By Jordan Nicholas. Cybersecurity Analyst
QR codes were designed to make digital life simpler. They have achieved exactly that for users and attackers alike. As quishing, the QR-based evolution of phishing, spreads across parking meters, restaurant tables, and corporate email inboxes, Jordan Nicholas, cybersecurity analyst and developer of the CyberScan threat detection tool, breaks down how it works, why it is so effective, and what individuals and organizations must do to protect themselves.
After a decade, QR codes have evolved from obscure logistics tools into an integral part of daily existence. From restaurant menus to parking tickets, event registrations, bank transfers, etc., in the African continent where digital adoption has bypassed traditional infrastructure, QR codes have become the main channel of interaction between the physical and digital realms. Their efficiency cannot be argued. However, their security risks are only now coming to light.
There is even a name for this danger, quishing. The combination of QR and phishing, quishing refers to the process of using malicious QR codes to trick users into accessing fake websites or install malware on their devices without their knowledge. This is no longer just a theory. Quishing attacks are already underway – in car parks, coffee shops, corporate environments, and in urban Africa. These attacks are successful because they exploit trust.
What exactly is quishing?
Quishing follows the principle of simplicity. When scanning a QR code, you give up the task of navigating to the destination to a small rectangle of pixels. You cannot analyze a QR code as you can analyze a URL; you cannot find typos in “paypa1.com” or “login.bank.verify.phishingsite.net”. This code is designed to be invisible. It is precisely the invisibility that makes it possible for cybercriminals to exploit.
In phishing, the malicious link is the very thing that makes it possible to recognize the scam. An experienced person can easily detect it. The spam filter can also identify a scam. However, once the URL is hidden behind the QR code, which may appear in print, on the display or in an email message, all the layers of protection that depend on analyzing the URL become useless. By the time the link redirects, it is too late.
“Once you scan a QR code, you’ve implicitly trusted a mysterious endpoint. That’s exactly what hackers are banking on.”
Why quishing is gaining ground
Quishing works effectively because it is designed into its structure. Multiple factors regarding QR codes and user behavior contribute to the efficacy of this type of attack.
- Obfuscated URLs – the target remains invisible until the scan occurs, thereby eliminating the possibility for users to detect the scam based on their most common fraud prevention technique.
- Mobile-based attack surface – most of the QR code scans happen on mobile phones, where security controls are less likely to be present and where small screens make URL previewing difficult.
- Trusted by nature – QR codes come with the notion of legitimacy attached to them. They appear on official signs, professional emails, and other legitimate documents. The cultural belief in their authenticity is what makes them vulnerable.
- Physical attack vectors – unlike phishing, quishing may also be used physically. For example, placing a malicious QR sticker over the legitimate one on a parking meter, restaurant menu, or community board does not require any technical skills.
- Evasion of email filters — Security systems that examine emails for malicious links can’t check the contents of a QR code image. A QR code contained within a seemingly legitimate email would easily bypass all enterprise spam filters.
Real-world attack scenarios
Quishing attacks are not something that may become an issue in the future they are currently taking place. Consider the following examples which have been confirmed.
Parking meter fraud
Stickers with fraudulent QR codes are applied to payment codes of parking meters. When users scan them, they are redirected to a convincing yet fake payment portal, through which their credit card details are stolen. It has been seen in several cities in Europe and North America and is currently growing popular in Africa too.
Restaurant and retail traps
Fraudulent QR codes are used for replacing legitimate ones in restaurants and retail stores. These fake websites usually pretend to be some sort of loyalty programs or ordering systems, trying to obtain users’ credentials and financial details.
Corporate email infiltration
Infiltration of corporate email accounts
Phishing attackers send emails with professionally designed QR codes asking recipients to scan them to authenticate their account, access a document, etc. Since QR code is an image and not a link, such attacks go undetected by any anti-phishing email security software.
Parcel delivery scams
These are widespread in Nigeria and throughout West Africa, where scam messages tell the victim that a package is waiting for pickup and then ask him/her to scan a QR code to “reschedule delivery”. This code takes the victim to an impersonation website.
The cybersecurity implications
In organizations, quishing presents a major blind spot in terms of current security infrastructure. The most common security measures such as email gateways, web proxies, and URL reputation filters are not meant for scanning QR code payloads. This means that an attack may go undetected by enterprise-level defense mechanisms, especially when the attack is delivered through physical media and not digitally.
The implications of a quishing attack may include stealing of credentials, fraudulent financial transactions, installing malware on a victim’s computer, and even accessing corporate systems without authorization. From an individual point of view, the impact of a QR phishing attack may be just as damaging as identity theft, compromising a person’s bank account and taking control of their devices.
Considering the current push towards digitization of payments, onboarding, and customer communication in African countries, there is a need for businesses to address the threat posed by QR phishing attacks. In other words, while technology is facilitating financial inclusion and economic development in Africa, it is simultaneously opening new attack vectors that cybercriminals are utilizing.
“Often times, the most dangerous threats are those that are invisible. A QR code is invisible threat intelligence — and most people scan without giving it a second thought.”
How to protect yourself
The practical reality of quishing is that awareness remains the most effective first line of defense. No security tool can fully substitute for an informed user who approaches QR codes with appropriate skepticism.
- Think before you scan — You should treat every QR code just like you would an unknown link. If you did not expect one or cannot vouch for where it came from, think twice. Scanning a QR code is much too convenient when it means risking your credentials.
- Check the physical code — Before scanning any QR code in public, you should inspect whether it has been tampered with by replacing another QR code. Signs of this include bubbling edges, misaligned codes, or simply looking visually different from others around it.
- Check the destination URL — Most modern smartphones give you a preview of the URL you are going to land on before loading the page. Take advantage of it, and if the domain does not look right, do not go any further.
- Use mobile security software – Mobile threat defense tools can identify malicious websites and prevent access to the phishing infrastructure in real-time. If an organization is providing devices to its employees, mobile endpoint protection should be made mandatory.
What organization’s must do
Although individual awareness is essential, it is not enough by itself. Organizations that use QR codes as part of their business processes or that have employees and customers that use them frequently have an obligation to take this threat seriously.
— Educate staff about QR-code attack methods and include quishing cases in security training programs.
— Deploy mobile threat defense technologies on all devices used by both employees and customers.
— Carry out audits of physical environments such as office spaces, retail spaces, and events venues for any tampered or unauthorized QR codes.
— Use branded QR codes that can be verified by the recipient before scanning.
— Collaborate with security experts to design a response plan for QR-related threats.
The road ahead
With more embedding of QR codes into the infrastructure that facilitates contactless payments, digital identity management, smart cities and healthcare access, the potential attack surface will only grow. It is the duty of the organizations and governments constructing this infrastructure to think about security issues from the beginning, rather than an afterthought.
The security industry understands this, and there are some emerging technologies on the horizon. This includes secure QR codes with cryptographic verification built-in, AI-driven real-time risk assessments for mobile QR scanning apps, and QR threat intelligence integrated into zero trust security platforms. All very promising but all also requiring some time until mainstream adoption.
Until then, it is up to users scanning codes and organizations deploying them. A QR code is a convenience technology. Scan it recklessly, and it becomes an attack vector. The line between those two scenarios is awareness and action.
“The next time you scan a QR code, ask yourself one question: do you really know where it leads?”





