Secure Email Gateways (SEGs) have become proficient at detecting malicious hyperlinks in HTML email. Attackers responded by eliminating the hyperlink entirely — encoding the malicious URL inside a QR code image, which SEGs scan as a blank pixel matrix. Quishing (QR Code Phishing) is now one of the fastest-growing email threat vectors, with a measurable spike in campaign volume since 2023, precisely because it exploits the gap between what email security sees and what the human eye perceives.
1. What is Quishing and Who Gets Targeted?
Quishing sends an email containing a QR code image rather than a clickable text link. The email body uses urgency-driven corporate pretexts to pressure the recipient into scanning immediately, before applying scrutiny:
- "MFA Security Token Update Required — Action Required Within 24 Hours"
- "HR Payroll Direct Deposit Form — Signature Needed"
- "IT Help Desk: Re-authenticate Your Microsoft 365 Account"
- "Annual Benefits Enrollment — Deadline Today"
- "DocuSign: [Executive Name] Sent You a Document"
Target profiles skew toward corporate employees, specifically those who routinely use MFA, DocuSign, and HR portals — because the pretext is credible, the call-to-action (scan a QR code) matches normal enterprise workflows, and the scan happens on a personal mobile device outside corporate monitoring.
Notable documented quishing campaigns have targeted Microsoft 365 credential harvesting (2023 Cofense report, ~1,000 organizations affected), cryptocurrency exchange account takeovers, and wire fraud via fake invoice approval portals.
2. Why Quishing Bypasses Secure Email Gateways
Understanding the evasion mechanism explains why traditional email security fails at this specific threat:
A. Image Scanning Overhead and QR Detection Latency
A standard SEG inspects email for malicious URLs by parsing HTML <a href> attributes, text content, and header fields. Scanning every embedded image for QR codes requires optical character recognition (OCR) and barcode computer vision — operations that are 50–100× more computationally expensive per message than text parsing.
Most enterprise mail gateways process millions of messages per hour. Adding real-time QR decoding to that pipeline introduces delivery latency that SLAs prohibit. As a result, image scanning is either omitted, performed only on attached files (not inline images), or subject to size thresholds that attackers deliberately stay under.
B. The Mobile Context Switch
When a victim scans a QR code with their phone camera, the threat transitions from a monitored corporate environment to an unmanaged personal device. The corporate laptop has an EDR agent, DNS filtering, secure browser extensions, and network-level web proxies. The personal mobile phone connected to a cellular carrier has none of these controls. The victim lands on a credential harvesting page with no security tooling between them and the attacker's server.
C. URL Shorteners and Multi-Stage Redirects
Attackers rarely embed the final phishing URL directly in the QR code. Instead they chain:
- QR payload → legitimately registered URL shortener (bit.ly, qr.io, etc.)
- Shortener → cloaking gateway that checks IP/user-agent (see redirect cloaking)
- Cloaking gateway → final credential harvester (served only to real human victims)
This means that even if a SEG decodes the QR image and inspects the encoded URL, it sees a legitimate shortened URL — which is clean at the time of scanning. The malicious redirect is activated after the email is delivered.
3. QR Code Technical Anatomy — What's Actually Being Decoded
A QR code is a 2D matrix symbology. Understanding the structure helps understand why attackers prefer it over traditional URL obfuscation:
| QR Pattern Zone | Technical Function | Attacker Relevance |
|---|---|---|
| Finder Patterns | Three large corner squares for camera orientation detection | Required; cannot be modified without breaking decoding |
| Alignment Patterns | Interior squares correcting perspective distortion at angles | Version-dependent; higher QR versions add more patterns |
| Data + Error Correction Modules | Reed-Solomon encoded blocks containing URL payload | Up to 30% of modules can be damaged and still decode — allows cosmetic logo overlays |
| Format Information | Error correction level (L/M/Q/H) and mask pattern | High correction (H, 30%) allows brand logos overlaid on QR without breaking decode |
| Version Information | QR size (1–40); higher = more data capacity | Version 3+ needed for full HTTPS URLs; attackers use URL shorteners to fit in lower versions |
The Reed-Solomon error correction property is particularly useful to attackers: a QR code at error correction level H can have up to 30% of its modules damaged or overlaid before it fails to decode. This is why branded quishing emails can include a company logo watermarked over the QR code center — it looks like a legitimate branded communication while the encoded URL is fully intact underneath.
