Quishing
Also called: QR code phishing
Quishing is phishing that hides a malicious link inside a QR code. The code arrives in an email, document, flyer or sticker, and scanning it opens a fake login or payment page on the victim's phone. Because the link is an image, it can slip past email filters that inspect written URLs.
How it works
The attacker embeds a QR code in a message that asks the target to scan it to view a document, verify an account or join a meeting. Scanning moves the victim from a managed work computer to a personal phone, where security controls are often weaker and the full web address is harder to check before typing a password.
A real example
In a January 2026 FLASH, the FBI said North Korean Kimsuky actors had targeted think tanks, academic institutions, and US and foreign government entities with malicious QR codes embedded in spearphishing campaigns.
Source: North Korean Kimsuky Actors Leverage Malicious QR Codes in Spearphishing Campaigns Targeting U.S. Entities (AC-000001-MW) — Federal Bureau of Investigation (FBI), 2026-01-08
The Identity Attack Ledger holds 31 cited incidents for phished or stolen credentials in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.
How to stop it
Phishing-resistant MFA bound to the real site's domain keeps a phone-captured password from working. Apply the same sign-in policies to mobile devices as to managed laptops.
Related terms
Sources
- North Korean Kimsuky Actors Leverage Malicious QR Codes in Spearphishing Campaigns Targeting U.S. Entities (AC-000001-MW) — Federal Bureau of Investigation (FBI), 2026-01-08
Last reviewed Oct 2, 2026