser protections the phone otherwise has. That makes the phone the weakest link in an otherwise reasonably well-defended environment — not because the technology on it is worse, but because fewer layers of inspection sit between the scan and the destination.
Controls that actually address this gap
Modern email security platforms are beginning to add QR-code-aware scanning — decoding embedded images and evaluating the resulting URL the same way a plain-text link would be checked. When evaluating or renewing an email security product, ask specifically whether QR code decoding is included, since many platforms still don't do this by default.
Mobile device management and endpoint protection extended to phones, not just laptops and desktops, closes part of the visibility gap, giving IT the ability to see and respond to threats on the device that's actually doing the scanning.
Awareness training needs a specific update here: teach employees to be as suspicious of an unexpected QR code as they would be of an unexpected link, and to check the destination URL that appears in the phone's preview before tapping through — most phones show a preview of the resolved link before opening it, and that pause is the same habit that already works against text-based phishing.
For any QR code your business displays publicly, a periodic physical check that the printed code hasn't been covered or swapped is a low-effort, high-value habit worth adding to a regular site walkthrough.
The pattern to remember
Quishing isn't a fundamentally new kind of attack — it's the same credential theft and payment fraud playbook, delivered through a channel most defenses weren't built to inspect. Closing that gap is less about new technology and more about extending the same scrutiny already applied to links, to a format that's been getting a pass.
Want your email security stack checked for QR-code coverage? Find your plan or book a free 15-minute call with our team.