6 minutes reading time

Quishing: Why QR-Code Phishing Slips Past Filters and How to Stop It

QR-code phishing (quishing) leaves no URL to scan and moves the attack to personal phones. Why it exploded, its scenarios, and how visual-content analysis stops it.

An email "from the IT department" landed with a company's HR team: "Your multi-factor authentication (MFA) is expiring. Scan the QR code below with your phone to renew it." There was no link to click anywhere in the email; just a polished corporate template with a QR code in the middle. Three employees scanned it with their phones and typed their usernames and passwords into the "Microsoft sign-in" page that opened. The attacker accessed all three accounts the same day.

This attack is called quishing — the fusion of QR (quick response) codes and phishing. It's one of the fastest-growing email attack vectors of the past two years, and its most frustrating property is this: it lives in a blind spot that classic URL filters cannot see. In this article we explain why quishing is so effective, the scenarios it arrives in, and how to stop it.

 


 

1. Why Does Quishing Slip Past Filters?

 

Traditional email security scans the links in text: it extracts the URL, compares it against reputation databases, rewrites it if needed (Safe Links-style click-time protection). Quishing breaks this chain in a single move because there is no URL in the email to scan — the URL is embedded inside an image (the QR code).

And a second blind spot kicks in: the user scans the QR not with the corporate computer but with a personal phone. The phone is usually entirely outside the company network, the proxy, and endpoint protection. The attack thus transports itself to the least-defended device — and has the victim do the transporting.

 

2. Three Quishing Scenarios We See in the Field

 

2.1 "Your MFA Is Expiring" — Credential Harvesting

 

The most common form. An email styled as "IT department" or "Microsoft" presents a QR code under the pretext of MFA renewal or password verification. The code leads to a sign-in page that closely mimics the real one. Entered credentials flow instantly to the attacker; some advanced kits also steal the session cookie, bypassing MFA entirely (adversary-in-the-middle).

 

2.2 Fake Invoice / Payment QR

 

An invoice-styled PDF or a "scan to pay" QR in the email body. Especially effective at companies whose field teams work on mobile devices. The QR goes to a fake payment page or a form harvesting bank details.

 

2.3 The Physical-Digital Hybrid: Event and Parcel Notifications

 

"Your parcel couldn't be delivered — scan to reschedule," "QR for your event badge." Employees' daily habit of scanning QR codes has become so ingrained that the suspicion reflex is nearly gone. Attackers exploit exactly this habit.

 

3. Why Did It Explode Now?

 

Three factors converged. First, post-pandemic QR use (menus, payments, check-ins) became a daily reflex; "see a QR, scan it" got normalized. Second, email security products got so good at URL scanning that attackers abandoned links and fled into images — quishing is a by-product of the defense's success. Third, ready-made quishing kits got cheap on dark markets; a campaign can be built with no technical skill.

 

4. Defense: Visual-Content Analysis + Mobile + People

 

Technology: A Layer That Sees the QR

 

The only reliable way to stop quishing is a protection layer that also analyzes the images in email. Check Point Harmony Email & Collaboration does the following here:

  • Automatically decodes QR codes in email — extracts the URL inside the image.
  • Scans the extracted URL in real time via ThreatCloud AI; flags newly registered domains, phishing kits, and redirect chains.
  • If malicious, blocks the email before it reaches the inbox (inline) or pulls it back if delivered (detect & remediate).
  • Because it scans all inbound and outbound email, it also sees QR attacks sent internally from a compromised account. For the architectural difference, see our API vs Gateway article.

 

Mobile: Don't Leave the Phone Undefended

 

Because quishing's final step happens on the phone, mobile protection is the critical complement. A solution like Harmony Mobile blocks the phishing page at the device level — a second line for the rare cases that get past the email layer.

 

People: The One-Sentence Rule

 

The message to teams should be short: "A QR code arriving by email carries the same risk as a clickable link — approach it with the same suspicion before scanning." It should be announced as company policy that MFA renewal or password verification will never be requested via QR.

 


 

Frequently Asked Questions

 

Doesn't Microsoft 365's protection catch quishing at all?

 

Microsoft has begun adding in-image QR analysis; however, its performance is still uneven and advanced kits (redirect chains, single-use URLs) frequently evade it. You can measure what the built-in protection misses in your own environment with a 14-day monitor-mode trial. For the general architectural limits, see our why Microsoft 365 falls short article.

 

Our employees scan QRs with personal phones — what can we do as a company?

 

Two things: cut the attack at the email layer before it reaches the phone (QR decode + URL analysis), and add mobile threat protection to phones with corporate access. If you have a BYOD policy, mobile protection matters even more.

 

Will our legitimate QR-code emails get blocked too?

 

No. The analysis evaluates the destination URL, not the QR itself. A legitimate event or payment QR is delivered normally if its destination is clean.

 

We experienced a quishing attempt — what should we do?

 

Immediately reset the passwords of users who scanned the code, terminate their sessions, re-enroll MFA, and check their inboxes for unauthorized mailbox rules. Then scan the environment to determine whether the same campaign reached other users — we can support you through this process.

 


 

What Should You Do Now?

 

If your teams scan QR codes arriving by email and your current protection doesn't perform visual-content analysis, you have an open blind spot.

  1. Free Field Audit: We report your current protection's QR/visual analysis capability and your overall email security posture.
  2. 14-Day Check Point Trial (monitor mode): We report the quishing attempts passing through your environment, without touching anything.

 

Schedule an intro meeting

 


 

About this article: Kinetik Bilişim is the Türkiye partner of Check Point Software Technologies at the Advanced Partner 2026 level, holding Email, Endpoint & Browser, Mobile, and SASE Solution Specialization accreditations. The author, Kemal Özleyen, is a cybersecurity engineer certified as a Check Point Workspace Security Expert. Field scenarios are shared in anonymized form.