Skip to content

Quishing

Quishing uses QR codes to move a target from a trusted-looking surface to a deceptive or unsafe destination. The code conceals the destination until scanned, reducing the visibility available before the interaction shifts to a website, form, payment page, download, or other service.

QR codes are routine across physical and digital environments. Their placement can carry contextual trust when a code appears on familiar signage, business material, or an expected communication. The surrounding context may therefore establish legitimacy before the destination is visible.

The mobile transition also changes the interaction. URL visibility, password manager behaviour, browser context, reporting paths, and security controls may differ from those used on a managed desktop. Attackers can exploit that shift alongside urgency, convenience, or familiarity.

Quishing can appear wherever a QR code can be displayed, printed, embedded, forwarded, or placed over an existing code. The QR code may be carried in a message or document, attached to a payment context, or introduced into a physical environment.

After scanning, the destination commonly asks for an action that benefits from the trust created by the original surface. Credential entry, payment, data submission, account approval, or software installation may follow.

ElementWhat it meansExamples
QR placementThe physical or digital surface on which the code appears.Email, poster, invoice, parking sign, event flyer, workplace notice, delivery card.
Surrounding messageThe context used to encourage scanning.Payment due, account verification, delivery update, survey, registration, security alert.
Concealed destinationThe link or service opened after scanning.Login page, payment page, document, app download, form, support page, file-sharing site.
Requested actionThe action sought after the destination opens.Enter credentials, provide an MFA code, make a payment, submit data, download an app.
Apparent legitimacyThe contextual details that make the code or destination appear official.Branding, workplace location, official-looking signage, known event, familiar document.
Channel transitionThe movement from the original trusted surface to a different device, browser, or service context.Desktop email to mobile browser, physical sign to payment page, document to app download.

Quishing indicators commonly appear in the placement of the code, the previewed destination, or the action requested after scanning. Professional presentation does not establish the destination’s legitimacy.

IndicatorWhat to look for
Unexpected QR codeA code appears in a message, document, invoice, sign, or workflow where QR codes are not normally used.
Sticker or overlayA QR code appears to have been placed over an existing code, label, payment notice, sign, or printed surface.
Destination mismatchThe previewed link uses a shortened, lookalike, unfamiliar, or contextually inconsistent domain or service.
Unexpected sensitive actionScanning leads to a login, MFA prompt, payment request, data submission, account recovery step, or other sensitive action that was not expected.
Brand or context inconsistencyThe code, surrounding material, destination, or wording does not align with established branding, known channels, or the location in which it appears.
Mobile-only pressureThe interaction creates urgency around completing the action on a mobile device, particularly where destination details are difficult to inspect.
Exclusive QR pathwayA service normally reached through an official app, portal, or known website is presented as accessible only through the supplied QR code.