Join our Newsletter — 33% off our NHI Course

Qishing

Qishing is a phishing technique that uses QR codes to steer victims to malicious destinations. The code is usually embedded in an email or image, which helps the attacker avoid some domain-based filtering and moves the interaction onto a device that security teams may monitor less consistently.

What Qishing Is in Practice

Qishing is a phishing method that weaponises QR codes to redirect people to attacker-controlled destinations. The QR code often sits inside an email, attachment, poster, or image, so the malicious link is hidden until the code is scanned.

The key feature is not the code itself, but the delivery path. A QR image can bypass the kind of visible link inspection many users rely on, and it can shift the final click from the inbox to a mobile device or other scanner app where enterprise controls may be thinner.

How Qishing Works

At a technical level, qishing still follows the same social engineering pattern as email phishing: create urgency, disguise the destination, and lure the victim into taking an action that reveals credentials, payment details, or other sensitive information. The QR code is simply a delivery container that makes the destination less obvious.

This technique is effective because the user sees a visual object rather than a readable URL. If the QR code points to a login page, document share, payment portal, or package-tracking page, the victim may trust the journey because the first-stage email itself can look harmless. The abuse often depends on the scanner opening the destination outside the protection layers that would normally inspect a typed or visible link.

That is why qishing belongs in the broader phishing family rather than in a separate technical category. The attacker is not exploiting the QR standard itself so much as the gap between human trust, email filtering, and mobile browsing behaviour. Where organisations rely on user review alone, the technique can be especially persistent.

Why Qishing Is Harder to Spot

Qishing is harder to recognise because the suspicious content is encoded, not readable at a glance. A user, mail gateway, or analyst may have little to inspect until the code is decoded, and even then the final destination may be shortened, redirected, or hosted on a benign-looking domain before the payload appears.

The technique also benefits from channel switching. A campaign may begin in email but finish on a phone, where browser isolation, URL rewriting visibility, and enterprise logging may not be as consistent as they are on managed desktop endpoints. That makes user awareness, message inspection, and endpoint monitoring more important than ever.

Where an organisation treats QR codes as inherently safe because they are only images, qishing can slip through ordinary assumptions. In practice, a QR code can be as dangerous as a visible malicious link, and sometimes more so because it hides the destination from simple human review.

Defensive Controls and Detection

Defence starts with treating QR codes as active links, not passive images. Email security controls should inspect attachments and embedded images where possible, and security teams should make sure users can report suspicious QR-based messages just as they would any other phish.

Training matters, but so does friction reduction. If users can preview the destination before opening it, or access a safe scanning workflow that shows the full URL, the attack loses much of its advantage. A strong baseline also includes monitoring for unusual sign-in behaviour after QR-driven campaigns, especially when the destination is a credential-harvesting page.

For broader phishing resilience, modern authentication helps because it reduces the value of stolen passwords. Guidance from NIST SP 800-63 Digital Identity Guidelines supports phishing-resistant authentication approaches, while OWASP Cheat Sheet Series provides practical advice on secure authentication and session handling. For email and gateway hardening, CIS Benchmarks and NIST Cybersecurity Framework 2.0 help anchor detection, response, and user-protection controls.

A useful supporting metric from Ultimate Guide to NHIs is that 79% of organisations have experienced secrets leaks, with 77% of those incidents causing tangible damage, which underscores how often phishing-style access abuse leads to real loss once a lure succeeds.

Risk and Threat Considerations

Qishing matters because it lowers the visibility of a phishing lure without removing the attacker’s end goal. The user still lands on a malicious destination, but the QR format can make the first-stage message look less suspicious and can move the final interaction to a device or context with weaker monitoring.

Failure mechanism: The attacker hides a malicious destination inside a QR image, then relies on user trust and weaker mobile-side inspection to capture credentials, push malware, or steer the victim into a fraudulent flow.

Impact: Successful qishing can lead to account takeover, credential theft, financial fraud, and broader compromise if the captured access is reused across systems or combined with further social engineering.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-63 Phishing-Resistant Authenticators — Phishing-Resistant Authenticators Qishing is a phishing variant that defeats password-only trust.
Recommendation — Adopt phishing-resistant authenticators to reduce the impact of QR-based credential theft.
CIS Controls v8 6 — Access Control Management Qishing aims to capture credentials and abuse access paths.
9 — Email and Web Browser Protections Qishing commonly arrives through email and redirects through web content.
Recommendation — Limit and review access so stolen credentials from qishing are less useful. Harden email and browser protections to detect or block QR-delivered phishing destinations.
NIST CSF 2.0 PR.AA — Identity Management, Authentication, and Access Control Qishing exploits weak authentication journeys after a user scans a malicious QR code.
DE.CM — Security Continuous Monitoring Qishing often succeeds by moving the interaction to less-monitored channels.
Recommendation — Strengthen authentication and access control to reduce the value of QR-driven credential theft. Monitor login and email abuse patterns that follow QR-based phishing activity.

Practitioner Guidance

Why practitioners should care: Qishing is a good example of how attackers adapt familiar phishing tactics to bypass user judgement and email controls. Security teams should treat QR codes as executable trust decisions, not harmless graphics, especially in mail, invoices, delivery notices, and brand-impersonation campaigns.

What to watch for: Sudden QR-heavy messaging, requests to “scan to view” content, and messages that push urgency or secrecy deserve scrutiny. The strongest operational signal is often the mismatch between a benign-looking email and an unexpected authentication or payment destination after scanning.