What’s new—and why this matters now
QR codes have been around for decades, but their explosion during the COVID-19 pandemic—for menus, payments, and check-ins—turned them into a goldmine for criminals. The FBI first warned in 2022 that attackers were hijacking QR codes to steal credentials or redirect payments. By late 2023, Microsoft researchers saw a sharp rise in QR phishing campaigns, particularly quishing attacks, and today, quishing is one of the fastest-growing phishing methods worldwide.
Criminals use QR codes because they:
- Bypass traditional defenses: A QR image embedded in an email or PDF often slips past security filters.
- Exploit mobile users: Most scans happen on phones, where it’s impossible to hover over a link to preview its destination, making quishing attacks more effective.
- Hide behind redirects: Quishing often uses shortened or trusted URLs that redirect to fake Microsoft 365 or banking logins.
- Trick in the real world: Fake QR code stickers on parking meters and posters send users to fraudulent payment portals.
- Steal beyond passwords: Advanced kits now use Adversary-in-the-Middle (AiTM) tactics to steal both credentials and session cookies.
📖 Read more background from Netcraft: Quishing is on the Rise and NBC News: QR Code Scams Are Growing.

The campaign we’re seeing at Symmetric IT Group
We’ve detected a phishing campaign targeting Accounting and HR teams that includes quishing attacks:
- Spoofed emails (appearing to come from inside your company).
- Attachments or images that instruct staff to “Scan the QR Code for more information.”
- Redirects to credential theft pages or malware sites.
We’ve turned on Impersonation Protection in AppRiver so spoofed emails are flagged as “spoofing.” Still, we can’t block the source outright because of how spoofing works. That means the best defense is awareness against quishing attacks.
👉 If you aren’t expecting the email—don’t scan the QR code.
Why quishing attacks works so well
Unlike a traditional phishing link you can hover over, QR codes mask their destination. Users often trust them blindly, which is why quishing has exploded. Victims who scan risk:
- Credential Theft (Microsoft 365, payroll, banking).
- Financial Fraud (bogus payment or payroll updates).
- Malware Infections (that can spread across your entire network).

How Symmetric IT Group protects you from QR scams
At Symmetric IT Group, we use layered defenses against phishing—including quishing:
- Email Security & AppRiver Protections: Stops spoofing and malicious attachments (Email Security Services).
- Endpoint & Network Protection: EDR and DNS filtering block malicious downloads (Managed IT Services).
- Security Awareness Training: Regular phishing drills—including QR-based simulations—train staff to spot threats (Employee Security Awareness Training).
- Rapid Response: If a scan slips through, we quickly revoke access, reset credentials, and hunt for malware.
What your team should do against quishing attacks
- Verify before scanning. If a QR asks you to log in, pay, or update records—go directly to the site or use a saved bookmark.
- Slow down. Urgent demands for payroll, banking, or HR action are classic red flags.
- Report it. Send any suspicious email to IT before interacting, especially if it involves quishing attacks.
- Educate staff. Regular training helps make smart decisions second nature.

Protecting What Matters Most
Quishing is an “easy button” for cybercriminals—and a blind spot for most employees. With awareness and layered protection against quishing attacks, your business can stay ahead.
👉 Want to strengthen your defenses against quishing and other phishing threats? Contact Symmetric IT Group today to get started.

