Cybersecurity

QR Code Phishing (Quishing): How to Protect Your Business

Recognize malicious QR codes in email, print, and public places, and reduce the risk to business accounts.

Reviewed October 10, 2026 3 minute read Reviewed by Meta IT Pro
Part of the Cybersecurity Learning Center

Quishing hides a phishing link inside a QR code. Because the link is an image, it can bypass some email filters and moves the victim from a protected computer to a personal phone.

Key takeaways

What to know before you act

  • QR codes hide their destination, which makes them useful for disguising phishing links.
  • Quishing often moves the victim from a protected work computer to a personal phone with fewer safeguards.
  • The safest habit is to navigate to known sites directly rather than scanning codes for sign-in or payment.

Why it matters

What business leaders should understand

QR codes appear on invoices, parking meters, restaurant tables, and fake security notices. A single scan can lead to a convincing sign-in page that captures business credentials.

The right response should reflect your environment, data, vendors, risk, and operational priorities. Use this guide as a practical starting point, then validate important decisions with the people responsible for your technology, cybersecurity, legal obligations, and insurance coverage.

How QR code phishing works

In email, attackers embed a QR code in the message or an attachment—often styled as a Microsoft 365, MFA, payroll, or document-sharing notice. Because the link is inside an image, some filters cannot inspect it. The recipient scans it with a phone and lands on a convincing sign-in page.

In the physical world, criminals place stickers over legitimate codes on parking meters, signs, or menus, or mail letters with codes that lead to fake payment portals. The Federal Trade Commission has warned consumers about these tactics.

Reducing the risk

Technical controls help, but the most effective defense is a simple rule: do not use a QR code to sign in to a work account or make a payment unless you were expecting it and can confirm the destination.

  • Preview the URL your phone displays and check the domain carefully before opening it.
  • Be suspicious of codes in unexpected emails, especially urgent account or MFA notices.
  • Inspect public codes for stickers or tampering.
  • Protect work accounts with phishing-resistant MFA so captured passwords are less useful.
  • Use mobile device management and protection on phones that access business data.
  • Report suspicious QR messages so they can be blocked for others.

Practical action plan

Steps your business can take

01

Treat QR codes in unexpected emails as suspicious, especially account or MFA notices.

02

Preview the destination address before opening it and check the domain carefully.

03

Navigate to known sites directly instead of scanning codes for sign-in or payment.

04

Report suspicious QR code messages so the security team can block the campaign.

Recommended next steps

Continue from this article.

These pages expand the specific risks and decisions covered in this guide. Use them to move from general understanding to the service, tool, or related topic that best matches your next question.

Warning signs

Do not ignore these indicators

  • An email asks you to scan a code to keep your account or MFA active
  • A sticker appears over an existing QR code in a public place
  • A scanned code leads to a sign-in page for a work account

How Meta IT Pro can help

Related services and practical next steps

Explore the services connected to this topic. These links provide more detail about scope, safeguards, support, and how to start a conversation with our team.

Authoritative references

Sources and further reading

These primary sources support the guidance in this article and provide additional technical or consumer information.

Need help with your IT solution?

Get practical guidance from a local IT and cybersecurity team.

Meta IT Pro helps Massachusetts and Rhode Island businesses improve support, security, Microsoft 365, Google Workspace, networks, backup, recovery, and compliance readiness. Tell us what is not working - or what you want to improve - and we will help identify a sensible next step.