Security filters have spent a decade getting good at one thing: reading URLs. They follow links in email, detonate them in sandboxes, compare domains against reputation lists, and quarantine the ones that look wrong. So attackers stopped putting links in the email. They started putting them in a QR code, a block of pixels no text scanner ever parses. The industry calls it quishing, and since roughly 2023 it has moved from novelty to one of the more reliable delivery tricks in the phishing playbook.
Why the codes get through
A QR code in an email attachment or embedded image is just pixels. Traditional email gateways historically did not decode images looking for URLs, so the malicious destination never appears as clickable text. The victim scans with their phone camera, which opens the link in the phone’s browser, outside every corporate proxy, every DNS filter, and every logged endpoint control. The attack deliberately moves the click from a managed laptop to an unmanaged phone. From the attacker’s side it is also better telemetry: the scan happens at a time and place of the victim’s choosing, and a QR code printed on a fake parking sign or stuck over a restaurant terminal’s real one works with no email at all.
Common 2026 lures: a package delivery rescheduling fee, a shared document that “expires today,” a multi-factor authentication re-enrollment prompt, and utility or road-toll invoices. The MFA one is the sharpest, because it arrives right after a real password compromise and points to a fake login page that harvests the one code that was supposed to be the last line of defense.
What the codes actually contain
Almost every malicious QR code encodes an ordinary HTTPS URL. A few nastier variants encode a javascript: URI or a deep link into a payment app, but the overwhelming majority just route to a credential page that mimics Microsoft, DHL, or a bank. Attackers favor freshly registered domains, sometimes with a legitimate lookalike spelling, sometimes hosted on a compromised real site with the phishing kit buried in an unused path. The freshness matters: reputation lists have never seen the domain, so even filters that do decode the code often let it through on first contact.
A worked example
Take the classic delivery lure, because it shows every moving part at once. The email arrives with no links in the body at all, just an image of a parcel and a code, plus two lines of text about a customs fee of 1.99 that must be paid within 24 hours or the parcel returns to sender. The fee is small on purpose, small enough that paying feels easier than thinking. Scanning takes the victim to a page hosted on a domain registered nine days earlier, visually identical to the courier’s, which asks for name, address, card number, expiry, CVC, and then, a screen later, the one-time code texted by the real bank. By the time the second screen appears, the card is already compromised and the code request is the attacker beating the bank’s fraud check in real time. The victim’s phone shows the real bank’s sender string, because the SMS genuinely comes from the bank. Everything about the flow looks legitimate at each individual step, which is precisely why it works.
What organizations can actually configure
On the defense side, the options have improved. Modern secure email gateways now decode QR codes in attachments and inline images and treat the embedded URL like any other link, subject to detonation and reputation checks. Conditional access policies that block logins from unmanaged devices into the MFA re-enrollment flow cut off the most damaging variant at the knee. And training that tells users “never scan a code from an email” fails, because legitimate emails now contain QR codes constantly, from boarding passes to restaurant menus. The instruction that survives contact with reality is narrower: read the preview, check the domain against the service you actually use, and never type credentials or one-time codes into a page you reached through a camera.
Reading a code before you scan it
Phone cameras show a preview of the URL before opening it. That half-second is the whole defense. Check the domain, not the page it points to. A real Microsoft login lives on login.microsoftonline.com, not microsoft-secure-login.net. If the preview shows a URL shortener, treat that as a refusal to tell you the destination, which is itself an answer. Several free decoder apps and even desktop tools will decode a photographed QR to plain text without ever loading anything, which is how you should inspect any code you did not generate yourself. And be suspicious of urgency mechanics: fees that triple in 24 hours, documents that expire at midnight, accounts that close today.
Physical codes deserve the same caution. A sticker placed over the legitimate QR on a parking meter, an EV charger, or a restaurant table-order code is a known scam pattern in most large cities. If a payment page appears after scanning a public code and the URL does not match the operator’s printed branding, pay at the counter instead.
Why phones are the weak endpoint
The scan lands on the device least likely to have a filtering DNS or a managed browser. Personal phones used for work mail compound this, since the phishing page opens where no corporate tooling watches. The practical mitigations are unglamorous: treat the camera preview as a mandatory checkpoint, never enter credentials on a page reached only via QR, and put a blocking DNS resolver on phones so at least known-bad domains fail even after the scan. None of this replaces reading the URL. It is the one habit that survives every new lure, the same core skill behind spotting SIM swap attacks that hijack your number and recognizing the infrastructure described in how rogue Wi-Fi hotspots capture traffic.
Quishing works because it splits the attack across two devices and trusts that nobody inspects the seam. Inspect the seam. The preview screen is the cheapest security control you own.




Leave a Reply