Secure Email Gateways (SEGs) have become proficient at detecting malicious hyperlinks in HTML email. Attackers responded by eliminating the hyperlink entirely — encoding the malicious URL inside a QR code image, which SEGs scan as a blank pixel matrix. Quishing (QR Code Phishing) is now one of the fastest-growing email threat vectors, with a measurable spike in campaign volume since 2023, precisely because it exploits the gap between what email security sees and what the human eye perceives.

1. What is Quishing and Who Gets Targeted?

Quishing sends an email containing a QR code image rather than a clickable text link. The email body uses urgency-driven corporate pretexts to pressure the recipient into scanning immediately, before applying scrutiny:

  • "MFA Security Token Update Required — Action Required Within 24 Hours"
  • "HR Payroll Direct Deposit Form — Signature Needed"
  • "IT Help Desk: Re-authenticate Your Microsoft 365 Account"
  • "Annual Benefits Enrollment — Deadline Today"
  • "DocuSign: [Executive Name] Sent You a Document"

Target profiles skew toward corporate employees, specifically those who routinely use MFA, DocuSign, and HR portals — because the pretext is credible, the call-to-action (scan a QR code) matches normal enterprise workflows, and the scan happens on a personal mobile device outside corporate monitoring.

Notable documented quishing campaigns have targeted Microsoft 365 credential harvesting (2023 Cofense report, ~1,000 organizations affected), cryptocurrency exchange account takeovers, and wire fraud via fake invoice approval portals.

2. Why Quishing Bypasses Secure Email Gateways

Understanding the evasion mechanism explains why traditional email security fails at this specific threat:

A. Image Scanning Overhead and QR Detection Latency

A standard SEG inspects email for malicious URLs by parsing HTML <a href> attributes, text content, and header fields. Scanning every embedded image for QR codes requires optical character recognition (OCR) and barcode computer vision — operations that are 50–100× more computationally expensive per message than text parsing.

Most enterprise mail gateways process millions of messages per hour. Adding real-time QR decoding to that pipeline introduces delivery latency that SLAs prohibit. As a result, image scanning is either omitted, performed only on attached files (not inline images), or subject to size thresholds that attackers deliberately stay under.

B. The Mobile Context Switch

When a victim scans a QR code with their phone camera, the threat transitions from a monitored corporate environment to an unmanaged personal device. The corporate laptop has an EDR agent, DNS filtering, secure browser extensions, and network-level web proxies. The personal mobile phone connected to a cellular carrier has none of these controls. The victim lands on a credential harvesting page with no security tooling between them and the attacker's server.

C. URL Shorteners and Multi-Stage Redirects

Attackers rarely embed the final phishing URL directly in the QR code. Instead they chain:

  • QR payload → legitimately registered URL shortener (bit.ly, qr.io, etc.)
  • Shortener → cloaking gateway that checks IP/user-agent (see redirect cloaking)
  • Cloaking gateway → final credential harvester (served only to real human victims)

This means that even if a SEG decodes the QR image and inspects the encoded URL, it sees a legitimate shortened URL — which is clean at the time of scanning. The malicious redirect is activated after the email is delivered.

3. QR Code Technical Anatomy — What's Actually Being Decoded

A QR code is a 2D matrix symbology. Understanding the structure helps understand why attackers prefer it over traditional URL obfuscation:

QR Pattern ZoneTechnical FunctionAttacker Relevance
Finder PatternsThree large corner squares for camera orientation detectionRequired; cannot be modified without breaking decoding
Alignment PatternsInterior squares correcting perspective distortion at anglesVersion-dependent; higher QR versions add more patterns
Data + Error Correction ModulesReed-Solomon encoded blocks containing URL payloadUp to 30% of modules can be damaged and still decode — allows cosmetic logo overlays
Format InformationError correction level (L/M/Q/H) and mask patternHigh correction (H, 30%) allows brand logos overlaid on QR without breaking decode
Version InformationQR size (1–40); higher = more data capacityVersion 3+ needed for full HTTPS URLs; attackers use URL shorteners to fit in lower versions

The Reed-Solomon error correction property is particularly useful to attackers: a QR code at error correction level H can have up to 30% of its modules damaged or overlaid before it fails to decode. This is why branded quishing emails can include a company logo watermarked over the QR code center — it looks like a legitimate branded communication while the encoded URL is fully intact underneath.

