All resources

13 April 2026 · Threat Spotlight · CyberSec360 Australia

Threat Spotlight: Quishing — When the Phish Arrives as a QR Code

Security filters got good at reading malicious links — so attackers stopped sending links. QR-code phishing ("quishing") embeds the malicious URL in an image: "Your MFA is expiring — scan to re-enrol", "Review the attached voicemail", "Update your payroll details". The email filter sees only a picture; the victim’s phone does the rest.

Why the pivot to phones works

  • Filters historically parsed text links, not pixels — the payload rides through in an image.
  • The scan moves the victim from a managed, protected laptop to a personal phone with no security stack.
  • Phone screens truncate URLs, making fake login pages harder to spot.
  • QR codes carry borrowed trust from menus, parking meters and payments — scanning feels routine.

The corporate lure that works best

The most effective quishing themes impersonate the systems businesses genuinely use: Microsoft 365 MFA re-enrolment, DocuSign, payroll portals, shared voicemail. The landing page is a pixel-faithful login clone that harvests credentials — and increasingly relays them in real time to defeat simple MFA codes.

Defence in three layers

  • Train the reflex: legitimate internal systems almost never demand a QR scan from an email. Teach "unexpected QR = suspicious".
  • Prefer phishing-resistant MFA (passkeys/security keys) for key accounts — cloned pages can’t harvest what isn’t typeable.
  • Report-and-revoke fast: a scanned-and-entered password is only a disaster if nobody hears about it before the attacker uses it.

Quishing is a reminder that phishing is a medium-agnostic con: email, SMS, QR, voice — the wrapper changes, the ask doesn’t. Train people to notice the ask.

Want help with this in your business?

Book a free security check with our Sydney team — plain-English advice, no obligation.

Get a Free Security Check