Attack technique

Quishing (QR Code Phishing)

Quishing is a phishing attack that hides a malicious link inside a QR code to trick people into visiting a fraudulent site or installing malware.

Definition

Quishing, a blend of QR and phishing, is a social engineering attack in which an attacker embeds a malicious URL inside a QR code instead of a clickable text link. When a victim scans the code with a phone camera, they are taken to a fraudulent website designed to harvest credentials, capture payment details, or deliver malware. Because the destination is encoded as an image rather than visible text, quishing often slips past email security gateways and link-scanning tools that inspect written URLs, and it deliberately shifts the victim onto a mobile device where the full address is harder to inspect.

A quishing attack typically starts with a QR code delivered by email, embedded in a PDF or image attachment, printed on a physical poster or letter, or pasted as a sticker over a legitimate code in a public place. The code resolves to a lookalike login page (commonly Microsoft 365, a bank, or a parking or payment portal). The attacker relies on two weaknesses: link scanners struggle to read URLs hidden inside images, and people instinctively trust QR codes and rarely preview the underlying address before tapping it on a phone.

Common examples include a fake multi-factor authentication setup email that asks employees to scan a code to re-enrol their account, a fraudulent parking or e-wallet payment notice with a QR code that opens a credential-harvesting page, and stickers placed over genuine codes on restaurant tables, EV chargers, or government notices. In Indonesia, where QRIS payments are part of daily life, a tampered or spoofed payment QR is a particularly believable lure.

Quishing matters because it bypasses controls that organisations rely on for written links and because it moves the victim to a personal or mobile device that is often outside corporate monitoring and endpoint protection. The defences are layered: train people to treat unexpected QR codes with the same caution as unexpected links, preview the decoded URL before opening it, avoid scanning codes in unsolicited emails or attachments, and enforce phishing-resistant multi-factor authentication so that stolen passwords alone are not enough to grant access.

At a glance

Severity
High
Prevalence
Growing rapidly
Primary targets
Mobile phone users, employees receiving MFA or payment-related emails
Also known as
QR code phishing

How it works

  1. 1

    Embedding: the attacker hides a malicious URL inside a QR code instead of a clickable text link.

  2. 2

    Delivery: the code is sent by email, embedded in a PDF or image attachment, printed on a poster, or pasted as a sticker over a legitimate code.

  3. 3

    Scan: the victim scans the code with a phone camera, moving the interaction to a mobile device where the full address is hard to inspect.

  4. 4

    Deceptive page: the code resolves to a lookalike login or payment page, commonly mimicking Microsoft 365, a bank, or a parking or e-wallet portal.

  5. 5

    Capture: entered credentials or payment details are captured and used immediately, often bypassing link-scanning tools built for written URLs.

Warning signs

  • Unexpected QR code in an email, attachment, poster, or flyer
  • A sticker that looks placed over an existing QR code
  • QR code linked to an urgent request, such as an MFA re-enrollment or a payment notice
  • Scanned link opens a login or payment page you did not expect
  • Request to enter credentials or a payment method right after scanning

How to defend

  • Preview the decoded URL before opening it; most phone cameras show the destination first
  • Treat unexpected QR codes with the same caution as unexpected links
  • Avoid scanning codes in unsolicited emails or attachments
  • Verify payment QR codes, such as QRIS, directly with the merchant or provider before scanning
  • Enable phishing-resistant multi-factor authentication so a captured password alone is not enough

Real-world example

An employee at a Jakarta company receives an email asking them to scan a QR code to re-enroll their Microsoft 365 multi-factor authentication before access is suspended. The code opens a convincing fake Microsoft login page, and the employee's credentials are captured the moment they are entered.

How Claro helps

Claro runs controlled quishing simulations that mirror real lures, including QR codes embedded in emails and attachments and QRIS-style payment scams tuned for the Indonesian context, so you can measure how many employees scan and submit credentials rather than guess. Scan and submit events feed directly into each user's human risk score, and anyone who falls for a simulation is enrolled in just-in-time micro-training that teaches them to preview QR destinations and verify payment codes. The same data rolls up into compliance reporting for OJK, BSSN, ISO 27001, and UU PDP, giving security teams defensible evidence that QR-based social engineering risk is being measured and reduced over time.

Frequently asked questions

What makes quishing different from regular phishing?

Quishing hides the malicious link inside an image rather than clickable text, which lets it slip past email security tools built to scan written URLs, and it deliberately shifts the victim to a mobile device where the full address is harder to inspect.

Can quishing bypass email security filters?

Often, yes. Because the destination is encoded as an image rather than visible text, many link-scanning tools that inspect written URLs never see the malicious address until a person scans the code.

How can I check a QR code is safe before scanning?

Most phone cameras show a preview of the decoded URL before opening it. Read that address carefully, and if the code arrived unexpectedly by email or is stuck over an existing code in public, do not scan it at all.

Are QRIS and other payment QR codes at risk?

Yes. Attackers replace or overlay legitimate payment QR codes with fraudulent ones. Always verify a payment QR directly with the merchant or provider rather than trusting the code alone.

Reduce your human risk

Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.

Request a demo