Quishing
Phishing via QR code. The malicious link travels as an image, slips past email filters and opens on the phone, outside corporate defenses.
Full definition
Quishing is phishing through QR codes: the attacker replaces the text link with a code the victim scans with their phone. Because the link travels inside an image, email filters that analyze URLs cannot detect it as easily.
The attack moves the victim from the protected corporate environment to their personal phone, where no proxy or filter inspects the destination page. Typical lures imitate HR notices, multi-factor authentication prompts, menus or payments, contexts where scanning a QR is already a normal gesture.
Purely technical defense arrives late against this vector, so the emphasis is on behavior: treating any QR received by email as an unknown link and verifying the destination before entering credentials.
Related terms
Phishing
An attack that impersonates a trusted sender, such as a bank, a colleague or a vendor, to steal credentials, data or money, or install malware.
Smishing
Phishing via SMS or mobile messaging. It exploits trust in the phone and the absence of filters: the message arrives direct, short and with a link.
Multi-factor authentication (MFA)
Identity verification with two or more independent factors. It makes a stolen password insufficient, though not invulnerable.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.