Quishing has turn into a preferred various to conventional phishing. Right here’s how companies can shut the hole.
17 Aug 2026
•
,
5 min. learn

Familiarity would possibly breed contempt. However on this planet of cybersecurity, it additionally breeds complacency, which generally is a lot extra harmful. So it’s with QR codes, which have turn into a typical sight on menus, lampposts and parking meters – and, more and more, in emails over current years. The problem is that they’re additionally an effective way to disguise malicious hyperlinks, bypass some conventional company safety filters, and to maneuver the interplay from a company pc to a private cellphone with fewer safety controls.
Attackers will proceed to experiment and innovate with new methods to keep away from detection. And new “quishing” methods to snare unwitting workers. Right here’s what it’s essential to perceive to maintain your group secure.
Why is quishing so harmful?
Brief for ‘Fast Response’, a QR code is a two-dimensional barcode that may encode URLs, fee particulars, contact data and different information, serving to customers get shortly from A to B – the vacation spot on this case normally being an internet site or app. They enchantment to risk actors for a number of causes. Their widespread use, accelerated by the demand for contactless interactions through the pandemic, has made scanning them an strange a part of each day life. Which means we’re extra prone to get our telephones out to scan them right now than a number of years again.
Additionally they slot neatly into phishing workflows – simply substitute that malicious hyperlink or attachment with a QR code. And they are often generated in seconds. The truth is, many phishing kits could have a devoted QR-code generator. Most significantly, they take the sufferer from a comparatively well-protected company setting to a probably unmanaged cellular gadget, thus bypassing business-grade safety.
One vital benefit for the attacker is concealment. The vacation spot is encoded in a visible sample, not displayed as readable textual content, which hides the malicious URLs behind them in order that some conventional e-mail filters can’t extract and examine them. Typically they’re additional obfuscated by being embedded in PDF or JPEG attachments. Which means they’re extra prone to find yourself in your workers’ inboxes. And once they do, your employees could wrestle to discern an actual message from a malicious one. There’s sometimes not a lot textual content to research for typos or grammatical errors. And since the hyperlink is successfully encoded in a visible sample, it’s invisible to the human eye.
If used at the side of a trusted model – say, a DocuSign e-mail or an replace from Microsoft – the quishing assault leverages comparable social engineering techniques as basic phishing messages. Trusted branding reassures the sufferer that they will click on via. And a way of urgency is usually created by the pretext. Malicious QR codes are continuously embedded in alerts urging customers to safe their account, or authenticate to verify their particulars.
The truth is, in response to the ESET Risk Report H1 2026, malicious QR codes have been embedded in no fewer than 11 % of all phishing e-mail within the first half of 2026. “ESET tracks quishing emails beneath the detection identify QRCode/Phishing. This detection works via a devoted layer of the ESET e-mail scanner, designed to establish QR codes within the overwhelming majority of file sorts, and to decode the URLs in them. The extracted URLs are scanned utilizing ESET anti-phishing, anti-malware, and anti-spam engines; any dangerous URLs are blocked, and the related emails flagged or deleted,” says the report.

Risk actors proceed to innovate
As with every risk panorama pattern, malicious actors proceed to hone their efforts for optimum affect. Quishing assaults are getting used not solely to put in malware and steal credentials but in addition harvest MFA tokens. Safety researchers have additionally seen them in assaults designed to:
- Bypass app retailer safety via direct app downloads the place malware is disguised as professional apps
- Take the consumer to not a malicious/phishing web site however hyperlink on to a professional social media, fee or different app. This could possibly be utilized in numerous situations akin to:
- Account takeover, the place the sufferer is directed to authenticate the attacker of their account
- Monetary fraud, the place the sufferer is directed to a fee app with pre-filled payee data
- Contact/calendar poisoning, the place malicious assembly hyperlinks or new contact data are embedded in utility apps and redirect customers to phishing websites when clicked on
- Malicious Wi-Fi, which the sufferer is routinely linked to a risk actor’s rogue entry level
- Obfuscate safety instruments by utilizing QR code shorteners, which convert lengthy, malicious internet addresses to small hyperlinks and embed them in QR codes

Even state-sponsored APT teams are utilizing quishing as a part of their tradecraft. An FBI discover from January 2026 warned that the North Korean Kimsuky outfit focused suppose tanks, educational establishments, and US/international authorities entities with embedded QR codes in spearphishing emails. The lures different. The emails in query variously claimed that scanning the code would lead customers to questionnaires, registration touchdown pages, and safe drives.
Maintaining your enterprise secure from QR phishing
Luckily, a well-judged mix of individuals, course of and expertise changes may also help to drastically cut back the quishing danger to your group.
Begin with folks. Construct quishing into consumer consciousness coaching programs and simulation workout routines. Encourage workers to keep away from scanning QR codes in unsolicited emails and report something suspicious. In the event that they consider it’s from a trusted supply, they need to test again with the sender, utilizing contact particulars sourced individually from the e-mail.
Subsequent, contemplate technical controls, together with e-mail safety from a good vendor to attenuate the danger of quishing emails ending up in customers’ inboxes. Add a cellular safety answer to worker gadgets to dam entry to malicious websites and different threats. And require phishing-resistant multi-factor authentication (MFA) on all delicate accounts, in order that even when customers are tricked, adversaries received’t be capable of achieve a foothold into company techniques. Cellular gadget administration (MDM) instruments may also help you to make sure all gadgets are protected in keeping with company coverage.
Cut back the assault floor, implement least privilege and just-in-time entry. Preserve all cellular working techniques and company software program updated – together with your safety instruments. And conduct steady monitoring for suspicious exercise. Follow incident response plans within the occasion of a worst-case situation.
A novelty no extra
QR codes have developed from one thing of a novelty to a daily sight within the enterprise. And so has quishing. Familiarity needn’t breed complacency. Simply as employees have grown used to being suspicious of conventional e-mail and SMS-based phishing, they are often educated to identify the warnings indicators of a attainable quishing try. Underneath the fitting circumstances, familiarity can construct safety.









