← Glossary

Quishing

Phishing where the malicious link is delivered as a QR code, evading text-based email scanners and moving the attack to the user's phone.

Updated

Key facts

  • The link hides in pixels: filters that do not analyze images pass the message as clean.
  • Scanning moves the session to a mobile device, typically outside corporate URL filtering and monitoring.
  • Common lures are operational: MFA re-enrollment, expiring passwords, missed voicemail, parcel notices, and shared documents.

Why quishing works

QR codes carry built-in legitimacy: workplaces trained everyone to scan them for menus, logins and MFA setup. An email that says "your authenticator expires today, scan to re-enroll" mimics a genuine IT flow exactly, and the phishing page it opens on the phone renders full-screen with the address bar barely visible. Credentials or session tokens entered there are harvested off-device, invisible to the desktop security stack. See also phishing, smishing, spear phishing and consent phishing.

How to defend

Email security that performs image analysis and QR decoding in scanning, mobile protection or at minimum DNS filtering on managed phones, MFA processes that never start from an emailed QR code (and users told exactly that), and reporting drills that include "weird QR email" as a category.

How Sentaro stops quishing

Sentaro's Message Defense analyzes full message content including images: QR codes are decoded, their destinations evaluated like any URL (lookalike domains, credential-harvest patterns, infrastructure age), and the surrounding intent (urgent MFA or password framing) weighs into the verdict. The pixel trick stops working when the scanner reads pixels.

Questions we get asked.

What does quishing mean?

Phishing via QR code: the malicious link is encoded as an image so that text-based email filters miss it and the victim opens it on their phone.

Why do attackers use QR codes instead of links?

Two reasons: many email scanners historically did not decode images, and the scan moves the victim to a mobile device outside corporate protections.

What are common quishing lures?

MFA re-enrollment, password expiry, voicemail notifications, delivery notices and shared-document invites, anything where scanning a code feels like a normal IT flow.

How do I protect my company from quishing?

Use email security that decodes and evaluates QR codes, keep MFA flows out of email-delivered QR codes as policy, and extend URL protection to mobile devices where possible.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.