What is Quishing? (QR Code Phishing)
Published: 10/26/2026
Written by: Brenda Buckman
On This Page
FAQs about quishing
No. Quishing is a type of phishing that uses QR codes as the attack method.
Yes. A QR code can lead to:
Malware downloads
Malicious app installs
Credential harvesting pages
The QR code itself isn't dangerous, but the site it takes you to can be!
QR codes hide the URL and push the attack onto mobile devices, which often lack business security protections.
Sometimes, but many tools struggle because the malicious link is embedded inside an image, not text.
Common targets include:
Financial services
Healthcare
Logistics and shipping
SaaS and cloud users
IT teams
Yes. Attackers increasingly use QR codes to steal Microsoft 365 and Google Workspace credentials, leading to BEC attacks.
Security awareness training should teach users to:
Treat QR codes like links
Verify requests through trusted channels
Avoid scanning codes from emails or letters
Only scan QR codes from trusted sources and always verify the URL before entering credentials or payment details.