Article summary: Attackers embed malicious links in QR codes that email filters cannot read, redirecting employees to credential-harvesting pages. Businesses need mobile-aware security policies and employee training to close this gap.
A QR code looks harmless. A pixelated square in an email, on a printed handout, or stuck to a conference room table is easy to scan without a second thought.
That is exactly what attackers are counting on. Mobile device security threats have evolved faster than most businesses have adapted, and QR code phishing, often called quishing, is the latest example.
The attack bypasses every traditional email filter because it hides the malicious URL inside an image. The moment your employee scans it on their work phone, they step completely outside your corporate security perimeter.
Traditional phishing emails work by inserting a clickable link that security gateways can scan and flag. QR codes remove that step.
The URL is encoded inside an image, and most email security systems are built to parse text, not images. A malicious link embedded in a QR code sails through the same filters that would catch an identical link typed in plain text.
According to the Anti-Phishing Working Group, attackers are increasingly using QR codes to bypass traditional email defenses. APWG reported that criminals are sending millions of QR-code-based phishing emails each day, while security researchers identified more than 1.7 million unique malicious QR codes over a six-month period.
That is not gradual drift. That is a deliberate shift in attacker tactics driven by one clear finding: it works.
The second advantage for attackers is the device shift.
When an employee scans a QR code using their phone, they move from a managed corporate endpoint, which has web filtering, endpoint detection, and DNS controls, to a personal mobile device that typically has none of those protections.
The URL resolves on the phone. The fake login page loads on the phone. The credentials are captured on the phone. Your security stack never gets a chance to intervene.
The most common version arrives in an email with no clickable links at all, just a QR code image. The message often impersonates Microsoft, Adobe, or even the target company's own HR department.
It creates urgency: review an important document, reset your MFA, sign an updated policy. The employee scans the code on their phone and lands on a convincing fake login page.
The page captures both the password and the MFA token in real time using a technique called Adversary-in-the-Middle.
Attackers print fake QR code stickers and place them over legitimate ones. Conference room whiteboards, payment terminals, parking meters, and restaurant tables are all targets.
The employee sees what appears to be a legitimate QR code and scans it without hesitation. A simple sticker placed over the original code can redirect users to a malicious site while leaving the underlying business unaware that anything has been altered.
A PDF invoice, a shared agenda, or an onboarding pack arrives with a QR code embedded inside. The file scans clean because security tools analyze the document structure, not the encoded destination of an image within it. The threat lives in the decoded destination.
C-level executives receive significantly more QR-code phishing attacks than other employees. A report by Abnormal Security found that C-suite executives were targeted by quishing campaigns at a rate roughly 42 times higher than non-executive staff.
Keepnet Labs reports that executives are frequent targets of quishing campaigns because they typically have broad access to sensitive data and decision-making authority. They also identify industries such as finance, healthcare, and energy as particularly attractive targets due to the value of the information they hold.
But executives are not the only risk. Finance teams, IT staff, and HR departments are also targeted because of the sensitive data they handle.
No single control eliminates this risk completely, but a layered approach closes most of the gap.
Traditional secure email gateways cannot parse QR codes embedded in images.
Look for email security tools that include QR code scanning as a specific capability. Several enterprise-grade solutions added this feature in 2024 and 2025 in direct response to the quishing surge.
Work phones should have a policy that requires employees to preview the URL a QR code resolves to before tapping through.
Most modern phones display the destination link before opening it. Pairing this with strong acceptable use policies reduces the chance that an employee scans an unexpected code without thinking.
Generic phishing training does not cover this threat. Employees need to recognize that scanning an unfamiliar QR code carries many of the same risks as clicking an unknown link.
They should know to verify with IT before scanning any code that prompts for login credentials, even if the branding looks legitimate.
Even when credentials are captured through a quishing attack, phishing-resistant MFA methods like hardware security keys (FIDO2) are far harder for attackers to bypass than standard one-time codes. If your team relies on SMS or app-based MFA today, this is worth upgrading.
QR code phishing is one of the fastest-growing attack types of the last two years, and most small businesses have not updated their defenses to account for it.
The combination of mobile device blind spots and image-based payloads that bypass email filters makes this a genuinely difficult threat to stop without the right setup.
Vudu Consulting works with businesses in Oklahoma City and across the country to assess their mobile security posture, update email filtering, and build employee training that covers threats like quishing. If your current security stack was configured more than a year ago, there is a good chance it was not built with this threat in mind.
Visit vuduconsulting.com/get-started to book a call with our team.
Quishing is QR code phishing. Attackers embed malicious URLs inside QR codes rather than typing them as plain links, which allows them to bypass email security gateways that scan text but cannot parse images.
The victim scans the code, typically on a mobile device, and lands on a page designed to steal their credentials.
Corporate laptops and desktops are typically protected by web filtering, DNS controls, and endpoint detection software.
Work phones, especially personal devices used for work, often lack these controls. When an employee scans a QR code on their phone, the malicious URL resolves outside the corporate security perimeter where none of those tools can intervene.
Standard MFA codes, including SMS texts and authenticator app one-time codes, can be captured in real time using Adversary-in-the-Middle phishing pages.
These pages relay credentials and MFA tokens to the attacker simultaneously. Phishing-resistant MFA methods like FIDO2 hardware keys are not vulnerable to this technique.