Was ist Quishing (QR-Code-Phishing)?

Ein QR-Code kann so gefährlich sein wie ein dubioser Link — nur dass die URL im Bild steckt. So funktioniert Quishing und wie Sie sich schützen.

Was ist Quishing (QR-Code-Phishing)?

Dieser Guide ist auf Englisch verfasst. Titel und Kurztext oben sind lokalisiert.

Scanning a QR code feels as ordinary as tapping a link: menus, parking, badges, invoices. Attackers noticed. Quishing (QR + phishing) hides a malicious destination inside a QR image so victims open a fake login or payment page without ever seeing a blue underlined URL in email.

This guide explains how quishing works, why it slips past some defenses, who gets targeted, and practical habits that reduce your risk—without abandoning QR codes for legitimate uses.

What is quishing?

Quishing is phishing delivered through a QR code image. The payload is still a URL (or similar). The trick is packaging: instead of a visible hyperlink, the destination sits inside modules your camera decodes.

Related family members:

NameChannelTypical bait
PhishingEmail / webClickable text link
SmishingSMSText with a link
VishingVoice callSocial engineering over the phone
QuishingEmail images, PDFs, stickersQR that opens a hostile page

Two common delivery patterns show up again and again:

  1. Inbox lures — a QR embedded in an email body or PDF “invoice” that asks you to scan with your phone.
  2. Physical overlays — a sticker pasted over a real parking, menu, or lobby code.

How a typical attack unfolds

  1. Attacker encodes a hostile URL into a QR image.
  2. They place the image in email, a PDF, or on a sticker.
  3. Text-centric mail filters may not extract the URL from the image pixels.
  4. The victim scans with a personal phone (often outside corporate web filters).
  5. The phone browser opens a lookalike login or payment page.
  6. Credentials, cards, or malware drop follow.

The dangerous handoff is often laptop → personal phone. The email lands on a managed device; the scan happens on an unmanaged one.

Why traditional filters struggle

Industry reports in recent years have described sharp growth in QR-bearing phishing mail and a strong bias toward credential theft. Exact percentages change by vendor and year—treat the trend as real even if a single statistic ages.

Who is in the blast radius?

How to protect yourself

Creating codes without training bad habits

If you publish QR codes for a business, make the destination obvious in nearby text (“Official Wi‑Fi for Lobby Guests — make-a-qr.com sample”), keep HTTPS on pages you control, and avoid surprising people with login walls they did not expect. Generate static codes on Create when the URL is final, test with Decode, and print with high contrast.

FAQ

Are QR codes unsafe?

The pattern is just data. Risk comes from hostile destinations and social engineering—the same as links, with worse visibility.

Can I tell a bad QR by looking?

Not reliably. Always reveal the URL first. Sticker overlays and brand impersonation are easier to spot than a well-made fake image in email.

What should companies do?

Train staff on quishing, restrict who can request “scan to reset” flows, improve mail filtering that inspects images where possible, and give people a safe decode path that shows the URL before navigation.