QR phishing - Quishing
Quishing is phishing through a QR code. Instead of a visible link, the user is given an image to scan with their phone. The QR code then takes them to a fake page for a login, a payment, a document download or an account confirmation.
Term
description · examples · notesQuishing is phishing through a QR code. Instead of a visible link, the user is given an image to scan with their phone. The QR code then takes them to a fake page for a login, a payment, a document download or an account confirmation.
Description
This attack is awkward because it hides the destination well. In an email or a document there is no ordinary link for a filter to read, and the user often carries on working on the phone, outside the protections that exist on the computer. A QR code feels like a fast and modern way in, so it is less often taken as a risk.
Quishing turns up in emails, PDF documents, fake invoices, posters, stickers on parking meters and notices in public places. The attack is simple: the user moves the session out of a controlled business environment onto a personal phone themselves.
Examples
- An email posing as a Microsoft 365 notification contains a QR code leading to a fake login page.
- A sticker with a fake QR code is pasted over the real code on a parking meter.
- A PDF invoice contains a QR code for a supposed document check, but the page asks for business credentials.
Notes
- A QR code is not safer than a link merely because it looks like a graphic.
- Opening a QR code from business mail on a personal phone steps outside the protection the company provides.
Mentioned in the news
Techniques
carried out with 3Techniques used to carry it out. Select one to open its page.
Defenses
countered by 5How it is defended against. Select one to open its page.