Quishing: QR Code Phishing Is Evading Every Email Security Gateway

Email security has never been better. Machine learning classifiers, sandboxed URL detonation, real-time reputation scoring, and AI-powered phishing detection have made it substantially harder to land a malicious link in someone’s inbox. Security vendors have invested billions in solving the problem of malicious URLs in email.
So attackers stopped putting URLs in email.
Instead, they put them in QR codes.
QR code phishing also known in the security industry as quishing has emerged as one of the fastest growing attack techniques of 2025 and 2026, exploiting a simple but devastating blind spot in email security architecture: gateways scan text and URLs. They cannot read a QR code embedded in an image.
The malicious URL is completely invisible to every major email security platform currently deployed.
Quishing is the delivery of phishing URLs via QR codes rather than clickable hyperlinks. The attack chain is elegantly simple:
- The attacker generates a QR code encoding a malicious URL
- The QR code is embedded in an HTML email as an image and often designed within a convincing branded template
- The email passes through the victim’s email security gateway without triggering any URL-based detection rules, because there are no URLs in the email body — only an image
- The email reaches the inbox
- The victim scans the QR code with their mobile phone camera
- The mobile browser navigates to the phishing URL
The phishing flow completes on the mobile device
That final step is particularly significant. The attack lands on a mobile phone — a device that typically has far weaker security controls than a corporate laptop. No enterprise browser extension with URL filtering. No EDR agent monitoring process execution. No corporate proxy inspecting the outbound traffic. The attacker has bypassed both the email security gateway and the endpoint security stack in a single technique.
To understand why quishing is so effective, it helps to understand how email security gateways work.
Modern secure email gateways (SEGs) use several complementary detection mechanisms:
URL extraction — the gateway parses the email HTML and text body looking for href attributes, anchor tags, and plain-text URLs. It extracts every link it finds.
URL reputation checking — extracted URLs are checked against threat intelligence feeds in real time. Known malicious URLs are blocked immediately.
URL sandboxing — for unknown or suspicious URLs, the gateway follows the link in a sandboxed environment and analyses the resulting webpage for phishing indicators — login forms, credential harvesting scripts, brand impersonation.
Machine learning classification — the overall email is scored against models trained on millions of phishing samples, looking at sender reputation, email structure, language patterns, and content features.
None of these mechanisms extract URLs from QR codes. A QR code in an email is processed as an image file — a block of pixels. Without specific QR code scanning capability (which most deployed SEGs lack or have only partially implemented), the URL inside is invisible.
Even platforms that have begun implementing QR code image analysis face a cat-and-mouse challenge. Attackers have responded by:
- Using high-contrast QR codes that are harder for automated scanners to decode
- Embedding QR codes within documents (PDFs, DOCX files) attached to the email rather than in the email body itself
- Using QR codes that redirect through legitimate URL shorteners or redirection services before reaching the phishing page
- Rotating QR code images frequently to defeat hash-based detection
PhishScout’s threat intelligence feeds and community submissions have identified the following active quishing campaign types in 2026:
Microsoft MFA Re-registration — the most prevalent. Corporate employees receive an email from apparent Microsoft IT security stating their MFA device needs re-registration. A QR code is provided to “scan to re-register your device securely.” The code leads to an AiTM phishing proxy targeting Microsoft 365 credentials and session tokens. The combination of MFA-bypass technique with QR delivery makes this particularly dangerous.
HR and Payroll Portals — emails impersonating HR departments direct employees to scan a QR code to access a new payroll portal, benefits system, or onboarding document. Effective particularly against new employees who are conditioned to complete HR processes without questioning them. Seen targeting NHS Trusts, local authorities, and large retailers.
SharePoint and OneDrive Document Sharing — emails mimicking Microsoft SharePoint notifications tell recipients a document has been shared with them and a QR code is provided to “access securely.” The phishing page captures Microsoft 365 credentials.
Parcel Delivery (Physical Mail) — an evolution of the digital attack vector. Physical packages or leaflets contain QR codes supposedly linking to tracking information, customs payment portals, or delivery scheduling. This extends quishing entirely outside the email security perimeter — there is no email gateway to bypass because there is no email.
Multi-Stage: MFA Fatigue + Quishing — a sophisticated combined attack. The threat actor first triggers repeated Microsoft Authenticator push notifications to exhaust and frustrate the victim. When the victim doesn’t approve, a follow-up email arrives offering a “simpler” QR-based re-authentication method. The emotional state of the victim (frustrated, wanting to resolve the issue quickly) increases click-through rate substantially.
Fake Invoice Payment — finance team targeting. An email with a PDF attachment contains a QR code within the PDF, directing the victim to a payment portal to “verify” an outstanding invoice. The portal harvests corporate banking credentials.
Quishing campaigns are targeted with precision. Analysis of known campaigns reveals clear victim selection patterns:
Executives and their personal assistants — high value targets who regularly scan QR codes in professional contexts (conferences, business cards, documents) and are less likely to question a QR code in a professional-looking email.
Finance and accounts payable teams — targeted because their actions (approving payments, updating banking details) have immediate high-value financial consequences.
