Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security Why do quishing attacks bypass some email security…
Cyber Security

Why do quishing attacks bypass some email security controls more easily than link-based phishing?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 16, 2026 Domain: Cyber Security

Quishing can evade some secure email gateways because the malicious destination is hidden inside an image rather than exposed as a visible link or attachment. If the gateway does not decode the QR code content, the message may appear benign and reach the inbox. That shifts detection from perimeter filtering to endpoint analysis, user reporting, and downstream URL inspection.

Why Quishing Slips Past Some Email Defenses

Quishing is harder for some mail filters because the dangerous part is not a plain URL string that a gateway can inspect at delivery time. The payload is embedded in an image, so the control has to read the image, decode the QR content, and then evaluate the destination behind it. Many email security stacks are tuned to spot links, attachments, and known malicious domains, not to interpret visual codes.

The practical consequence is that the message can look like an ordinary flyer, invoice, delivery notice, or account alert until a person scans it on a phone or camera app. That shifts the security decision away from the mail layer and into whatever device or browser opens the destination. In practice, many security teams discover the gap only after users start scanning from inbox previews rather than from any obvious malicious link.

How It Works in Practice

Link-based phishing is easier to inspect because the URL is explicit. A secure email gateway can rewrite, detonate, reputation-check, or block that destination before the message reaches the user. Quishing reduces that visibility by moving the destination into an image object, often inside a PDF, poster-style email, or branded notification where the QR code looks like a legitimate business element.

The control break usually happens in one of three places:

  • The gateway does not OCR or decode embedded QR codes.
  • The QR code is delivered through an image format or document type that is only lightly scanned.
  • The user scans the code on a mobile device, bypassing the desktop email security stack entirely.

Once the code is scanned, the real inspection burden moves downstream to browser controls, mobile protection, URL reputation services, and the user’s own ability to notice lookalike domains or consent prompts. That is why quishing often succeeds even when the same campaign would have been blocked if the attacker had pasted the URL directly into the email body.

Good defenders treat QR delivery as a content-inspection problem, not just a messaging problem. That means checking image decoding coverage in the mail stack, watching for image-only lures, and making sure endpoint and web controls can still intercept the landing page. These controls tend to break down when scanning happens on unmanaged mobile devices because the security boundary shifts outside enterprise telemetry.

Common Variations and Edge Cases

Tighter inspection usually reduces user convenience, so organisations have to balance delivery speed and brand-style messaging against deeper content analysis. That tradeoff becomes more visible in environments that rely heavily on QR codes for logistics, visitor management, retail operations, or customer support.

Some campaigns do not rely on QR decoding alone. Attackers may combine a QR code with short-lived links, branded email templates, or a harmless first-hop page that redirects only after device fingerprinting. Others use a QR code as the opening step in a credential-harvest flow, where the first page appears legitimate but the second step collects credentials or session tokens.

Defenders should also expect that a message can be benign in the inbox but malicious after it leaves the mailbox. That matters when users forward the email into personal mail, open it on unmanaged phones, or reuse the same scan workflow across multiple channels. The edge case that most often defeats standard policy is a message that is visually low-risk but operationally high-risk once the QR content is acted on outside the mail stack.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.DS — Data SecurityQuishing uses content that evades initial inspection.
DE.CM — Security Continuous MonitoringDetection must move beyond the mailbox to landing-page and endpoint telemetry.
Recommendation — Harden content inspection and downstream web filtering for image-based lures. Monitor endpoint and web telemetry for QR-driven phishing follow-through.
CIS Controls v89 — Email and Web Browser ProtectionsQR phishing bypasses email inspection unless mail and web controls cover embedded content.
8 — Audit Log ManagementQuishing investigations depend on correlating mail, endpoint, and web events.
Recommendation — Extend email and browser protections to inspect embedded QR-delivered destinations. Correlate mail, endpoint, and web logs to trace QR-based phishing activity.
NIST SP 800-635.2.7 — Phishing ResistanceQR lures often lead to credential prompts that should resist phishing tactics.
Recommendation — Prefer phishing-resistant authenticators for any workflow exposed to QR-delivered login pages.
MITRE ATT&CKT1566 — PhishingQuishing is a phishing delivery variant that hides the malicious destination in an image.
Recommendation — Map QR-based lures to phishing detections and hunt for image-delivered initial access.

Practitioner Guidance

What to verify: Confirm whether the secure email gateway actually decodes QR codes, not just whether it scans attachments and text URLs. If it does not, treat QR-heavy campaigns as an inspection gap and validate how downstream URL filtering and browser protection will catch the landing page.

Common mistake: Assuming image-based messages are lower risk because no suspicious link is visible. That assumption fails when the image is the link, especially if users are encouraged to scan on mobile devices before any enterprise control can inspect the destination.

Decision rule: If the QR code can deliver a credential prompt, a login page, or a payment action, apply the same scrutiny you would use for a direct phishing URL and require a control path beyond the mail gateway alone.

Practitioner takeaway: Quishing is less about a new attacker objective than a shifted inspection point, so the real test is whether your controls can still evaluate the destination after the email layer has stopped seeing it.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 16, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org