166 terms · 75/46/45
Threat № 034 · class: social eng.

QR phishing - Quishing

Quishing is phishing through a QR code. Instead of a visible link, the user is given an image to scan with their phone. The QR code then takes them to a fake page for a login, a payment, a document download or an account confirmation.

Term

description · examples · notes

Quishing is phishing through a QR code. Instead of a visible link, the user is given an image to scan with their phone. The QR code then takes them to a fake page for a login, a payment, a document download or an account confirmation.

Description

This attack is awkward because it hides the destination well. In an email or a document there is no ordinary link for a filter to read, and the user often carries on working on the phone, outside the protections that exist on the computer. A QR code feels like a fast and modern way in, so it is less often taken as a risk.

Quishing turns up in emails, PDF documents, fake invoices, posters, stickers on parking meters and notices in public places. The attack is simple: the user moves the session out of a controlled business environment onto a personal phone themselves.

Examples

  • An email posing as a Microsoft 365 notification contains a QR code leading to a fake login page.
  • A sticker with a fake QR code is pasted over the real code on a parking meter.
  • A PDF invoice contains a QR code for a supposed document check, but the page asks for business credentials.

Notes

  • A QR code is not safer than a link merely because it looks like a graphic.
  • Opening a QR code from business mail on a personal phone steps outside the protection the company provides.

Mentioned in the news

Composite
Wikipedia

Techniques

carried out with 3

Techniques used to carry it out. Select one to open its page.

Defenses

countered by 5