The QR code works to the advantage of the fraudster because it provokes a reflex: phone next to the picture, scan, open the website. The employee does not see the address he is going to, and the scanning itself transfers him from the company computer to his private smartphone, beyond the security measures that were supposed to protect him. Quishing exploits exactly this gap between trust in QR codes and lack of control over what lies behind them.
What is quishing?
Quishing (from QR code phishing) is a type of phishing in which the attack medium is a crafted QR code – after scanning, it redirects the victim to a fake website used to extort data or install malware. The name combines “QR” and “phishing”.
Quishing belongs to the family of phishing attacks, but differs from them in the point of contact with the victim. In email phishing, the victim clicks on the link visible in the message content, and in vishing he acts under the pressure of a telephone conversation. In quishing, the malicious address is hidden in the image. The user does not have it in front of him until he scans the code, and then he makes the decision on the phone screen, often in a hurry and beyond the reach of the company’s security tools.
Why does quishing bypass corporate security?
The effectiveness of quishing comes from three mechanisms that together weaken an organization’s typical defenses:
- Address hidden in the image. Spam filters and email gateways analyze the text of messages and links in text form. The QR code is a graphic, so the malicious URL is sometimes invisible to them and the message goes to the inbox.
- Transferring the action to a private phone. The employee scans the code with a smartphone, which is usually not covered by the company’s MDM system, traffic filtering or workstation protection. The attack takes place outside the organization’s network.
- Masked target. The target address is sometimes shortened or redirected through several domains, so even a preview of the link after scanning does not always immediately reveal that the website is fake.
How does a quishing attack work? Step-by-step diagram
A quishing campaign usually takes place in three stages:
- Preparation and delivery of the code. The criminal generates a QR code leading to a malicious website and places it where the victim expects it: in an email, in a PDF attachment pretending to be an invoice, in a messenger or in a physical space, for example on a poster or sticker.
- Scan and redirection. After scanning, the phone opens a camouflaged link that leads to a website confusingly similar to the website of a bank, payment operator or courier service.
- Fraud or infection. On a fake website, the victim provides a login, password or card details, makes an “urgent” transfer or downloads a file that installs malware on the device.
Where can you find malicious QR codes? Attack channels
Quishing is unique in that it combines the digital and physical worlds, which expands the attack surface beyond the email inbox.
In the digital channel, the QR code appears in emails (for example, as a supposed account verification or re-authentication request), in invoices and PDF documents, and in instant messaging. The graphic form helps bypass some of the security measures and make the message more credible.
In the physical channel, criminals stick their own codes on real materials:
- parking meters,
- posters,
- menu in restaurants,
- leaflets,
- plates with payment information.
The victim scans the code in a natural context, such as to pay for parking, and has no reason to suspect that the sticker has been tampered with.
How to recognize quishing? Warning Signals
Quishing can be recognized by several repeating signals:
- A QR code in an unexpected email, especially one asking you to log in or “verify your account”.
- Pressure of urgent payment for a service, parcel or invoice, combined with a quick payment code.
- Code pasted on top of another code or placed carelessly on official material, which may indicate substitution.
- The address of the page after scanning does not match the institution’s domain, is shortened or contains minor errors in the name.
- After the scan, the website immediately asks for login details, card details or downloading an application from outside the official store.
How to protect yourself against quishing?
Quishing protection works on two levels: the habits of an individual user and the preparation of the entire organization.
In everyday user practice, it is crucial to check the full URL address that the phone displays after scanning the code, before approving it. You should not scan codes from unreliable sources or provide login details on a website opened from a QR code. It is safer to enter the address of the bank or payment operator manually or open it from a saved tab, instead of trusting the redirection from the code.
At the organizational level, theoretical education alone is not enough, because quishing reaches private phones and takes place outside the eyes of the security department. Clear procedures for verifying unusual payment requests and regular training on realistic scenarios that train the reflex to check the code before an employee scans it are effective. As part of the Practical Anti-Phishing Training, we conduct simulations that also include QR codes, thanks to which the team practices safe responses using the same vector that a real attacker would use.
If you want to see from the inside what such a simulation and reporting of results looks like, arrange a free demo of the platform. A theoretical supplement for the team is also a free guide on recognizing QR Code Phishing. How to recognize QR Code Phishing?
Free guide for the team: How to recognize QR Code Phishing?
What to do after scanning a malicious QR code?
If you entered your login or card details after scanning the code, act immediately.
- Change passwords for your account and related services.
- Then contact your bank to block the card or dispute suspicious transactions.
- If you downloaded and installed the application from the code, disconnect the phone from the network and scan it with security software, and if in doubt, report the matter to the IT department.
It is worth reporting the incident to limit the consequences and help block the campaign. You can report suspicious codes and messages to CERT Polska, and a description of this fraud along with tips can be found on the government website gov.pl. In case of financial loss, also notify the police.
FAQ – quishing
What is the difference between quishing and phishing?
Quishing is phishing in which the malicious link is hidden in a QR code instead of a clickable link. This difference has practical consequences: the code as a graphic bypasses some email filters, and scanning takes the victim to a private phone, outside the security of the company computer.
Is scanning a QR code dangerous?
Just opening a website from the code usually does not immediately cause harm, the risk occurs when the victim provides data on a fake website or downloads the specified file. Therefore, before confirming, it is worth checking the full address that the phone displays and not providing login details on a website opened with an unknown code.
Do phishing simulations include QR codes?
Yes. As part of the Practical Anti-Phishing Training, we prepare campaigns that also use QR codes, in addition to phishing and smishing. We adapt the scenarios to the industry and positions, and the results are included in reports ready for the management board and auditors.