What is Quishing (QR Phishing)?
Quishing is phishing that uses QR codes instead of (or in addition to) links. Victims scan with a phone, land on a malicious page, and often never see a full desktop URL bar. Printed mailers and slide decks make the tactic especially effective.
How a Quishing (QR Phishing) Attack Works
Create a believable prompt
Parking tickets, package notices, conference check-ins, and "Wi-Fi login" posters are common.
Encode a malicious destination
The QR points to a credential harvester or malware download.
Capture mobile sessions
Phone logins often have different MFA UX — attackers exploit the confusion.
Reuse access
Stolen credentials open email, VPN, or SaaS apps.
Real-World Example
Attendees at a trade show scanned a lobby poster QR "for the session slides." The page cloned the event SSO look and captured dozens of vendor emails.
How AiVERSARY Detects Quishing (QR Phishing) Risk
AiVersary focuses on the reconnaissance that tells attackers which brands, events, and facilities to impersonate with QR lures — so you can brief staff on realistic local pretexts.
Is your organization exposed to quishing (qr phishing)?
AiVERSARY scans your public footprint and identifies the exact data attackers would use against you. $499 per report.
Get Your Threat ReportRelated Terms
Spear Phishing
Spear phishing is a targeted email attack where criminals research a specific person and craft a message designed just for them. Unlike mass spam, these emails reference real details about your job, your colleagues, or recent company events to appear legitimate. They are the number one way attackers breach organizations today.
Smishing
Smishing is phishing delivered by SMS. Messages impersonate banks, parcel carriers, IT help desks, or executives and push victims to fake login pages or callback numbers. Mobile screens hide full URLs, which makes hasty taps especially dangerous.
Pretexting
Pretexting is when an attacker creates a fabricated scenario — a "pretext" — to trick someone into sharing information or performing an action they normally wouldn't. Think of it as method acting for criminals: they invent a believable character and situation, then play that role convincingly enough to bypass your team's natural skepticism. The quality of the pretext depends entirely on how much real information the attacker can gather beforehand.
Lookalike Domains
Lookalike domains are registered names that visually or typographically resemble a trusted brand — rn instead of m, extra letters, or alternate TLDs. They power phishing sites, fraudulent invoices, and executive impersonation that bypass casual visual checks.