Quishing hides a phishing link inside a QR code. Because the link is an image, it can bypass some email filters and moves the victim from a protected computer to a personal phone.
Key takeaways
What to know before you act
- QR codes hide their destination, which makes them useful for disguising phishing links.
- Quishing often moves the victim from a protected work computer to a personal phone with fewer safeguards.
- The safest habit is to navigate to known sites directly rather than scanning codes for sign-in or payment.
Why it matters
What business leaders should understand
QR codes appear on invoices, parking meters, restaurant tables, and fake security notices. A single scan can lead to a convincing sign-in page that captures business credentials.
The right response should reflect your environment, data, vendors, risk, and operational priorities. Use this guide as a practical starting point, then validate important decisions with the people responsible for your technology, cybersecurity, legal obligations, and insurance coverage.
Learn how Meta IT Pro can help with cybersecurity services and security awareness training.
Related reading: What is a phishing attack? and Secure your business smartphone in 5 minutes.
How QR code phishing works
In email, attackers embed a QR code in the message or an attachment—often styled as a Microsoft 365, MFA, payroll, or document-sharing notice. Because the link is inside an image, some filters cannot inspect it. The recipient scans it with a phone and lands on a convincing sign-in page.
In the physical world, criminals place stickers over legitimate codes on parking meters, signs, or menus, or mail letters with codes that lead to fake payment portals. The Federal Trade Commission has warned consumers about these tactics.
Reducing the risk
Technical controls help, but the most effective defense is a simple rule: do not use a QR code to sign in to a work account or make a payment unless you were expecting it and can confirm the destination.
- Preview the URL your phone displays and check the domain carefully before opening it.
- Be suspicious of codes in unexpected emails, especially urgent account or MFA notices.
- Inspect public codes for stickers or tampering.
- Protect work accounts with phishing-resistant MFA so captured passwords are less useful.
- Use mobile device management and protection on phones that access business data.
- Report suspicious QR messages so they can be blocked for others.
Practical action plan
Steps your business can take
Treat QR codes in unexpected emails as suspicious, especially account or MFA notices.
Preview the destination address before opening it and check the domain carefully.
Navigate to known sites directly instead of scanning codes for sign-in or payment.
Report suspicious QR code messages so the security team can block the campaign.
Recommended next steps
Continue from this article.
These pages expand the specific risks and decisions covered in this guide. Use them to move from general understanding to the service, tool, or related topic that best matches your next question.
Related guide
What is a phishing attack?
Recognize the fake sign-in pages QR codes often lead to.
Explore nextRelated guide
Secure your business smartphone in 5 minutes
Protect the phone used to scan codes and approve sign-ins.
Explore nextRelated guide
The S.E.C.U.R.E. method
Give employees a repeatable way to check suspicious messages.
Explore nextService
Managed email security
Add filtering that inspects image-based phishing attempts.
Explore nextWarning signs
Do not ignore these indicators
- An email asks you to scan a code to keep your account or MFA active
- A sticker appears over an existing QR code in a public place
- A scanned code leads to a sign-in page for a work account
How Meta IT Pro can help
Related services and practical next steps
Explore the services connected to this topic. These links provide more detail about scope, safeguards, support, and how to start a conversation with our team.
Authoritative references
Sources and further reading
These primary sources support the guidance in this article and provide additional technical or consumer information.
Federal Trade Commission
How to Recognize and Avoid Phishing Scams
Consumer guidance on common phishing messages, warning signs, and how to report them.
Cybersecurity and Infrastructure Security Agency
Recognize and Report Phishing
Plain-language guidance for recognizing, reporting, and removing phishing messages.
National Institute of Standards and Technology
NIST SP 800-124 Rev. 2: Guidelines for Managing the Security of Mobile Devices
Guidance for managing mobile-device security across deployment, use, and disposal.
Need help with your IT solution?
Get practical guidance from a local IT and cybersecurity team.
Meta IT Pro helps Massachusetts and Rhode Island businesses improve support, security, Microsoft 365, Google Workspace, networks, backup, recovery, and compliance readiness. Tell us what is not working - or what you want to improve - and we will help identify a sensible next step.
