Free Phishing Test

QR codes look harmless
and that makes them dangerous

You have just done exactly what cybercriminals want you to do – scanned a QR code without being absolutely certain that the page was safe. Check the URL of this page, where you found a tip about what to do.

But do not worry! This time you reached a micro-training where we will show you how to protect yourself from quishing.

Quishing – QR-code phishing
    Quishing – QR-code phishing

    But imagine if…

    This might not have been a simulation, but a real quishing attack.
    • Instead of the micro-training, a fake login page for a trusted company (such as Microsoft 365) would have opened.
    • You might have entered your business credentials, such as your username and password, without suspecting anything.
    • That is how a cybercriminal would gain access to your email, systems and data.

    This is quishing – and it is becoming a popular attack vector.

    QR-code phishing is increasingly used by scammers to steal data: it grew from 1.4% to 12.4% of all attacks (Egress 2024). Up to 25% of phishing emails already contain a QR code (MDDR 2024).

    Quishing

    Why is QR Code Phishing so effective?

    It bypasses system defenses
    Spam filters scan links in the body of a message. A QR code is an image – the filter sees the graphic, not the URL. The link is activated only after scanning it with a phone, outside the organization’s protection systems.
    It hides the real URL
    After scanning a QR code, the URL is often displayed in a shortened form. It is much harder to spot issues such as typos in the domain name or unusual extensions.
    It exploits trust
    An email with a QR code supposedly sent by IT feels trustworthy. But is it [email protected] or [email protected]? Pay attention to the details – one letter can change everything.
    It masks its destination with shorteners
    Bit.ly and TinyURL hide the real address. You do not know where a link leads until you click it, so if you are not sure that a QR code is safe, do not open it.

    What should you check before scanning a QR code?

    Context of the QR code you received

    Before scanning a QR code, ask yourself a few key questions. Where did the code come from? Did you find it in an email, on a poster, on a sticker in a public space? Were you expecting this message? Is this communication typical for your organization or institution?

    URL security

    Most modern phones show a link preview before opening it. This is your most important line of defense. Carefully check the address to which the QR code wants to redirect you. Pay attention to link shorteners. Addresses such as bit.ly should immediately raise your suspicion.

    Physical signs of tampering

    If you find a QR code in physical form – for example, as a sticker on a paper document or poster – look closely at how it was made. Does the sticker peel off easily, or have a different color or texture from the rest of the document? If anything looks different, a scammer may have placed the QR code there.

    What to remember when scanning a QR code

    • Use your phone camera – QR-scanning apps may automatically open links without your consent. After scanning a QR code with your camera, look for the small icon that lets you preview the full URL before clicking.
    • Do not log in on a page opened from a QR code – always use the official app or a saved bookmark.
    • If the page asks for data such as a username, password, card details or a national ID number, close it and contact your IT team.

    What if you have already entered data on a suspicious page?

    Immediately change your password in all company systems. Report the incident to IT or security. Enable multi-factor authentication (MFA) if you have not already done so. Also monitor activity such as login history, active sessions and settings changes. If you see an unknown location, nighttime activity or unknown devices, sign out of all sessions, change the password again and report it to IT.

    Think before you scan a QR code

    QR codes spark our interest and curiosity.

    That is exactly why cybercriminals use them to steal data. Before scanning a QR code or clicking a link, remember to stay cautious. This helps keep you and your organization safe.