QR CODES · SMARTPHONES · BUSINESS
Quishing: the hidden risk of fake QR codes at work
Quishing, a combination of QR code and phishing, uses a code to hide a deceptive destination. A familiar-looking document can lead an employee to a fake login or payment page.
The risk is not the QR code itself, but the link and actions it invites. Understanding this sequence helps interrupt the trap before sharing sensitive information.
What is quishing and how does it work?
Instead of displaying a readable URL, the attacker places it inside a QR code and supplies a reason to open it. The scenario can follow three steps:
The pretext
An employee receives a fake invoice, HR update request or parcel notification containing a QR code. The message encourages them to act quickly.
The move to mobile
They use a work or personal smartphone to decode the QR code. Depending on the app, an address is displayed before the user chooses to open it.
The fraudulent destination
The link may lead to an imitation Microsoft 365 portal, HR service or payment page. The trap aims to obtain credentials, an MFA code, a sign-in approval or a download.
Why some protections may miss a QR code
It would be inaccurate to say all filters are powerless. Some solutions decode QR codes and analyse their destinations. Coverage depends on enabled features, document format and analysis conditions.
Image and PDF handling: an encoded URL may escape a check that only examines text. Mobile coverage: a personal phone using a mobile network may not benefit from the workstation’s proxy or network controls. Device, browser or cloud-service protections may still apply.
Where can fake QR codes appear at work?
These example scenarios illustrate digital and physical contact points to watch.
Fake invoices and supplier reminders
A message impersonating a supplier reports a payment problem. The QR code leads to a supposedly secure portal to “resolve the issue”. Before paying, confirm the request using the supplier’s usual contact details.
Trade shows, badges and posters
A sticker can cover a QR code on a physical item and change its destination. Check the material and the displayed domain before opening a document or form, even at a legitimate event.
Letters and administrative documents
A letter can impersonate a benefits provider, insurer or public authority and request an account update. Find the official portal independently instead of relying on a logo or QR code alone.
How can you build a checking habit?
Pause before opening
An unexpected QR code deserves a check, even if the sender looks familiar. Decoding the code and opening its destination are different actions: review the displayed address and stop if unsure.
Use a suspicious QR code checker
Analyse an image or screenshot of the code with SecurCheck before opening the link. The report helps examine the destination, domain reputation and observable redirects. Do not submit QR codes containing authentication secrets or confidential data.
Use an official channel
For HR, banking or IT requests, open the portal using a trusted bookmark or internal directory. Confirm unusual requests with a contact already saved in your records, and report the document to IT.
Breaking the habit of opening immediately, confirming through a known channel and making reporting easy helps reduce risk. Analysis time varies with content and available sources: no check is infallible.
Support your employees’ digital safety habits.
Make SecurCheck part of your teams’ routine for examining suspicious links, texts, files and QR codes. Discuss your use cases and the terms of a pilot suited to your business.
Request a discussion about a pilot