Blog Layout

Explained: Quishing

Anthony Regina • Oct 15, 2023

Explained: Quishing

Quishing is phishing using QR (Quick Response) codes. QR codes are basically two-dimensional barcodes that hold encoded data, and they can be used to work as a link. Point your phone's camera at a QR code and it will ask you if you want to visit the link.

The use of QR codes in malicious campaigns is not new, and because they can provide contactless access to a product or service they grew in popularity during the Covid-19 pandemic.


In August, 2023 we wrote about an email campaign that used QR codes to phish for Microsoft credentials. The links in the QR codes redirected from legitimate domains associated with Bing, Salesforce, and Cloudflare to send the targets to phishing sites that were after Microsoft credentials. Since the subject of the emails were often fake Microsoft security notifications, the Bing URLs would not have looked out of place to any victims who gave them a cursory examination.


Lately, there has been an increase in quishing emails, which either send victims to malware-infested sites or ones looking for credentials. 


The usual methods are used to make the emails look convincing: The email will pretend to come from a bank or another organization you trust, or might look like internal mails from the organization you work for, perhaps pretending to come from HR or the IT department. The QR codes in these mails are either embedded or sent as an attachment.

Most of the email contains little to no text, which reduces the chances of the scammer making a mistake and gives spam filters less to read. The message is displayed in an image, which also helps the email get through spam filters.



As you can see, a lot of the normal signs by which we can recognize a phishing mail are there:

  • Urgency
  • A link leading to a site to fill out personal information
  • Sloppy lay-out of the mailNew Paragraph


The QR code contained a link to the lihi1.com URL shortener which pointed me to a clone of the KVK site.

It asks for name, birth date, address, mobile phone number, my KVK registration number and bank account number. A successful phisher can probably sell that data for a few bucks on the dark web.


To stay safe from quishing, you can follow the same advice we provide for phishing, because that’s what it is. It's just that the method to obfuscate the phishing site is a bit more sophisticated, which also makes the use of it more suspicious.

One extra measure you can take is to install a QR code scanner that doesn’t take you to the destination in the URL, but displays it for you, so you can decide whether you want to proceed.


Stay alert for hallmarks of phishing campaigns, such as a sense of urgency, appeals to your emotions. Be extremely wary if a QR code takes you to a site that asks for personal information, login credentials or payment.


By Anthony Regina 07 Dec, 2023
New And Urgent Bank Account Fraud Alert
By Anthony Regina 02 Nov, 2023
Cybersecurity Awareness Month draws to a close and Halloween is just around the corner, so here is a bunch of spine-tingling figures about some very real tricks and threats lurking online
Women in Cybersecurity
By Anthony Regina 02 Nov, 2023
Global Diversity Awareness Month is a timely occasion to reflect on the steps required to remove the obstacles to women's participation in the security industry, as well as to consider the value of inclusion and diversity in the security workforce.
By Anthony Regina 25 Oct, 2023
Should you sign in with Google or Facebook on other websites?
By Anthony Regina 14 Oct, 2023
Your preparedness to deal with cyberattacks is key for lessening the impact of a successful incident – even in home and small business environments
By websitebuilder 14 Oct, 2023
One of the biggest threats to watch out for on social media is fraud perpetrated by people who aren’t who they claim to be. Here’s how to recognize them.
By websitebuilder 14 Oct, 2023
Phishing emails are a weapon of choice for criminals' intent on stealing people’s personal data and planting malware on their devices. The healing process does not end with antivirus scanning.
By websitebuilder 14 Oct, 2023
Plus, 7 ways to tell that you downloaded a sketchy app and 7 tips for staying safe from mobile security threats in the future
More Posts
Share by: