The email looks legitimate. The logo is correct, the tone is familiar, and the subject line says you need to verify access to your account. In the body of the message, instead of a link, there is a QR code. You scan it with your phone. At that moment you have left your company's protected environment and landed on a phishing page from a device that probably has none of the same security controls.

This is quishing — phishing via QR code — and according to ESET's threat report for the first half of 2026, one in eleven phishing emails detected during that period contained a malicious QR code. It is no longer an experimental technique: it is part of attackers' standard toolkit.

Imagen del artículo

🔍 Suspicious message?

Analyze senders, links or files in real time with our scanner.

Analyze now

Why QR codes bypass traditional security filters

A malicious link in an email is text. Email security systems can extract it, analyse it, compare it against databases of known fraudulent domains and block it before it reaches the user. A QR code is an image. The URL it encodes is hidden inside a visual pattern that most traditional email filters are not designed to decode and analyse.

That difference is the core of the technique. The attacker replaces the malicious link with a QR code encoding exactly the same URL, and in doing so bypasses a significant part of the detection chain. To add another layer of opacity, malicious QR codes are often embedded inside PDF files or JPEG images attached to the email — making automated extraction and analysis of the link even harder.

There is also a device-shift effect that attackers deliberately exploit. When an employee scans a QR code with their personal phone, they leave the corporate security perimeter — the work computer with its controls, policies and security software — and move to a mobile device that may have no equivalent controls. The attacker gets the victim to do the work of bypassing the organisation's security themselves.

How quishing is evolving

Quishing attacks documented in the first half of 2026 go well beyond credential theft through a fake login page. ESET researchers have identified variants designed to:

State-sponsored espionage groups have also incorporated quishing into their operations. In January 2026, the FBI warned that the North Korean Kimsuky group used malicious QR codes in spearphishing campaigns targeting think tanks, academic institutions and government bodies, disguising the code as a link to questionnaires or secure document platforms.

Why QR codes generate visual trust

A QR code as a visual object conveys a sense of legitimacy that a suspicious link does not always manage. During the pandemic, QR codes became the standard mechanism for accessing menus, registering for events and making payments — associated with legitimate services in trusted contexts. That familiarity is exactly what attackers exploit.

Combined with the impersonation of recognisable brands — Microsoft, DocuSign, the organisation's own IT department — and the usual urgency mechanism ("your session will expire", "verify your identity within 24 hours"), quishing replicates all the elements of classic phishing with the added advantage that the attack vector is invisible to the human eye: no one can read a URL encoded in a pattern of dots.

If you receive an email with a QR code

Don't do this:

Do this:

A QR code in an email is not suspicious by itself — but it is when it appears in an unsolicited message asking you to verify, authenticate or access something urgently. The URL it hides is just as analysable as any text link: you just need to extract it before opening it.