HR and payroll teams — targeted because they process personal data and have access to banking details for direct deposit fraud.
New employees — particularly vulnerable because they have a legitimate expectation of receiving onboarding communications with links, portals, and documents to access. They haven’t yet built up the pattern recognition that identifies unusual requests.
Healthcare workers — NHS Trusts have been specifically targeted with quishing campaigns impersonating NHS Digital, NHS login, and CQRS (Calculating Quality Reporting Service) portals.
Microsoft 365 environments — the overwhelming majority of quishing campaigns target Microsoft 365 credentials, reflecting both the ubiquity of M365 and the value of a compromised Microsoft session token.
The email security vendor landscape has begun responding to quishing, but coverage remains inconsistent.
Microsoft Defender for Office 365 has QR code URL extraction in its preview/advanced features. When enabled, it can extract the URL from a QR code image and subject it to standard URL analysis and sandboxing. Enable this in the Microsoft 365 Defender portal under Email & Collaboration → Policies.
Proofpoint released QR code detection capabilities in late 2024, scanning QR code images in email bodies and extracting URLs for reputation and sandbox analysis.
Mimecast has announced QR code scanning features, with coverage expanding through 2025-2026.
Awareness gap: Even with vendor QR scanning, attackers who embed QR codes in PDF attachments (rather than the email body directly) bypass most current scanning implementations, as attachment-level QR code scanning is even less widely deployed.
For security teams:
Enable QR code scanning in your email security gateway if your vendor supports it. Check your SEG’s release notes and admin console for this capability — it may require explicit enablement.
Consider a policy-based approach for high-risk groups: flag all emails from external senders containing image attachments for enhanced review, or quarantine external emails containing QR codes if your business has limited legitimate use cases for them.
Extend your phishing simulation programme to include quishing scenarios. Most major simulation platforms (KnowBe4, Proofpoint Security Awareness, Cofense) now support QR code phishing simulations. If your team hasn’t been tested on quishing, they haven’t been adequately prepared.
Implement Mobile Device Management (MDM) solutions that can enforce safe browsing on corporate mobile devices. If employees scan a QR code on a managed device running a protected browser, the malicious URL may still be caught at the device level.
For end users:
Before scanning any QR code in an email, use your phone camera to preview the URL before opening it. Most modern smartphone cameras display the decoded URL before navigating — take one second to read it. If the URL doesn’t match the claimed sender’s domain, do not proceed.
Never scan a QR code in an unsolicited email, regardless of how legitimate it appears. Legitimate organisations — Microsoft, your employer, your bank — will not ask you to scan a QR code to re-authenticate or complete a security action without prior notice through established channels.
If you receive a suspicious QR code email at work, report it to your security team before scanning it. The QR code itself is harmless — it’s just an image. The danger is in scanning it.
For security awareness programmes:
Update your phishing awareness training to explicitly cover QR code phishing. Traditional phishing training teaches people to hover over links — a skill that’s completely irrelevant for quishing. The awareness behaviour you need to build is: treat QR codes in unsolicited emails with the same suspicion as unsolicited links.
YARA Detection Rule
```yaml
rule Quishing_Email_Embedded_QR
{
meta:
description = "Detects emails with embedded QR code images - potential quishing"
author = "PhishScout Research Team"
date = "2026-05-10"
severity = "medium"
strings:
$png_header = { 89 50 4E 47 0D 0A 1A 0A }
$jpeg_header = { FF D8 FF }
$content_inline = "Content-Disposition: inline"
$content_image = "Content-Type: image/"
$qr_ref_1 = "scan" nocase
$qr_ref_2 = "QR" nocase
$qr_ref_3 = "camera" nocase
condition:
($png_header or $jpeg_header) and
$content_inline and
$content_image and
any of ($qr_ref_*)
}
```
Sigma Detection Rule
```yaml
title: Quishing Attempt - QR Code URL Navigation from Email Client Process
id: 8a3f2b1c-4d5e-6f7a-8b9c-0d1e2f3a4b5c
status: experimental
description: Detects browser navigation to external URLs immediately following email client activity - may indicate QR code scan from email
logsource:
category: network_connection
product: windows
detection:
selection:
ParentImage|contains:
- 'outlook.exe'
- 'thunderbird.exe'
- 'chrome.exe'
filter_legit:
DestinationHostname|endswith:
- 'microsoft.com'
- 'office.com'
- 'google.com'
condition: selection and not filter_legit
falsepositives:
- Legitimate link clicks from email
level: low
tags:
- attack.initial_access
- attack.t1566
```
Quishing represents a fundamental evolution in phishing technique — one that deliberately exploits the gap between where email security operates (the email gateway) and where the attack completes (the mobile device). The technique is simple, effective, and widely deployed.
The defence requires a layered response: gateway-level QR code scanning, device-level safe browsing on mobile, user awareness training that explicitly covers QR phishing, and phishing simulations that test this specific vector. Organisations that assume their existing email security controls cover quishing are mistaken — and that mistaken assumption is exactly what attackers are counting on.
—
Report quishing emails to PhishScout at phishscout.net