Key facts
- The link hides in pixels: filters that do not analyze images pass the message as clean.
- Scanning moves the session to a mobile device, typically outside corporate URL filtering and monitoring.
- Common lures are operational: MFA re-enrollment, expiring passwords, missed voicemail, parcel notices, and shared documents.
Why quishing works
QR codes carry built-in legitimacy: workplaces trained everyone to scan them for menus, logins and MFA setup. An email that says "your authenticator expires today, scan to re-enroll" mimics a genuine IT flow exactly, and the phishing page it opens on the phone renders full-screen with the address bar barely visible. Credentials or session tokens entered there are harvested off-device, invisible to the desktop security stack. See also phishing, smishing, spear phishing and consent phishing.
How to defend
Email security that performs image analysis and QR decoding in scanning, mobile protection or at minimum DNS filtering on managed phones, MFA processes that never start from an emailed QR code (and users told exactly that), and reporting drills that include "weird QR email" as a category.
How Sentaro stops quishing
Sentaro's Message Defense analyzes full message content including images: QR codes are decoded, their destinations evaluated like any URL (lookalike domains, credential-harvest patterns, infrastructure age), and the surrounding intent (urgent MFA or password framing) weighs into the verdict. The pixel trick stops working when the scanner reads pixels.