What is "quishing"?
Quishing is QR code phishing — an attack that uses a QR code in place of a traditional link to send victims to a fraudulent website. It has become significantly more common because it sidesteps most email security tools.
Why attackers use QR codes instead of links
Standard email security tools scan message text and embedded links for known threats. A QR code is just an image — security tools cannot read what is encoded inside it. This means a malicious URL hidden in a QR code passes straight through filters that would have blocked the same link written as text.
Once scanned, the QR code opens a URL on your mobile device, which is often less protected than your work computer and may not have the same security software installed.
Four reasons QR code attacks are so effective
Understanding why these attacks succeed makes it easier to defend against them.
Bypasses email link scanning
Security tools read text and URLs. A QR code is an image — the hidden URL inside it is invisible to automated filters.
Moves the attack to your phone
Mobile devices typically have fewer security controls than work computers. Scanning shifts the risk to a less-protected device.
People trust QR codes
QR codes are associated with restaurants, payments, and event check-ins. Many people scan without thinking, unlike suspicious links.
The URL is hidden until scanned
You cannot hover over a QR code to preview the destination the way you can with a hyperlink. The risk is concealed by design.
How attackers deliver malicious QR codes
Quishing attacks arrive through several different channels. These are the most common scenarios you are likely to encounter.
Email with a QR code instead of a link
A message claims your Microsoft 365 account, parcel, or bank account needs attention and asks you to scan a QR code to resolve it. The code leads to a convincing fake login page designed to steal your credentials.
Text message or WhatsApp with a QR code image
A QR code is sent via SMS or a messaging app, often posing as a delivery company, HMRC, or a bank. Because it arrives on your phone, you are already one tap away from scanning it.
PDF attachment containing a QR code
An email with a PDF attached — often posing as an invoice, courier notice, or HR document — where the actual link is presented as a QR code inside the PDF rather than as a clickable URL. Security tools scan the email but often do not inspect PDF contents deeply.
Physical QR codes in public or on printed materials
Stickers placed over legitimate QR codes in car parks, restaurants, or reception areas. Fake posters or printed documents left in public spaces. Scanning these can lead to credential theft or malware downloads — and the physical code appears entirely trustworthy.
What a QR code phishing email looks like
These emails are designed to look official and routine. The QR code replaces the suspicious link — making it harder to spot the threat at a glance.
Dear User,
We have detected unusual sign-in activity on your Microsoft account. To protect your account, we have temporarily limited access.
To restore full access, please scan the QR code below using your mobile device's camera and follow the on-screen instructions.
If you did not attempt to sign in, you can ignore this message.
— Microsoft Account Security
What to do if you receive an unexpected QR code
Whether it arrives by email, text, PDF, or printed material — these steps apply any time a QR code appears unexpectedly.
Do not scan it
If you were not expecting a QR code from this sender, do not scan it. Unlike a link, you cannot preview where it leads without scanning — which is exactly what makes it dangerous.
Check the sender and the context
Does the email address match who it claims to be from? Were you expecting this message? Legitimate services — Microsoft, your bank, HMRC — will not ask you to scan a QR code out of the blue to verify your account.
If you must check, preview the URL before visiting it
Most phone camera apps show a preview of the URL before opening it. Read the URL carefully — does it match the legitimate domain of who the email claims to be from? If in doubt, do not proceed.
If you have already scanned it and entered details — act immediately
Change your password for any account you may have signed into via the QR code, enable MFA if not already active, and contact your IT team straight away. Speed is critical — attackers can use stolen credentials within minutes.
Report it to your IT team
Forward suspicious emails to your IT support team. If you are a managed customer of The Cloud Network, call us immediately on 0345 450 9666 and we will assess and help secure your account.
Dos and don'ts for QR codes
- Preview the URL your camera shows before tapping to open it
- Ask yourself whether you were expecting a QR code from this source
- Keep your phone's operating system and apps up to date
- Report suspicious QR codes in emails to your IT team immediately
- Use MFA on all accounts so a stolen password alone is not enough
- Scan a QR code from an unexpected or unsolicited email
- Enter login credentials on a page reached by scanning an unknown QR code
- Assume a QR code is safe because it arrives in an otherwise professional-looking email
- Ignore urgency warnings in the message — they are designed to stop you thinking
- Scan physical QR codes that look tampered with or out of place
Need help or have a concern?
Our team is available to advise on any security concerns, investigate suspicious activity, or help you improve your organisation's security posture.
Please use our contact details below to get in touch
