quishingQR code phishinghuman risk management

    June 27, 2026 · 5 min read · By José Vicente Chávez

    Quishing: QR code phishing that bypasses email filters

    An employee gets an email with a QR code: a supposed credential renewal, an invoice or a security alert. They scan it with their phone, land on a cloned page, type their password and, without realizing it, just handed over access to the company. That is quishing, QR code phishing, and it works because it moves the attack from the monitored computer to the personal phone, where almost no controls apply.

    The takeaway is direct: quishing is not a technical curiosity, it is a form of phishing built to dodge the very defenses companies trust most. Email filters inspect links and attachments, but a QR code is an image, so the malicious destination travels hidden inside a pattern of pixels and opens on a device the security team does not manage. More than 90% of successful cyberattacks start with a phishing email, according to CISA, and the QR variant removes the most friction for the attacker.

    What quishing is and why it slips past email

    Quishing comes from joining QR and phishing. Instead of a clickable link, the attacker embeds a QR code in an email, a PDF, a printed poster or a notification that mimics an internal process. Once scanned, the victim opens a fraudulent URL that asks for credentials, requests an approval or triggers a download.

    Human risk is managed automatically.

    Turn human risk into your first line of defense.

    Book a demo

    Free demo · 30 minutes · No commitment

    The method gives the attacker three advantages. First, many email controls do not resolve the destination of a QR code the way they read a text link, so the message reaches the inbox. Second, the scan happens on the phone, usually outside the corporate perimeter, without the same protected browser or policies. Third, the QR feels natural and urgent, because we already use it for menus, payments and access, so scanning feels routine.

    At its core, quishing is human risk management (HRM): detect who is most exposed, simulate the attack as it would actually arrive, correct at the moment of the mistake and confirm with a retest that the lesson stuck.

    What a quishing attack looks like inside a company

    The most common scenarios copy everyday business friction. An email warns that multifactor authentication is expiring and offers a QR to reconfigure it. A vendor PDF includes a QR payment code that changes the destination account. A poster in a meeting room invites people to scan for guest wifi. A message from the people team asks employees to validate their data by scanning a code.

    In every case, the QR leads to a page that captures credentials or secures an approval. And not every employee carries the same risk. The finance approver, the salesperson who lives in email and the executives who field urgent requests concentrate more impact than the average user. Treating the whole workforce the same dilutes defense where it hurts most.

    What does not work against quishing

    Banning QR codes is unrealistic: they are part of daily operations. Relying only on the email filter is not enough either, because the QR is designed to pass that control. And an annual awareness talk arrives late and speaks in the abstract, exactly when the attack unfolds in seconds and on the phone.

    Measuring only the click rate is another trap. A lower percentage in one campaign does not prove that a person will resist a convincing QR next time. Without validating the change in behavior, the organization manages activity, not risk.

    What actually reduces quishing risk

    Effective defense is continuous and rests on four pieces that work together. First, visibility into each person's real exposure, especially the leaked credentials an attacker reuses. Second, simulations that reproduce quishing as it arrives, with the QR in the email and the landing on mobile, not a generic exercise. Third, immediate contextual training the moment someone scans the lure, focused on verifying the domain before entering credentials. Fourth, a targeted retest weeks later with a different template of the same pattern, to confirm the person learned the logic, not the example.

    That last step is the one most often skipped and the one that matters most. Validating the change with a fresh test, rather than a completion certificate, is the only thing that proves risk went down. For companies of 25 to 500 employees running on Microsoft 365 or Google Workspace, a fast OAuth deployment makes it possible to see actionable signals in days, not in a quarter.

    What to measure to know the defense works

    Track recurrence against QR lures, the time between detecting an exposure and correcting it, the presence of compromised credentials and the reduction of critical users in high risk tiers. Above all, one signal carries the most weight: whether the person, faced with a similar quishing weeks later, no longer scans or hands over data. That is the proof that behavior changed.

    Quishing will keep growing because it offloads work from the attacker onto the victim. A platform like Fensivo addresses that gap by uniting credential monitoring, adaptive simulation and contextual training in a single flow, and validating with a retest that behavior improved. The question worth asking is not whether the team knows malicious QR codes exist. It is whether the organization can prove, person by person, that it responds better today when one shows up.

    Sources and references

    • CISA, "4 Things You Can Do To Keep Yourself Cyber Safe". cisa.gov

    Human risk is managed automatically.

    Turn human risk into your first line of defense.

    Book a demo

    Free demo · 30 minutes · No commitment