WorkNest

Blog

What is Quishing? - QR Code Phishing Explained

Find out about a popular new phishing attack called quishing, or QR phishing. Find out how it works, and how your business can defend against it.

Background Image


You’ll probably already be familiar with phishing in some form – and have probably been on the receiving end of a phishing attack. If you need a refresher, this ‘what is phishing’ , article does a good job of laying down the basics. Phishing takes many forms, including spear phishing, whaling, smshing and vishing. It’s a form of social engineering in which a scammer pretends to be somebody trustworthy such as a friend, subscription service or a bank to convince a person to do something for them, such as:

  • Reveal confidential information

  • Click on a malicious link

  • Give them credentials

Quishing is a new form of phishing that uses QR codes, and it’s becoming more popular – you may have even already seen it in the wild. A QR code, or Quick Response code, is a two-dimensional barcode that stores information in a machine-readable format. These can be read and interpreted your smartphone camera and store a variety of information. QR codes are designed to be used for a range of different purposes including:

  • Linking to websites

  • Making instant payments

  • Storing event ticket information

  • Saving contact information directly to a device

QR codes look like this:


This QR code is not malicious and links to the Bulletproof.co.uk homepage

In the case of QR code phishing, attackers create a malicious QR code that, when scanned by a mobile device or QR code reader, leads the user to the same kind of activities as we see in other types of phishing. This could be a fraudulent website, a fake login page that captures sensitive information, or a URL that delivers malware. As for how the QR code gets to you in the first place, often it’s via an email, pretending to be from a reputable company, or from a friend’s email address. No, your friend probably hasn’t turned into a cyber criminal, but their email might have been hacked. Social media apps and messaging apps like Whatsapp are also attack vectors for quishing.


Quishing has the potential to get through spam filters and antimalware protection that may be scanning emails. If a malicious link is sent in an email, a spam filter or antimalware software would scan and block this, however, if the malicious link is a QR code, it may be seen as ‘just an image’ and therefore would not trigger a spam filter or malware scanner.

Cyber security is a constant game of cat and mouse between good guys and cyber criminals. New technologies present new opportunities and challenges, and the bad guys are often the first to exploit new tech capabilities. While QR codes might slip through some spam filters and anti-malware programs now, the defensive tech will evolve to combat QR-based threats.

In the meantime, I recommend the same defence as any other type of phishing attack: education. Regular security awareness training is a fundamental part of stopping all cyber attacks, but especially for phishing and social engineering attacks.

The rise of quishing attacks highlights how hackers and malicious actors are adapting to people becoming more security conscious and aware of the risks of links in emails. This advice, although correct and important, does not usually stretch to QR codes specifically and may lead a user to scan the QR code without thinking of the security repercussions as it may not have been specifically outlined as a potential risk to them in the past.

In the ever-evolving cyber landscape, where hackers continually devise innovative ways to exploit vulnerabilities, our awareness becomes paramount in safeguarding against emerging threats. We must never forget that there are malicious actors always trying to find new and unexpected ways to exploit and attack. It can never be understated how important awareness and knowledge of emerging threats are for preventing attacks and data breaches. And even things as straightforward as reading this blog can be the difference between falling for quishing and remaining safe online.

Building a multi-layered security strategy can help overcome the impact of a successful quishing attack. And I recommend getting the basics right first. A good example here is Cyber Essentials certification and especially Cyber Essentials Plus. This makes you look at the elemental security components of your organisation and build a strong foundation. Even businesses with a mature security strategy can benefit from Cyber Essentials certification. Who knows, you might even get me as your Cyber Essentials Assessor!

Talk to an expert

Share your challenge with us and we’ll help you find the right level of support for your business.

Your certified partner

Proven standards, trusted expertise, complete peace of mind

Award logo 1
Award logo 2
Award logo 3
Award logo 4
Award logo 5
Award logo 6
Award logo 7
Worknest logo
© 2020-2026 WorkNest. All rights reserved. (888) 243-3110