What Quishing Actually Is
Quishing, a blend of QR code and phishing, is a social engineering attack delivered through a QR code instead of a clickable link or an email attachment. The victim scans what looks like a routine QR code, perhaps on a poster, a parking ticket, an invoice, or an email, and the code silently opens a phishing website, triggers a malicious app download, or in some cases initiates a payment or account-linking flow designed to steal credentials or money. The mechanics after the scan are identical to any other phishing attack: a convincing fake login page, a request for one-time passwords, or a form that harvests personal and financial data.
What makes quishing distinct is not the payload, it is the delivery mechanism and the point of human suspicion it defeats. A QR code is, by design, unreadable to the human eye: nobody can look at a QR code and tell whether it points to a legitimate bank domain or a lookalike one. That opacity is precisely why attackers have shifted toward it as email filters, link-scanning gateways, and user training around suspicious URLs have all improved.
Quishing attacks typically arrive through one of three channels: physical, a QR sticker on a real payment terminal, parking meter, or poster, sometimes literally pasted over a legitimate code; digital-embedded, a QR image inside an email or PDF that bypasses text-based link scanners because the destination URL is encoded as an image rather than a clickable link; and shared-document, a QR code inside a shared PDF invoice or presentation that an employee is asked to scan for convenience. Each channel exploits a different point of trust: physical proximity, professional document formatting, or workplace habit.
Why QR Codes Slip Past the Instincts People Use for Email
Years of security awareness training have taught employees to hover over links, check the sender's domain, and look for spelling mistakes in a suspicious email. Every one of those instincts requires a visible target to inspect, and a QR code has none. The link is compressed into a pattern of black and white squares that a phone's camera decodes instantly, with most scanning apps showing, at best, a truncated preview URL that a user glances at for a fraction of a second before tapping open.
Quishing also benefits from a context-shift that email phishing does not get: QR codes are strongly associated with physical, real-world, already-trusted objects, a menu, a parking sign, a courier's delivery slip, a bank's own promotional poster. When the delivery channel itself feels legitimate, the code inherits that legitimacy in the victim's mind before they have evaluated the destination at all. This is the same trust-transfer principle that makes a phishing email spoofing a courier company effective, except QR codes add a physical, tangible layer of false credibility that a screen-based email never had.
Mobile scanning behavior compounds the problem. Most people scan QR codes on their personal phones, often outside any corporate mobile device management or web filtering, and the resulting browser session frequently has no antivirus or DNS-based phishing protection running at all. A QR code scanned on a personal device that then asks for a corporate single sign-on credential, because the phishing page is a convincing clone of the company's login portal, walks straight past every layer of protection the security team built into the corporate network.
Why Indonesia Is a Prime Target: QRIS, Parking, and Poster Culture
Indonesia has one of the highest rates of everyday QR code usage in the world, driven by QRIS, the Quick Response Code Indonesian Standard mandated by Bank Indonesia, which now sits on nearly every warung, parking attendant vest, restaurant table tent, and street vendor cart. Scanning a QR code to pay is now a completely unremarkable, multiple-times-a-day action for tens of millions of Indonesians, which means the population-level instinct to pause before scanning is close to zero. That is a gift to attackers: the single highest-friction moment in a quishing attack, getting someone to scan in the first place, has already been solved by years of legitimate QRIS adoption.
This creates specific, documented local attack patterns: fraudulent QRIS stickers physically pasted over legitimate merchant or parking QR codes that redirect payment to an attacker-controlled account, fake QR codes on printed flyers claiming to offer a government bantuan disbursement or BPJS refund that instead harvest banking credentials, and QR codes embedded in WhatsApp messages impersonating banks or e-commerce platforms asking customers to verify an account by scanning and logging in. Because QRIS itself is genuinely ubiquitous and safe when used correctly, employees and consumers have no learned signal that distinguishes a real merchant code from a tampered one.
For enterprises, the relevant risk surface is less customers paying at a warung and more the internal equivalent: QR codes on printed internal memos, visitor badges, meeting room booking posters, or vendor invoices that ask staff to scan to confirm attendance, access the Wi-Fi, or review the document. Any of those can be a quishing vector aimed squarely at employee credentials rather than consumer payments, and Indonesian offices that have normalized just scan the QR code for legitimate internal tools are exactly as exposed as consumers are at the parking gate.
How to Spot and Verify a QR Code Before You Scan
The single most reliable defense is to never scan a QR code and immediately proceed on autopilot. Most modern phone cameras show a preview of the destination URL before opening it; take the extra second to actually read that preview, check the domain against the organization it claims to be from, and be suspicious of shortened URLs, since a legitimate bank or vendor almost never needs to shorten its own domain in a printed or official QR code.
Physical QR codes deserve a visual inspection: a sticker that looks slightly misaligned, has a different finish or printing quality than the surface around it, or is clearly layered on top of another code, is a strong tampering signal, especially on parking meters, ATMs, and payment terminals in public spaces. When a QR code arrives digitally, whether in an email, a WhatsApp message, or a PDF, treat it with exactly the suspicion normally reserved for a link: verify the sender through a separate channel, never scan a code that arrives with urgency language such as a warning that your account will be suspended if you do not scan now, and never enter a password or one-time password on a page reached by scanning a code from an unsolicited message.
For anything involving payment or credentials, prefer navigating manually: open the bank's app directly rather than scanning a code that claims to be from the bank, or type a known-good URL rather than following a scanned one. Organizations should also formalize a simple reporting habit: if an employee is unsure about a QR code on a poster, an invoice, or an email, reporting it through the same phish-reporting channel used for suspicious emails should be normal, not something they have to figure out on their own.
How to Simulate Quishing Responsibly in a Training Program
Because quishing exploits a genuinely different instinct than email phishing, a security awareness program that only ever simulates email attacks leaves this entire category of risk untested. A responsible quishing simulation follows the same design principles as any phishing simulation: a realistic but clearly internally-authorized scenario, such as a fake scan-to-confirm-your-parking poster in the office pantry, a QR code in a simulated internal memo, or a QR embedded in a test email, a landing page that captures the click without harvesting real credentials, and immediate just-in-time training for anyone who scans and proceeds.
The scenario design should mirror the local lures that actually work: a QRIS-styled payment confirmation, a fake BPJS or government aid QR flyer, or a WhatsApp-delivered QR asking staff to verify their corporate account, run only against employees who have consented to being part of a training program and communicated in advance at the organizational level through HR and legal, exactly as any other phishing simulation should be. The goal is measuring and improving genuine behavior, never embarrassing or punishing individuals.
Track the same metrics as any other campaign: scan rate, proceed-past-warning rate, credential-submission rate, and report rate, and feed the results into the same risk-scoring and JIT training workflow used for email and vishing simulations, so a user who is vulnerable to quishing gets the same fast, targeted remediation as a user who clicks a phishing email. Over successive quarters, a genuinely effective program should show scan-and-proceed rates falling and report rates rising, the same behavior-change signal that matters for every other channel.
Key takeaways
- Quishing hides the destination URL inside an image, defeating the hover-and-inspect instinct email training relies on.
- Indonesia's QRIS-driven, multiple-times-a-day QR scanning habit means the highest-friction step of an attack, getting someone to scan, is already solved for attackers.
- Common local lures include tampered QRIS payment stickers, fake BPJS or bantuan flyers, and WhatsApp-delivered account verification QR codes.
- Always check the URL preview before opening, inspect physical stickers for tampering, and never enter credentials on a page reached by scanning an unsolicited code.
- Include QR-code scenarios in your phishing simulation program; email-only testing leaves this entire attack surface unmeasured.