Quishing: QR code phishing and why filters miss it
QR codes hide malicious URLs inside images, out of reach of many link scanners. How quishing works, why it evades filters and what defenses help.

On this page(6 sections)
- How a quishing attack works
- Why it slips past filters
- The URL is not text
- Evasion techniques
- The phone is outside your controls
- Defenses that help
- 1. Make sure your filtering decodes QR codes
- 2. Treat QR codes in internal-looking mail as suspicious
- 3. Use phishing-resistant authentication
- 4. Protect mobile devices where you can
- 5. Train with real examples
- What legitimate senders should do
- A quick checklist
- Key takeaways
A phishing email with a link has to get that link past a scanner. A phishing email with a QR code only has to get an image past it, and then persuade someone to point a phone at the screen.
That small change is why QR code phishing, often called quishing, became a staple of credential theft campaigns.
How a quishing attack works
The typical message impersonates something routine and slightly urgent:
- "Your multi-factor authentication needs to be re-enrolled. Scan to continue."
- "A document has been shared with you. Scan to view."
- "Your mailbox password expires today."
- "Payroll update: confirm your direct deposit details."
The body contains a QR code, sometimes as an inline image, sometimes as an attachment, and sometimes inside a PDF. The QR code encodes a URL that leads, often through several redirects, to a convincing login page. The victim scans it with their phone, lands on a page that looks like their company's sign-in screen, and enters their credentials and sometimes a one-time code.
Why it slips past filters
The URL is not text
Email security products inspect URLs in message bodies: they check them against reputation lists, rewrite them for click-time analysis, and sometimes visit them in a sandbox. A QR code is a picture. To inspect the URL inside it, the filter must first find the image, decode the QR code, and then apply the same URL checks. Many products have added QR decoding, but attackers respond by making codes harder to detect.
Evasion techniques
Common tricks include:
- Rendering the code with HTML tables or text characters instead of an image, so image-based decoders miss it.
- Splitting the code into several images placed side by side.
- Embedding it in a PDF or other attachment that requires deeper inspection.
- Low contrast, unusual colors or added noise that humans can scan but naive decoders cannot.
- Redirect chains and legitimate services, such as open redirects on well-known sites, so the first URL looks harmless.
The phone is outside your controls
The most important reason is not technical cleverness. The scan happens on a personal or mobile device, which often lacks the web filtering, endpoint protection and managed browser that protect a work laptop. The user also sees less of the URL on a small screen, and is used to scanning QR codes for menus and parking payments without much thought.
Defenses that help
1. Make sure your filtering decodes QR codes
Ask your email security provider directly whether it decodes QR codes in inline images, attachments and PDFs, and what it does with the resulting URLs. If it does, confirm it is enabled. Test with a harmless internal QR code pointing to a known test page and see whether the URL appears in logs or detections.
2. Treat QR codes in internal-looking mail as suspicious
Legitimate IT and HR teams rarely need you to scan a QR code from an email to sign in. Make that a stated policy: "We will never ask you to scan a code in an email to re-enroll MFA or reset a password." A clear rule turns a judgment call into a simple pattern match for employees.
3. Use phishing-resistant authentication
Quishing pages usually harvest a password plus a one-time code, then replay them in real time. Phishing-resistant methods, such as passkeys and hardware security keys based on WebAuthn, are bound to the legitimate site's origin and will not authenticate to a lookalike page. They are the strongest technical answer to credential phishing of any kind, including quishing.
4. Protect mobile devices where you can
If staff access work accounts from phones, mobile device management, managed browsers or DNS-based filtering on those devices can block known phishing domains after the scan. This is uneven on personal devices, which is why the authentication and policy layers matter more.
5. Train with real examples
Show staff what quishing messages look like, including codes rendered from text or embedded in PDFs. Emphasize two habits: check the URL preview your camera app shows before opening it, and never enter work credentials on a page reached by scanning an email.
What legitimate senders should do
If your organization uses QR codes in email, for event tickets, boarding passes or in-store offers, you are teaching recipients that scanning codes from email is normal. A few practices reduce the risk you create:
- Never use QR codes for login or account actions. Use a normal, visible link to your known domain.
- Point codes at your own primary domain, not a third-party shortener, so the preview shows a recognizable address.
- Always include a text link alternative next to the code.
- Authenticate your mail fully, with DMARC at enforcement, so impersonation of your exact domain fails.
A quick checklist
| Control | Owner | Status to check |
|---|---|---|
| QR decoding in email filtering | Security / IT | Enabled for images, attachments, PDFs |
| "We never ask you to scan to log in" policy | IT / HR | Published and repeated in training |
| Phishing-resistant MFA | IT | Rolled out to high-risk roles first |
| Mobile protections | IT | Managed devices and browsers where feasible |
| Reporting button | Security | Staff can report suspicious mail in one click |
| Outbound QR usage | Marketing / product | No login codes; own domain; text link included |
Key takeaways
- Quishing hides the phishing URL inside an image, which many link scanners do not decode by default.
- Attackers evade decoders with text-rendered, split or PDF-embedded codes and redirect chains.
- The scan moves the attack to a mobile device with fewer protections.
- Phishing-resistant authentication defeats the credential theft that most quishing aims for.
- Clear policies and better filtering reduce exposure; legitimate senders should avoid QR codes for anything account-related.
Start with Koltrix
Your domain, one inbox, and an API that sends.
A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.

