Quishing is phishing delivered through a QR code instead of a link: a scannable code in an email, PDF, parking meter, cafe menu or Teams chat sends the victim's phone to a fake login or payment page. It matters in 2026 because the code sidesteps the link-inspection habits staff were trained on — the URL stays invisible until the phone opens it, and the scan often happens on a personal device your email security never sees. Australian authorities have flagged the pattern: Scamwatch's QR code scam alert warns that scammers hide malicious links inside QR codes on parking meters and posters.
TL;DR
- Quishing is QR code phishing: a scannable code that sends a phone to a fake login, payment or download page.
- It works because the destination URL is hidden until scan time and often opens on a personal phone, outside corporate email protection.
- Common vectors: codes embedded in emails and PDFs, sticker overlays on real signage (parking, menus, EV chargers) and codes in chat apps.
- Train the reflex: treat an unsolicited QR code like an unknown link — check the code's source, type the URL manually, and never scan to log in.
- Simulations should include a QR lure; a tabletop drill covers the gap for platforms that cannot send one.
What is quishing?
The word is a mashup of QR and phishing, and the mechanic is exactly the phishing you already know — a convincing story plus a malicious destination — with one twist: the delivery vehicle is an image. Attackers favour it for three reasons. First, email filters that disassemble links cannot read a code reliably. Second, the human check fails: staff trained to hover over links have nothing to hover over, and the code's encoded URL is opaque. Third, the scan usually happens on the victim's personal phone, where your mail gateway, DNS filtering and browser policies do not apply.
The term spread as vendors and researchers started counting: Verizon's 2025 Data Breach Investigations Report lists quishing among the faster-growing templates, and national agencies including Australia's Scamwatch have published QR scam alerts covering parking meters, posters and cafe tables.
Where the malicious QR codes hide
- Inside emails and PDFs. The email body carries no link at all — just a code, often as an attached PDF invoice or benefits update that only opens on a phone.
- Sticker overlays. A fake label stuck over a legitimate code on a parking meter, EV charger or restaurant menu. People scan in good faith; the code was never the venue's.
- Payment and invoice lures. An invoice with a scan-to-pay code that routes to a payment page controlled by the attacker.
- Microsoft Teams and chat apps. The same file-and-code lure that works in email, delivered through a channel staff treat as internal — the pattern is covered in the Teams phishing guide.
- Recruitment and onboarding paperwork. Fake HR forms where the code leads to a credential-harvesting sign-in.
Why the phone changes everything
A desktop click happens on a managed device: corporate DNS, browser warnings, the reporting button one tab away. A phone scan happens on the device you do not control. The fake page renders smaller, the URL bar truncates the domain, and the victim is often walking, ordering or fuelling — distracted on purpose. The attacker's goal is the same as any credential phish: a Microsoft 365 or bank login, or a payment. What changes is that the defensive layers are thinner on the receiving end.
How to train staff against quishing
- Teach the reflex before the specifics. The rule: an unsolicited QR code is an unknown link in picture form. The same suspicion applies, and the check-before-you-act habit transfers from email.
- Cover the physical vector. Sticker overlays are the headline scam on Australian signage. The check: is the code printed on the sign itself, or is there a sticker sitting on top of it? A code behind a raised sticker edge is hostile until proven otherwise.
- Kill the login-over-QR habit. Nobody should ever sign in to a work system by scanning a code that arrived by message. If IT needs them somewhere, they type the address themselves or use the bookmark.
- Show the payment pattern. Invoice QR codes in finance teams: scan-to-pay routes the money wherever the attacker points it. Payment details change only after a phone call on a known number — the same rule as any invoice fraud defence.
- Add a QR simulation. Send a simulated quishing lure — an office parking-change email with a code — and auto-enrol anyone who scans into remediation. Cyber Aware's phishing simulations support code-based lures; platforms that do not still run a tabletop drill on the same script.
- Report the scan. A staff member who scans and lands on a login page should report it the same way they report a phished email. Speed still beats certainty.
What to check before you scan (the one-minute policy)
- Source check first. Who put the code there, and why is it reaching you? Codes in unexpected attachments are the email vector; stickers are the physical vector.
- Preview when possible. Most phone cameras show the decoded URL before opening it. Read the domain — the truncation is where the trick hides, so check the beginning and the end.
- Never scan to log in or to pay. Bookmarks and typed addresses for logins; verified payment details for money.
- Report the odd one. A suspicious sticker on the office's own signage is an incident for the building, not just your phone.
What businesses can do beyond training
Training is the human layer; a few controls shrink the surface:
- Email security with QR detection. Modern gateways decode embedded QR codes and rewrite or block the destination — check whether your current filter supports it, because older ones do not.
- Physical audits of signage. Anywhere you display a code — reception, menus, car park — gets a periodic check for overlays and tampering.
- MFA that survives a phished password. Phishing-resistant MFA or number matching limits what one scanned credential is worth.
- Reporting that covers phones. Staff need a way to report a scan, not just an email — even a photo of the fake sticker sent to IT counts.
A security gap assessment will show whether your email filter decodes QR payloads and where the reporting path breaks on mobile — the two controls this attack exploits first.
FAQ
What is quishing in simple terms? It is phishing with a QR code instead of a link. Scanning the code opens a fake login or payment page on your phone, where the usual link-checking habits and email security do not apply.
Why is quishing more dangerous than email phishing? The URL is invisible until scanned, and the scan usually happens on a personal phone outside corporate protections. Smaller screens and truncated URL bars make the fake domain harder to read.
What are common quishing examples? QR codes embedded in invoice or benefits PDFs, scan-to-pay payment lures, sticker overlays on parking meters and cafe menus, and codes shared in Teams or WhatsApp chats.
How do I spot a malicious QR code? Check the source first — who placed it and why. Look for stickers sitting on top of printed signage. Let the camera preview the URL and read the domain before opening. Never scan a code to log in or make a payment.
Can email filters detect quishing? Newer gateways decode embedded QR codes and block the destination; older ones often cannot. It is worth verifying with your vendor, because the gap is exactly where attackers aim.
Is quishing a problem in Australia? Yes. Scamwatch has published QR code scam alerts covering parking meters, posters and menu stickers, and the pattern keeps appearing in business email compromise reporting.
One last thing
Walk the car park. The most common real-world quishing in Australia is a sticker over a legitimate code on signage your own business or building displays. A two-minute walk with someone from facilities — checking every printed code for overlays — closes the physical vector better than any memo.