QR code phishing, also called quishing, is a phishing attack that hides a malicious link inside a QR code instead of a clickable URL. Attackers place these codes in phishing emails, PDF attachments, texts, unsolicited packages, and fake parking meter stickers to steal credentials, card details, or install malware. Microsoft’s Q1 2026 email threat report ranks QR code phishing as the fastest-growing email phishing technique, climbing from 7.6 million attacks in January to 18.7 million in March.
Plenty of SMBs and nonprofits still treat a QR code as a harmless square of pixels. It isn’t, and your spam filter often can’t tell either. Skip codes you didn’t expect, check the web address before you type a password, and pay through official apps.
What Is QR Code Phishing (Quishing)?
Quishing is phishing that swaps a clickable link for a QR code, so the victim opens the malicious site by scanning it with a smartphone.
The goal is the same old one. Attackers want your credentials, your payment details, or a foothold on your device.
The FBI flagged this years ago. Its January 2022 public service announcement on QR code tampering warned that criminals tamper with both digital and physical QR codes. Those codes lead to sites that steal login and financial details, or to malware that can access the phone, including its location.
Why does it still work? Because most of us scan menus, tickets, and parking signs on autopilot. Attackers count on that reflex.
To see why that reflex is risky, start with what a QR code holds.
Static vs. Dynamic QR Codes: Why the Destination Can Change
A static QR code stores the web address in the pattern itself, while a dynamic QR code stores a short link its owner can repoint at any time.
Static codes can’t be edited. Print one, and it goes to the same place forever.
Dynamic codes are popular with marketing teams because the landing page changes without a reprint. That flexibility cuts both ways. A code that looked clean when someone checked it can point somewhere else the next day.
The practical rule for your business is simple. Treat every QR code as a link you can’t read until your phone shows the address. Then read the address.
How a Quishing Attack Works in Five Steps
A typical quishing attack moves the victim from a message they trust to a fake page on their own phone in five steps.

The switch to a smartphone matters most, because it moves the victim outside most company security tools.
The cover story is usually dull on purpose. The FTC’s alert on scammers hiding links in QR codes describes codes sent by text or email with made-up reasons, like a missed delivery or an account problem. Nobody questions a delivery notice.
The five stages of a common email-based quishing attack are:
- The lure. A phishing email arrives with an urgent reason to act, such as a password reset or a shared document.
- The code. The QR code sits in the email body or inside a PDF attachment as an image.
- The switch. The message asks you to scan with your smartphone, which moves you off your protected work computer.
- The fake page. The code opens a login page dressed up as a trusted brand, such as a Microsoft 365 sign-in.
- The harvest. You type your credentials or card number, and the attacker keeps them. That’s credential harvesting.
Step three does the real damage. The moment someone picks up a phone, most of your company’s security tools drop out of the picture.
The urgency and fake branding are classic phishing moves, so our guide to spotting and avoiding phishing scams covers the same red flags from another angle.
Why QR Code Phishing Slips Past Email Filters
QR code phishing slips past many email filters because the malicious link is stored inside an image, and traditional scanning looks for text links it can check.
APWG’s Q4 2025 phishing trends report says QR codes in email send phones to phishing sites or malware, and traditional email filtering misses them. A secure email gateway that only inspects typed-out URLs sees a picture and lets it through.
Then there’s the device. A personal device on mobile data sits outside your corporate web filtering, so nothing checks the site before it loads.
Volume makes this harder. Mimecast saw an average of 2.7 million emails a day carrying QR codes between October 2024 and March 2025, according to APWG’s Q1 2025 trends report. That count includes plenty of harmless ones, so blocking every code isn’t an option.
Filters can learn, though. In a November 2024 post on Defender for Office 365 QR protections, Microsoft said it blocked about 3 million QR phishing attempts a day at the peak. After new protections rolled out, that fell to about 200,000 a day.
So ask your IT provider one blunt question: does our email security read QR codes inside images and PDF attachments? If the answer is “probably,” treat it as a no.
Redirects, Turnstile and Mobile Tricks That Hide the Trap
Since late 2024, Unit 42’s QR code phishing research has tracked three new quishing tactics: redirects through legitimate sites, Cloudflare Turnstile checks, and pages tailored to each victim.
