Skip to main content

QR phishing (quishing)

QR phishing, or "quishing", hides a malicious link inside a QR code so victims scan their way to a fraudulent page, bypassing many email and URL filters in the process.

How it works

A QR code appears in an email, poster, invoice, or parking meter. Because it is an image, security filters often miss the embedded URL, and the victim opens it on a phone, outside corporate protections, where the lookalike page does its work.

How it relates to brand impersonation

Quishing is a fast-growing delivery method for brand-impersonation phishing, especially against financial institutions. The destination is still a lookalike page that monitoring and takedowns can address.

How nebty helps

Our guide on QR phishing for financial institutions breaks down the threat, and nebty takes down the fraudulent destinations these codes point to.

QR phishing guide

Why QR codes slip past defences

A QR code is just an image, and that is the whole trick. Email security tools that scan for malicious links often do not read the URL hidden inside a picture, so a quishing message can sail through filters that would have blocked the same link in text. The code also moves the victim onto a personal phone, outside the corporate browser, endpoint protection, and proxy that might otherwise flag the destination. Physical placement adds another angle: a sticker over a real QR code on a poster, parking meter, or restaurant table sends people to a lookalike page they had every reason to trust. The defences are to treat an unexpected QR code like any unknown link, to preview the URL before opening it, and, for a brand, to take down the lookalike destinations these codes point at. Our QR phishing guide covers the threat in depth.

A concrete example

Customers of Solara Finance receive a printed letter, on convincing letterhead, asking them to reconfirm their online banking access "due to a security update". Instead of a link there is a QR code. It resolves to solara-finance-secure.com, a cloned login page. Because the lure arrived on paper and the URL sat inside an image, no email filter ever saw it, and victims typed their credentials on their personal phones, outside every corporate protection. The bank got ahead of it by taking the destination domain down and alerting customers the same week.

How to spot and stop it

  1. Treat every unexpected QR code like an unknown link. Preview the URL your phone shows before opening it, and stop if the domain is not the one you expect.
  2. Never log in through a page you reached by scanning. Open the app or type the known address instead.
  3. As a brand, monitor for the lookalike domains these codes point at and take them down. The QR code is only the delivery route; the destination is what does the harm.

Frequently asked questions

Can a QR code itself be malicious?

The code is just an encoded URL; scanning it does not infect anything. The danger is the destination: a phishing page, a malware download, or a payment redirect. That is why previewing the URL before opening is the single most useful habit.

What should I do if I already scanned and entered data?

Change the affected password immediately, from a device you trust, and enable multi-factor authentication. If payment data was involved, contact your bank. Then report the page so it gets blacklisted before the next victim scans.

See who is impersonating your brand

The free nebty report scans the web for lookalike domains and fake profiles targeting your brand, with no obligation.

Get your free report