Quishing is QR-code phishing – a cyber attack where criminals use malicious QR codes to trick you into visiting fake websites, entering credentials, or downloading malware. The term combines QR + phishing.
What quishing actually is
Quishing is now a common tactic for stealing Microsoft 365 credentials, often through fake “MFA expired – scan to re‑authenticate” emails. Scanning the QR code sends users straight to a fraudulent login page on their mobile device, bypassing desktop‑based protections — a weakness attackers deliberately exploit because they know IT admins frequently authenticate on their phones.
Quishing uses a QR code instead of a normal clickable link. When you scan it, you may be taken to a fake login page — such as Microsoft 365, your bank or HMRC — or redirected to a malicious payment site, a malware download, or a subscription scam.
Because you can’t preview a QR code’s URL before scanning, attackers use it to hide the real destination and slip past many email security filters.
Why quishing works so well
- QR codes feel trustworthy – menus, parking meters, delivery notices.
- As previously discussed the URL is hidden until after scanning.
- Scanning happens on mobiles, often with weaker protection.
- Email getaways treat QR codes as images, so malicious URL’s slip through.
Common quishing scams
- Fake parking meter QR codes that steal card details.
- Fake restaurants menu QR codes that redirect you to phishing pages.
- Delivery notices taped to doors asking you to ‘scan to reschedule’.
- Fake Microsoft 365 re-authentication QR codes that leads to credential theft.
- Fake refunds/offers that creates a subscription trap.
How to protect yourself
- Don’t scan QR codes from unexpected emails or printed flyers.
- Check the physical code by looking for stickers place over the original QR code.
- After scanning, inspect the URL before entering anything.
- Never enter credentials on a site opened from a QR code unless you’re 100% sure it’s legitimate.
- Use mobile security apps that preview URL’s before opening.