Each one hides the trap from a different watcher. An open redirect bounces you through a real website first, so the link looks respectable. Turnstile, a Cloudflare human check, stops automated security crawlers from reaching the phishing page at all.
The tailored page is the nastiest part. A login page built around you feels routine, and routine is when people type passwords without thinking.
Your phone doesn’t help much either. KnowBe4’s summary of the Unit 42 findings notes that scan previews often show only part of the URL, which makes redirect tricks harder to notice.
Attackers also go after the mobile device itself. Unit 42’s report on QR codes as an attack vector found malicious codes paired with URL shorteners, in-app deep links, and direct APK downloads to dodge mobile security. It also tracked targeted QR phishing against Ukrainian Signal users tied to the Russia-Ukraine war.
A shortened link, or a prompt to install an app from outside the official store, is your cue to stop and close the page.
Real-World Quishing: Parking Meters, Packages and Fake Brands
Real-world quishing shows up on parking meters, in surprise packages, and in phishing emails that impersonate brands like DHL and Microsoft.
Fake QR Stickers on Parking Meters
Fake QR stickers on parking meters send drivers to lookalike payment sites that collect card details.

Police recovered about 200 fake QR stickers from downtown Orlando meters in June 2025. Pay only through the official app or the meter.
In June 2025, NYC DOT issued an alert about a fake ParkNYC meter sticker that led to a site asking for card details. DOT said payment works only through the official ParkNYC app or the meter itself.
The city then began checking parking meters citywide. Orlando had it worse.
Police recovered about 200 fake QR stickers from downtown Orlando meters that same month. They noted the real ParkMobile code is printed directly on the sticker, on a green background.
The problem crosses borders. Kensington and Chelsea Council warned drivers in January 2025 that fake codes had been stuck to parking payment signs in at least six locations.
If your team drives to client sites or events, this is a two-minute talk at your next staff meeting. Pay in the official app. Never through a sticker.
Surprise Packages With QR Codes
Unsolicited packages with QR codes are a variation of brushing scams that the FBI warned about in July 2025.
The FBI also said the scheme is less widespread than other fraud schemes. Fair enough. It still deserves a heads-up for whoever handles your mailroom.
The FTC’s January 2025 alert on QR code gift packages describes a note urging recipients to scan a code to learn who sent the gift. Curiosity is the whole hook.
Brand Impersonation in Phishing Emails
Brand impersonation drives email quishing, and Mimecast counted 1,642 brands targeted with malicious QR codes in Q2 2025, according to APWG’s Q2 2025 trends report.
DHL topped the list with 3,543 distinct codes, and Microsoft came a close second. Delivery notices and Microsoft login prompts land in every office inbox, so they blend right in. Our real-world phishing examples show how convincing these lures get.
Quishing Growth and the Business Risk Behind It
Quishing volume has swung up and down since late 2024, but a single stolen login from one scan is enough to hurt your business.
Quishing Growth Trends From 2024 to 2026
Quishing activity rose, dipped, and surged again between late 2024 and early 2026, based on Mimecast and Microsoft data.

Microsoft ranked it the fastest-growing email phishing technique of Q1 2026, after a dip in late 2025.
Mimecast identified more than 1.7 million unique malicious QR codes between October 1, 2024 and March 31, 2025, according to Dark Reading’s report on Mimecast QR code data. Those are unique codes, and each one can hit many inboxes.
The count kept climbing. APWG’s Q3 2025 trends report shows Mimecast found 716,306 unique malicious QR codes in email attachments that quarter, up 13% from Q2. Attachments are exactly where older filters are weakest.
Then it dipped. APWG’s 2025 Year in Review said QR code phishing declined from Q3 to Q4 2025 as phishers moved to new infrastructure and targets.
Dips are temporary. By Q1 2026, Microsoft’s quarterly email threat data ranked it the fastest-growing email phishing technique.
For perspective, Hoxhunt’s 2026 Threat Intelligence Report found malicious QR codes in less than 2% of the malicious emails it observed. Quishing is a small slice of phishing. The danger is that it’s the slice your email filters handle worst.
What One Stolen Login Means for Your Business
One set of credentials stolen through quishing can lead to account takeover, business email compromise, and attackers moving deeper into your systems.
