What is quishing (QR code phishing)?

Quishing is phishing via QR code: hidden URLs, fake parking and menu stickers, scan-to-pay lures. How it works and how to train staff against it in 2026.

Quishing is phishing delivered through a QR code instead of a link: a scannable code in an email, PDF, parking meter, cafe menu or Teams chat sends the victim's phone to a fake login or payment page. It matters in 2026 because the code sidesteps the link-inspection habits staff were trained on — the URL stays invisible until the phone opens it, and the scan often happens on a personal device your email security never sees. Australian authorities have flagged the pattern: Scamwatch's QR code scam alert warns that scammers hide malicious links inside QR codes on parking meters and posters.

TL;DR

What is quishing?

The word is a mashup of QR and phishing, and the mechanic is exactly the phishing you already know — a convincing story plus a malicious destination — with one twist: the delivery vehicle is an image. Attackers favour it for three reasons. First, email filters that disassemble links cannot read a code reliably. Second, the human check fails: staff trained to hover over links have nothing to hover over, and the code's encoded URL is opaque. Third, the scan usually happens on the victim's personal phone, where your mail gateway, DNS filtering and browser policies do not apply.

The term spread as vendors and researchers started counting: Verizon's 2025 Data Breach Investigations Report lists quishing among the faster-growing templates, and national agencies including Australia's Scamwatch have published QR scam alerts covering parking meters, posters and cafe tables.

Where the malicious QR codes hide

Why the phone changes everything

A desktop click happens on a managed device: corporate DNS, browser warnings, the reporting button one tab away. A phone scan happens on the device you do not control. The fake page renders smaller, the URL bar truncates the domain, and the victim is often walking, ordering or fuelling — distracted on purpose. The attacker's goal is the same as any credential phish: a Microsoft 365 or bank login, or a payment. What changes is that the defensive layers are thinner on the receiving end.

How to train staff against quishing

  1. Teach the reflex before the specifics. The rule: an unsolicited QR code is an unknown link in picture form. The same suspicion applies, and the check-before-you-act habit transfers from email.
  2. Cover the physical vector. Sticker overlays are the headline scam on Australian signage. The check: is the code printed on the sign itself, or is there a sticker sitting on top of it? A code behind a raised sticker edge is hostile until proven otherwise.
  3. Kill the login-over-QR habit. Nobody should ever sign in to a work system by scanning a code that arrived by message. If IT needs them somewhere, they type the address themselves or use the bookmark.
  4. Show the payment pattern. Invoice QR codes in finance teams: scan-to-pay routes the money wherever the attacker points it. Payment details change only after a phone call on a known number — the same rule as any invoice fraud defence.
  5. Add a QR simulation. Send a simulated quishing lure — an office parking-change email with a code — and auto-enrol anyone who scans into remediation. Cyber Aware's phishing simulations support code-based lures; platforms that do not still run a tabletop drill on the same script.
  6. Report the scan. A staff member who scans and lands on a login page should report it the same way they report a phished email. Speed still beats certainty.

What to check before you scan (the one-minute policy)

What businesses can do beyond training

Training is the human layer; a few controls shrink the surface:

A security gap assessment will show whether your email filter decodes QR payloads and where the reporting path breaks on mobile — the two controls this attack exploits first.

FAQ

What is quishing in simple terms? It is phishing with a QR code instead of a link. Scanning the code opens a fake login or payment page on your phone, where the usual link-checking habits and email security do not apply.

Why is quishing more dangerous than email phishing? The URL is invisible until scanned, and the scan usually happens on a personal phone outside corporate protections. Smaller screens and truncated URL bars make the fake domain harder to read.

What are common quishing examples? QR codes embedded in invoice or benefits PDFs, scan-to-pay payment lures, sticker overlays on parking meters and cafe menus, and codes shared in Teams or WhatsApp chats.

How do I spot a malicious QR code? Check the source first — who placed it and why. Look for stickers sitting on top of printed signage. Let the camera preview the URL and read the domain before opening. Never scan a code to log in or make a payment.

Can email filters detect quishing? Newer gateways decode embedded QR codes and block the destination; older ones often cannot. It is worth verifying with your vendor, because the gap is exactly where attackers aim.

Is quishing a problem in Australia? Yes. Scamwatch has published QR code scam alerts covering parking meters, posters and menu stickers, and the pattern keeps appearing in business email compromise reporting.

One last thing

Walk the car park. The most common real-world quishing in Australia is a sticker over a legitimate code on signage your own business or building displays. A two-minute walk with someone from facilities — checking every printed code for overlays — closes the physical vector better than any memo.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.