TechTarget.com/searchsecurity

https://www.techtarget.com/searchsecurity/feature/Quishing-on-the-rise-How-to-prevent-QR-code-phishing

QR code phishing: 14 quishing prevention tips

By Alissa Irei

During the COVID-19 pandemic, QR codes became popular among restaurants and other businesses looking to facilitate contactless interactions. Today, cybercriminals are turning to email-based QR code phishing attacks, and fraud is on the menu.

Quishing, also known as QR code phishing, is a type of phishing attack that tricks a user into scanning a malicious QR code with a mobile device. In a typical attack, the QR code opens a fraudulent website in the user's browser, which then might download malware or harvest sensitive information, such as login credentials or credit card numbers.

How a QR code works

A QR code, or quick response code, is a square barcode -- an image consisting of black squares on a white background -- that contains data. When a user points a compatible camera or app at a QR code, it scans the data and initiates an action, typically opening a webpage. It could also trigger a phone call, text message or digital payment.

QR codes are easy and inexpensive to create, and businesses often use them to facilitate customer interactions and transactions. A legitimate QR code might, for example, contain event ticketing details, payment portal information or a link to a company website. But the rising popularity of QR codes has also made them an attractive attack method for cybercriminals.

How quishing works

Traditional phishing campaigns try to induce users to download attachments or click on hyperlinked text. Email-based quishing attacks hide malicious links within QR code images and attempt to convince users to scan them using secondary mobile devices. Malicious QR codes are challenging to catch and block because most antiphishing email filters analyze texts and links but not images.

In a worst-case scenario, a successful quishing attack could compromise an enterprise user's credentials and give attackers access to a private corporate network. This could, in turn, lead to a data breach, ransomware attack or other serious cybersecurity incident.

In some cases, users might also encounter QR code scams offline. For example, criminals have previously attached QR code stickers to parking meters to direct drivers to fraudulent payment portals.

14 quishing prevention tips

The best way to prevent quishing -- or any type of phishing -- is to cultivate an educated user base. With that in mind, enterprises should provide security awareness training that teaches users the following:

Organizations should also consider the following quishing prevention security measures, which help combat all types of phishing:

Finally, some organizations might decide to avoid QR code use entirely. In this case, inform and regularly remind employees that they should not scan any QR codes they receive on their professional accounts or using company devices.

Alissa Irei is senior site editor of Informa TechTarget's SearchSecurity.

09 Apr 2025

All Rights Reserved, Copyright 2000 - 2025, TechTarget | Read our Privacy Statement