Quishing: Why QR Codes Are Becoming a New Cybersecurity Risk
QR codes have become part of everyday life. We scan them to view restaurant menus, pay invoices, check in at events, download apps, verify accounts and access information faster. They are simple, convenient and familiar, which is exactly why cybercriminals are now using them as a new doorway into business systems.
This growing threat is called quishing, which is short for QR code phishing. Like traditional phishing, the goal is to trick someone into giving away sensitive information. The difference is that the attack starts with a QR code instead of a suspicious link. According to the attached Barracuda infographic, quishing is an evolution of phishing attacks, and recent Barracuda research found that around 1 in 20 email accounts were targeted with QR code attacks in the last quarter of 2023.
That number should make every business pause.
Why QR Codes Are So Appealing to Cybercriminals 
QR codes work because people trust them. They feel routine and low-risk. We are used to seeing them on posters, invoices, emails, packaging, payment portals and even inside office lobbies. Most of us scan first and think second.
Cybercriminals know this.
A quishing attack may arrive in what looks like a legitimate email from a vendor, bank, software provider or internal department. Instead of asking the recipient to click a link, the message asks them to scan a QR code to verify their account, review a document, make a payment or reset a password.
Once scanned, the QR code sends the user to a spoofed website that may look almost identical to a real login page. The victim enters their username, password or payment details, and the attacker captures that information.
From there, the damage can spread quickly.
Why Quishing Can Be Harder to Catch
Traditional phishing filters are built to inspect links, attachments and suspicious email content. QR codes create a different challenge because the malicious destination may be hidden inside an image. That means some email security tools may not immediately recognize where the QR code leads.
The infographic also notes that some quishing emails contain no clickable link at all. The message may simply tell the user to scan the image with their phone. This can move the interaction outside the company’s protected network and onto a personal device, where the same security controls may not apply.
That is what makes quishing especially concerning for businesses. It blends a familiar behavior with a security blind spot.
Where Quishing Attacks Show Up
Quishing codes can appear in several places, including:
- Spoofed emails that appear to come from trusted companies or internal departments
- Fake payment portals requesting invoice review or payment confirmation
- Posters or public materials where a legitimate QR code has been replaced or covered
- Account verification requests designed to create urgency
- Event check-in or registration scams that mimic trusted organizations
The common thread is trust. The QR code does not need to look suspicious. It just needs to appear in the right context.
How Businesses Can Reduce the Risk
The best protection starts with awareness. Employees should be trained to treat QR codes with the same caution they apply to links and attachments.
Before scanning, users should ask: Does this request make sense? Was I expecting this message? Is the sender legitimate? Is there urgency or pressure to act quickly?
Businesses can also strengthen defenses by blocking known QR code attacks, using email security tools that can detect image-based threats, backing up critical data and training users to recognize suspicious requests.
If someone has already scanned a QR code, the next steps matter. They should check the URL before entering information, avoid submitting login details if anything seems off and report the message to the security team immediately. Fast reporting can help stop an attack before it spreads.
A Small Code Can Create a Big Problem
QR codes are not the problem. They are useful, efficient and here to stay. The risk comes from assuming every QR code is safe simply because it looks ordinary.
For businesses, quishing is a reminder that cybercriminals do not always need complex tools to get inside a network. Sometimes, all they need is a familiar square, a convincing message and one distracted click, or in this case, one quick scan.
The good news is that awareness goes a long way. With the right training, smart security tools and a healthy dose of caution, businesses can keep the convenience of QR codes without handing cybercriminals an easy way in.
Interested in learning how to protect you and your team from Quishing? Contact Global CTI today and let’s have a conversation!