Quishing: The Easy Way for Cybercriminals to Fool You

What’s new—and why this matters now

QR codes have been around for decades, but their explosion during the COVID-19 pandemic—for menus, payments, and check-ins—turned them into a goldmine for criminals. The FBI first warned in 2022 that attackers were hijacking QR codes to steal credentials or redirect payments. By late 2023, Microsoft researchers saw a sharp rise in QR phishing campaigns, particularly quishing attacks, and today, quishing is one of the fastest-growing phishing methods worldwide.

Criminals use QR codes because they:

  • Bypass traditional defenses: A QR image embedded in an email or PDF often slips past security filters.
  • Exploit mobile users: Most scans happen on phones, where it’s impossible to hover over a link to preview its destination, making quishing attacks more effective.
  • Hide behind redirects: Quishing often uses shortened or trusted URLs that redirect to fake Microsoft 365 or banking logins.
  • Trick in the real world: Fake QR code stickers on parking meters and posters send users to fraudulent payment portals.
  • Steal beyond passwords: Advanced kits now use Adversary-in-the-Middle (AiTM) tactics to steal both credentials and session cookies.

📖 Read more background from Netcraft: Quishing is on the Rise and NBC News: QR Code Scams Are Growing.

The campaign we’re seeing at Symmetric IT Group

We’ve detected a phishing campaign targeting Accounting and HR teams that includes quishing attacks:

  • Spoofed emails (appearing to come from inside your company).
  • Attachments or images that instruct staff to “Scan the QR Code for more information.”
  • Redirects to credential theft pages or malware sites.

We’ve turned on Impersonation Protection in AppRiver so spoofed emails are flagged as “spoofing.” Still, we can’t block the source outright because of how spoofing works. That means the best defense is awareness against quishing attacks.

👉 If you aren’t expecting the email—don’t scan the QR code.

Why quishing attacks works so well

Unlike a traditional phishing link you can hover over, QR codes mask their destination. Users often trust them blindly, which is why quishing has exploded. Victims who scan risk:

  • Credential Theft (Microsoft 365, payroll, banking).
  • Financial Fraud (bogus payment or payroll updates).
  • Malware Infections (that can spread across your entire network).

How Symmetric IT Group protects you from QR scams

At Symmetric IT Group, we use layered defenses against phishing—including quishing:

  • Email Security & AppRiver Protections: Stops spoofing and malicious attachments (Email Security Services).
  • Endpoint & Network Protection: EDR and DNS filtering block malicious downloads (Managed IT Services).
  • Security Awareness Training: Regular phishing drills—including QR-based simulations—train staff to spot threats (Employee Security Awareness Training).
  • Rapid Response: If a scan slips through, we quickly revoke access, reset credentials, and hunt for malware.

What your team should do against quishing attacks

  1. Verify before scanning. If a QR asks you to log in, pay, or update records—go directly to the site or use a saved bookmark.
  2. Slow down. Urgent demands for payroll, banking, or HR action are classic red flags.
  3. Report it. Send any suspicious email to IT before interacting, especially if it involves quishing attacks.
  4. Educate staff. Regular training helps make smart decisions second nature.

Protecting What Matters Most

Quishing is an “easy button” for cybercriminals—and a blind spot for most employees. With awareness and layered protection against quishing attacks, your business can stay ahead.

👉 Want to strengthen your defenses against quishing and other phishing threats? Contact Symmetric IT Group today to get started.

Interested in our Services?

You should be able to run your business without having to worry about managed it support or the security of your data.

Read more about our services and how we can help you.

Related Posts

Schedule Your Free Consultation

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Services you are interested in?*
Yes, subscribe me to Newsletter

Schedule Your
Free Consultation

Are you exposed to cybersecurity, or technology obsolescence risks? Are their ways to reduce your ongoing Managed IT Support costs or improve business operations?

Information Security by your Managed IT Services provider