A single Microsoft 365 password can unlock email, SharePoint files, and every app tied to that account. From there, an attacker can send invoices from a real company address, and your clients have no reason to doubt them.
The personal device angle makes it worse. When an employee scans on their own phone, your team may never see the credential harvesting happen. Quishing is social engineering at heart, so the same social engineering attack prevention steps apply.
For nonprofits holding donor records, that’s a compliance problem too.
How to Spot and Stop a Malicious QR Code
You can spot a malicious QR code by checking where the code sits, why it arrived, and which web address it opens before you enter anything.
Warning Signs of a Malicious QR Code
A malicious QR code usually gives itself away through its placement, its message, or its URL. Watch for these red flags:
- A sticker placed over another code, or a code where it doesn’t belong.
- An unexpected email, text, or package that pressures you to scan right now.
- A phishing email that asks you to switch to your phone to “verify” or “sign.”
- A shortened or odd-looking URL in the scan preview.
- A login page or payment form you reached from a code instead of the official app.
How to Protect Your Business From QR Code Phishing
Protecting your business from QR code phishing takes five habits that cover email, accounts, people, devices, and reporting. The five protections to put in place, in order, are:

Multi-factor authentication means a stolen password alone won’t open the door, so turn it on first.
- Check your email security. Confirm it scans QR codes inside images and PDF attachments, along with regular links.
- Turn on multi-factor authentication. Cover Microsoft 365 and every business app, so a stolen password alone won’t open the door.
- Train with QR examples. Add quishing to your phishing training for employees, including parking meter and package scenarios.
- Set a device rule. Staff should type known addresses or use official apps for logins and payments, instead of scanning on a personal device.
- Make reporting easy. Give staff one place to report suspicious codes, and report fake stickers to the business or city.
Security awareness training does the heavy lifting. Filters catch what they can. A person who pauses before typing a password catches what slips through.
What to Do If You Scanned a Phishing QR Code
If you scanned a phishing QR code and entered a password, change it right away and turn on multi-factor authentication for that account.
The FTC’s advice after a QR code package scam is blunt: if you entered a username and password, change them. Call your bank if you typed card details, then tell your IT or security team. Fast reports turn a breach into a near miss.
Quick Answers About QR Code Phishing
QR code phishing questions usually come down to four things: whether it’s real, what it can steal, what the FBI said, and what to do next.
Can QR codes be used for phishing?
Yes, QR codes can be used for phishing because each code hides a web address that your smartphone opens when you scan it. Attackers point that address at fake login pages, payment forms, or malware.
Can someone steal your info with a QR code?
Yes, a malicious QR code can lead to stolen personal and financial information. The FBI’s alert on unsolicited packages with QR codes says scanning them can bring requests for your details, or malware that steals data from your phone.
What is the FBI warning about QR codes?
The FBI has warned about QR codes in a January 2022 alert on tampered digital and physical codes and a July 2025 alert on QR code brushing packages. Both warn that scanning can lead to stolen details or malware.
What should you do if you scan a phishing QR code?
If you scan a phishing QR code, close the page without entering anything. If you already typed a password or card number, change the password, turn on MFA, call your bank, and report it to your IT team.
Key Takeaways: Secure Today, Safe Tomorrow
Quishing works because it moves a phishing link into an image and onto a phone, two places older security setups often miss.
The key takeaways for your business are:
- Quishing hides phishing links inside QR codes delivered by email, PDF, text, package, or sticker.
- Traditional email filters often miss QR codes, and personal devices skip corporate web filtering.
- Attackers use redirects, Cloudflare Turnstile, and tailored login pages to avoid detection.
- Multi-factor authentication limits the damage when credentials get stolen.
- Staff who check URLs and report fast are your best early warning.
Start where the protection comes fastest. Turn on MFA everywhere today. This week, confirm your email security reads QR images, then brief your team with real examples.
Within seven days, every staff member should know exactly where to report a suspicious code. Once that’s in place, add QR codes to your phishing simulation testing so you can see who scans and who reports.
Want to know where your cyber risks sit right now? Grab RiskAware’s free cybersecurity score or book a discovery call. A QR code is a door, so make sure you know who’s on the other side before you open it.



