QR Code Phishing (Quishing)
Pronunciation: Q-R code FISH-ing; KWISH-ing
Also known as: Quishing, Malicious QR phishing
Definition
QR code phishing, or quishing, uses a deceptive QR code to direct a person to a malicious site, payment address, application, credential prompt, or wallet action. It differs from ordinary link phishing mainly in delivery and visibility: the destination may be hidden until scanned and may move the victim from a managed computer to a less monitored mobile device. Operationally, teams should display and verify destinations, use trusted QR generation, protect printed and digital codes from replacement, and train users to inspect domains and payment details.
Overview
QR code phishing, or quishing, uses a deceptive QR code to direct a person to a malicious site, payment address, application, credential prompt, or wallet action.
QR Code Phishing (Quishing) is closely connected to Phishing Simulation, Permit Phishing, and Payment Page Script Attack. It differs from ordinary link phishing mainly in delivery and visibility: the destination may be hidden until scanned and may move the victim from a managed computer to a less monitored mobile device.
Operational implementation should display and verify destinations, use trusted QR generation, protect printed and digital codes from replacement, train users to inspect domains and payment details, restrict unknown apps, and provide simple reporting channels.
The principal failure modes include sticker replacement, fake login pages, malicious wallet deep links, payment-address substitution, device-management bypass, shortened destinations, and user trust in codes displayed in physical locations.
Useful measures include reported malicious codes, QR destination blocks, payment mismatches, training detection rate, and time to remove replaced codes.
Operationally, teams should display and verify destinations, use trusted QR generation, protect printed and digital codes from replacement, and train users to inspect domains and payment details. Key risks include sticker replacement, fake login pages, malicious wallet deep links, and payment-address substitution.
Operational review of QR Code Phishing (Quishing) should reconstruct the use of a deceptive QR code to direct a person to a malicious site, payment address, application, credential prompt, or wallet action using the identities, communications, devices, and transaction records available for the affected case. Investigators should separate confirmed facts from hypotheses about payment address, application, and credential prompt, preserve the original evidence, and document why the event was cleared, escalated, or treated as a loss. Containment, recovery, and customer communication for the QR Code Phishing context should match the harm indicated by payment address, application, and credential prompt.
Key Takeaway
QR code phishing, or quishing, uses a deceptive QR code to direct a person to a malicious site, payment address, application, credential prompt, or wallet action.
Sources
- Phishing Guidance: Stopping the Attack Cycle at Phase One — Cybersecurity and Infrastructure Security Agency (2026-08-03)
- Digital Identity Guidelines: Authentication and Authenticator Management, NIST SP 800-63B-4 — NIST (2026-08-03)
- OWASP Client-Side Security Top 10 — OWASP (2026-08-03)