Quishing

What Is Quishing?

Quishing is phishing carried out through a malicious QR code. Here is why it bypasses common safety habits and how to spot it before you scan.

What Is Quishing?

Quishing is phishing carried out through a malicious QR code. The term combines "QR code" and "phishing." Instead of clicking a link in an email, the victim scans a QR code that leads to a fraudulent website, often designed to steal login credentials or payment information.

Quishing has grown alongside the widespread use of QR codes for everyday tasks like restaurant menus, parking payments, and two-factor authentication setup. Because QR codes hide the destination URL until after they are scanned, they bypass a habit many people have built around inspecting links before clicking them.

A typical quishing attempt might appear in an email disguised as a delivery notice or invoice, asking the recipient to scan a code to "view the attachment" or "complete verification." Because the code is usually scanned on a personal mobile device, it can also bypass corporate email security tools that are designed to inspect links rather than images.

Awareness is especially important for quishing, since there is often no visible link text to scrutinize. Treating an unexpected QR code with the same caution as an unexpected link, and verifying the source before scanning, is the most effective way to avoid falling for it.