Security Glossary

What is Quishing (QR Phishing)?

Quishing is phishing that uses QR codes instead of (or in addition to) links. Victims scan with a phone, land on a malicious page, and often never see a full desktop URL bar. Printed mailers and slide decks make the tactic especially effective.

How a Quishing (QR Phishing) Attack Works

1

Create a believable prompt

Parking tickets, package notices, conference check-ins, and "Wi-Fi login" posters are common.

2

Encode a malicious destination

The QR points to a credential harvester or malware download.

3

Capture mobile sessions

Phone logins often have different MFA UX — attackers exploit the confusion.

4

Reuse access

Stolen credentials open email, VPN, or SaaS apps.

Real-World Example

Attendees at a trade show scanned a lobby poster QR "for the session slides." The page cloned the event SSO look and captured dozens of vendor emails.

How AiVERSARY Detects Quishing (QR Phishing) Risk

AiVersary focuses on the reconnaissance that tells attackers which brands, events, and facilities to impersonate with QR lures — so you can brief staff on realistic local pretexts.

Is your organization exposed to quishing (qr phishing)?

AiVERSARY scans your public footprint and identifies the exact data attackers would use against you. $499 per report.

Get Your Threat Report