4. Attack Sophistication Levels

Not all quishing attacks are equal. Understanding the sophistication spectrum helps defenders prioritize controls:

Sophistication LevelCharacteristicsDetection Difficulty
BasicStatic QR image, direct URL to phishing domain, no evasionLow — QR-aware SEGs catch these
IntermediateURL shortener as QR payload; phishing domain registered after deliveryMedium — SEG sees clean URL; domain turns malicious post-delivery
AdvancedMulti-stage redirect chain + cloaking; mobile-only victim targeting; one-time token in URL that expires after first useHigh — sandboxes see benign page; only real victim sees phishing portal
Targeted (BEC)Victim-specific QR codes; personalized landing pages with prefilled email address; AiTM (adversary-in-the-middle) session capture for MFA bypassVery High — each QR is unique; session cookies stolen even with MFA enabled

5. Enterprise Defense Controls — Prioritized

Control 1: Deploy a QR-Aware Email Gateway

Modern SEGs from Proofpoint, Mimecast, Abnormal Security, and Microsoft Defender for Office 365 now include QR image detection. Verify that your SEG vendor has enabled QR decoding — it is often a feature toggle, not on by default. Test it by sending an internal test QR code embedding a known-bad domain and confirming the message is quarantined.

Control 2: Mobile Device Management (MDM) with Web Filtering

The mobile context switch is the core of why quishing works. MDM solutions (Microsoft Intune, Jamf, VMware Workspace ONE) with mobile threat defense (MTD) integration can enforce web filtering on corporate-enrolled devices. Require corporate device enrollment to access corporate resources, and block camera-to-browser QR scanning on personal devices through Bring Your Own Device (BYOD) policy.

Control 3: User Training — Teach the Camera Preview Truncation Problem

When iOS and Android display the URL from a scanned QR code as a camera preview popup, the URL is truncated after approximately 40–50 characters. A URL like https://paypal.account-security-update.co/verify?token=a9f2b... displays as https://paypal.account-security-update.co/... — the paypal prefix makes it look legitimate at first glance. Train users to:

  • Never tap "Open" from the camera preview popup for any corporate QR code
  • Copy the URL instead and paste it into a browser address bar for full inspection
  • Use a dedicated QR scanner app that shows the full URL before opening it

Control 4: Pre-Scan QR Codes from Suspicious Emails

For any QR code received in an unexpected email — particularly one requesting credential entry — extract the URL and audit it before opening. IncogSay's QR Code URL Scanner accepts a QR image file by drag-and-drop. The engine decodes the Reed-Solomon matrix at the edge, extracts the URL payload, traces any redirect chain, checks the final destination domain's reputation, domain age, SSL certificate validity, and flags typosquatting or homograph characters — all without opening the URL in a browser.

Control 5: Enforce Phishing-Resistant MFA

Advanced quishing campaigns use adversary-in-the-middle (AiTM) proxies that capture the victim's session token even after a correct TOTP or push notification MFA response. Traditional TOTP (Google Authenticator, Authy) does not protect against AiTM. Deploy phishing-resistant MFA: FIDO2 hardware security keys (YubiKey, Titan) or passkeys. These bind authentication to the origin domain — the credential is physically impossible to use on a spoofed domain, regardless of how convincing the phishing page is.

6. How to Audit a Suspicious QR Code Without Opening It

  1. Do not scan the QR code with your phone's primary camera app — this opens the URL directly.
  2. Take a screenshot of the email or save the QR image to your computer.
  3. Upload the image to IncogSay's QR URL Scanner. The scanner decodes the image server-side, extracts the embedded URL, and runs a full threat analysis on the destination — including redirect chain tracing and domain reputation checks.
  4. If the scanner returns a threat score above 35, or flags a newly registered domain, a redirect chain, or a typosquatted domain, do not open the link. Report the email to your security team.
  5. If you need to verify the URL visually, paste it into IncogSay's URL Scanner for a second independent analysis.