Threats & Social EngineeringBeginnerThreat1 validated evidence record

QR Code Phishing

Also known as: Quishing

30 sec

A phishing technique that uses a QR code to hide or simplify navigation to a malicious destination.

Know

What is QR Code Phishing?

A phishing technique that uses a QR code to hide or simplify navigation to a malicious destination. In practice, qr code phishing should be understood in the context of the identities, systems, applications, data, trust relationships, and business processes it affects. The useful question is not only what the term means, but how it changes attacker capability or defensive control.

Why it matters

A phishing technique that uses a QR code to hide or simplify navigation to a malicious destination. Attackers can use this behavior to turn a single weakness, identity, or interaction into broader compromise, so defenders need to recognize both the mechanism and the business consequence.

Evidence, not hype

Validated in the real world

Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.

Government / AuthoritativeGovernment advisory

CISA validates phishing as a cross-channel social-engineering risk

2026CISACross-sector

CISA guidance treats phishing as a social-engineering problem that can use deceptive messages, links, identity cues, and multiple communication channels to steal access or manipulate users. The defensive guidance emphasizes recognition, independent verification, reporting, and stronger authentication.

Why this is evidence

It provides a government-backed baseline for targeted phishing, SMS/QR variants, credential theft, spoofing, lookalike-domain abuse, and pressure against authentication workflows.

See the source — CISA: Recognize and Report Phishing

Understand the mechanics

How it works

  1. 1

    An adversary identifies a condition where qr code phishing can provide access, control, information, or evasion.

  2. 2

    The attacker executes the technique directly or combines it with credentials, social engineering, exploitation, or trusted tools.

  3. 3

    Successful activity creates a new capability such as access, execution, persistence, privilege, movement, collection, or impact.

  4. 4

    Defenders investigate the surrounding identity, host, application, network, and cloud telemetry to determine scope and interrupt the attack chain.

Practice

What to watch for

  • Activity consistent with qr code phishing in identity, endpoint, email, application, cloud, or network telemetry
  • Unexpected authentication, privilege, execution, or data-access behavior
  • New or unusual infrastructure, domains, processes, tokens, or administrative actions
  • A sequence of events that matches a known adversary technique rather than normal business activity

Perform

What to do

  1. 1

    Stop or contain the risky activity without destroying useful evidence.

  2. 2

    Determine which identities, systems, applications, data, and sessions are affected.

  3. 3

    Revoke exposed access, isolate compromised assets, and block malicious infrastructure as appropriate.

  4. 4

    Hunt for related qr code phishing activity and adjacent attacker behaviors before declaring the incident contained.

How to reduce the risk

  • Use independent verification for sensitive requests.
  • Deploy phishing-resistant authentication where possible.
  • Make suspicious-message reporting easy and fast.
  • Train by role using realistic examples rather than generic awareness only.

Business impact

  • Account compromise
  • Fraud or unauthorized payments
  • Malware execution
  • Sensitive-data disclosure

What different roles should do

Employee / Operator

  • Pause when an interaction or system behavior is unexpected.
  • Use approved verification and reporting paths rather than improvising.

Security

  • Correlate identity, endpoint, network, application, and cloud evidence.
  • Contain the attack path and hunt for follow-on activity.

Framework & standards context

  • NIST Cybersecurity Framework (CSF) 2.0

Keep learning

Source transparency

Authoritative sources

Last reviewed: 2026-09-02