What is Quishing (QR code phishing)?

Quishing is phishing with a QR code. The attacker places a fake QR code in an email, on a parking meter, a restaurant menu or a poster. Scanning it opens a fake page on the phone that asks for login details or a payment.

A QR code is unreadable to people and often to mail filters too, because the link is inside an image. And the scan happens on a personal phone, outside corporate protection.

How to spot it

  • A QR code in an email asking you to "renew two-factor authentication"
  • A sticker pasted over the original code

What to do

  • After scanning, check the address before opening it
  • Log in or pay from the official app instead

Related courses

Terms on this topic

← Cybersecurity glossary

Start with your team's risk baseline

15-30 employees, one phishing simulation and a one-page report for management. No annual commitment.