Skip to content
Cybersecurity · · 4 min read

QR code phishing: how quishing works and how your team can spot it

Scammers hide links in QR codes: in emails, PDFs, letters and on stickers. Why it works, how to recognise it, and what to tell your employees about it.

By Limburg Cyber Group

You know the advice: hover your mouse over a link before you click, so you can see where it really goes. With a QR code, you cannot do that. All you see is a block of black squares, and only after scanning do you find out where it leads. Scammers take advantage of that. This form of phishing is called quishing, a blend of QR and phishing. Below you will read why it works, what it looks like and what to tell your employees.

Why attackers use a QR code

For a scammer, a QR code has two advantages.

  1. The link is hidden. An employee cannot tell at a glance whether the address is genuine. Email filters also find a link inside an image harder to recognise than an ordinary link in the text.
  2. The victim picks up their phone. The email arrives on the laptop, where your business has set up filtering and security. But you scan with your phone, often a personal one, outside that protection. The screen is small, you see less of the address and you are quicker to tap through.

Where you come across them

Quishing is not limited to your inbox:

  • in emails, as an image in the message;
  • in attachments, such as a PDF made to look like an official document;
  • in letters that arrive by post, for example a fake invoice or payment reminder;
  • on stickers placed over a genuine QR code, on parking meters or posters.

The stories that come with them

The pretext is usually something ordinary, with a little urgency added:

  • “Your MFA needs to be set up again.” Scan the code to reconnect your authenticator app, or lose access to your email.
  • “A document has been shared with you.” Scan to view the contract, the payslip or the quote.
  • A parking fine or an unpaid invoice. Scan to pay straight away and avoid extra charges.

Behind the code is a fake sign-in page, for example for Microsoft 365, or a payment page. Some fake sign-in pages also ask for your MFA code and pass it straight on to the real site. If you fill in everything yourself, the code on your phone no longer protects you.

How to recognise it

  • A QR code in a business email is unusual. Why would a colleague or supplier ask you to pick up your phone when they could simply include a link or a button?
  • Look at the address after scanning. Many camera apps first show you where the link goes. If the domain name is not exactly right, do not open it.
  • Landing on a sign-in page after scanning is a warning sign. Especially if the code came from an email or a letter.
  • A sticker over another code, or a code that is loose or crooked.
  • The familiar signals still apply: urgency, threats and an unexpected request. See also spotting phishing emails.

What to tell your team

Keep it short and concrete:

  1. Our IT will never ask you by email to scan a QR code to reset your MFA or your account. Agree this with your IT partner, so that it is actually true.
  2. Never pay through a QR code from an unexpected letter or email. Check the invoice in your own records or call the sender on a number you look up yourself, just as with invoice fraud.
  3. Pay for parking at the meter itself or in the app you already use, not through a code on a sticker.
  4. Report a suspicious QR code the same way as any other phishing, even if you have already scanned it.
  5. Already entered your details? Report it at once. Your password can then be changed and your account signed out everywhere before any harm is done.

Include quishing in your existing security awareness efforts. Showing one real example makes more of an impression than explaining a rule.

Getting started

Want your team to recognise new variants like this one, without turning it into a full course? We run short, practical awareness sessions and help set up your email and accounts so that one wrong scan does not immediately become an incident. See our cybersecurity service or get in touch.

Read more

Cybersecurity ·

When an employee leaves: what to arrange digitally

When someone leaves, their accounts, passwords and sharing links often keep working longer than you think. A practical checklist to close them off properly.

Read more 3 min read

Shall we meet?

No sales pitch. Just a conversation about where you stand and what makes sense for your business.