Ein QR-Code kann so gefährlich sein wie ein dubioser Link — nur dass die URL im Bild steckt. So funktioniert Quishing und wie Sie sich schützen.

Dieser Guide ist auf Englisch verfasst. Titel und Kurztext oben sind lokalisiert.
Scanning a QR code feels as ordinary as tapping a link: menus, parking, badges, invoices. Attackers noticed. Quishing (QR + phishing) hides a malicious destination inside a QR image so victims open a fake login or payment page without ever seeing a blue underlined URL in email.
This guide explains how quishing works, why it slips past some defenses, who gets targeted, and practical habits that reduce your risk—without abandoning QR codes for legitimate uses.
Quishing is phishing delivered through a QR code image. The payload is still a URL (or similar). The trick is packaging: instead of a visible hyperlink, the destination sits inside modules your camera decodes.
Related family members:
| Name | Channel | Typical bait |
|---|---|---|
| Phishing | Email / web | Clickable text link |
| Smishing | SMS | Text with a link |
| Vishing | Voice call | Social engineering over the phone |
| Quishing | Email images, PDFs, stickers | QR that opens a hostile page |
Two common delivery patterns show up again and again:
The dangerous handoff is often laptop → personal phone. The email lands on a managed device; the scan happens on an unmanaged one.
Industry reports in recent years have described sharp growth in QR-bearing phishing mail and a strong bias toward credential theft. Exact percentages change by vendor and year—treat the trend as real even if a single statistic ages.
If you publish QR codes for a business, make the destination obvious in nearby text (“Official Wi‑Fi for Lobby Guests — make-a-qr.com sample”), keep HTTPS on pages you control, and avoid surprising people with login walls they did not expect. Generate static codes on Create when the URL is final, test with Decode, and print with high contrast.
The pattern is just data. Risk comes from hostile destinations and social engineering—the same as links, with worse visibility.
Not reliably. Always reveal the URL first. Sticker overlays and brand impersonation are easier to spot than a well-made fake image in email.
Train staff on quishing, restrict who can request “scan to reset” flows, improve mail filtering that inspects images where possible, and give people a safe decode path that shows the URL before navigation.