Quishing (QR Code Phishing)
A phishing variant where attackers embed malicious URLs in QR codes, bypassing traditional email link-scanning security tools.
Quishing exploits the growing ubiquity of QR codes by embedding malicious URLs within them. Because QR codes are opaque to the human eye (you can’t read the URL before scanning), and because many email security tools don’t scan QR code contents, quishing bypasses traditional phishing defenses.
Attackers send emails with QR codes claiming to link to MFA setup pages, document sharing platforms, or company portals. When scanned, the QR code directs to a credential-harvesting page.
Defenses include training employees to verify QR code destinations before entering credentials, using QR scanning apps that preview URLs, and ensuring that password managers (which won’t autofill on fake domains) are the primary method of entering credentials.
Related reading
Stop sharing passwords in spreadsheets
TeamPassword stores, shares and rotates your team credentials, encrypted end to end.
Trusted by 900+ agencies and small teams worldwide