4. Attack Sophistication Levels
Not all quishing attacks are equal. Understanding the sophistication spectrum helps defenders prioritize controls:
| Sophistication Level | Characteristics | Detection Difficulty |
|---|---|---|
| Basic | Static QR image, direct URL to phishing domain, no evasion | Low — QR-aware SEGs catch these |
| Intermediate | URL shortener as QR payload; phishing domain registered after delivery | Medium — SEG sees clean URL; domain turns malicious post-delivery |
| Advanced | Multi-stage redirect chain + cloaking; mobile-only victim targeting; one-time token in URL that expires after first use | High — sandboxes see benign page; only real victim sees phishing portal |
| Targeted (BEC) | Victim-specific QR codes; personalized landing pages with prefilled email address; AiTM (adversary-in-the-middle) session capture for MFA bypass | Very High — each QR is unique; session cookies stolen even with MFA enabled |
5. Enterprise Defense Controls — Prioritized
Control 1: Deploy a QR-Aware Email Gateway
Modern SEGs from Proofpoint, Mimecast, Abnormal Security, and Microsoft Defender for Office 365 now include QR image detection. Verify that your SEG vendor has enabled QR decoding — it is often a feature toggle, not on by default. Test it by sending an internal test QR code embedding a known-bad domain and confirming the message is quarantined.
Control 2: Mobile Device Management (MDM) with Web Filtering
The mobile context switch is the core of why quishing works. MDM solutions (Microsoft Intune, Jamf, VMware Workspace ONE) with mobile threat defense (MTD) integration can enforce web filtering on corporate-enrolled devices. Require corporate device enrollment to access corporate resources, and block camera-to-browser QR scanning on personal devices through Bring Your Own Device (BYOD) policy.
Control 3: User Training — Teach the Camera Preview Truncation Problem
When iOS and Android display the URL from a scanned QR code as a camera preview popup, the URL is truncated after approximately 40–50 characters. A URL like https://paypal.account-security-update.co/verify?token=a9f2b... displays as https://paypal.account-security-update.co/... — the paypal prefix makes it look legitimate at first glance. Train users to:
- Never tap "Open" from the camera preview popup for any corporate QR code
- Copy the URL instead and paste it into a browser address bar for full inspection
- Use a dedicated QR scanner app that shows the full URL before opening it
Control 4: Pre-Scan QR Codes from Suspicious Emails
For any QR code received in an unexpected email — particularly one requesting credential entry — extract the URL and audit it before opening. IncogSay's QR Code URL Scanner accepts a QR image file by drag-and-drop. The engine decodes the Reed-Solomon matrix at the edge, extracts the URL payload, traces any redirect chain, checks the final destination domain's reputation, domain age, SSL certificate validity, and flags typosquatting or homograph characters — all without opening the URL in a browser.
Control 5: Enforce Phishing-Resistant MFA
Advanced quishing campaigns use adversary-in-the-middle (AiTM) proxies that capture the victim's session token even after a correct TOTP or push notification MFA response. Traditional TOTP (Google Authenticator, Authy) does not protect against AiTM. Deploy phishing-resistant MFA: FIDO2 hardware security keys (YubiKey, Titan) or passkeys. These bind authentication to the origin domain — the credential is physically impossible to use on a spoofed domain, regardless of how convincing the phishing page is.
6. How to Audit a Suspicious QR Code Without Opening It
- Do not scan the QR code with your phone's primary camera app — this opens the URL directly.
- Take a screenshot of the email or save the QR image to your computer.
- Upload the image to IncogSay's QR URL Scanner. The scanner decodes the image server-side, extracts the embedded URL, and runs a full threat analysis on the destination — including redirect chain tracing and domain reputation checks.
- If the scanner returns a threat score above 35, or flags a newly registered domain, a redirect chain, or a typosquatted domain, do not open the link. Report the email to your security team.
- If you need to verify the URL visually, paste it into IncogSay's URL Scanner for a second independent analysis.