Train your team to question every QR code
Run realistic internal-company quishing simulations in email and on printed materials. Test the moment a QR code hides its destination, measure scans, and teach the warning signs immediately.
Why run quishing simulations
QR code phishing moves the decision away from familiar link checks and onto a phone. Train that scan-first blind spot before an attacker exploits it.
Test the scan-first blind spot
A QR code hides its destination until it is scanned. Measure whether people pause, verify the context, and recognize an unexpected request before continuing.
Simulate QR code lures in email
Send target-specific QR codes inside realistic, AI-assisted phishing emails without exposing a fallback text link that gives the QR phishing exercise away.
Extend training into physical spaces
Create printable QR phishing materials for named locations such as an office, reception area, noticeboard, or event and compare placement-level scans.
Report QR risk clearly
Track QR scans as their own interaction instead of blending them into ordinary link clicks, while keeping email delivery and opens as transport metrics.
Teach at the moment of risk
After a scan, show QR-specific warning signs such as unexpected prompts, hidden destinations, mismatched context, and scan-now pressure.
Use one awareness platform
Quishing runs alongside email phishing and SMS smishing campaigns with the same target lists, scheduling, landing experiences, reporting, and training workflow.
What is quishing?
Quishing — short for QR code phishing — is a phishing attack that uses a QR code instead of a visible link to deliver a malicious destination. Because the URL is packed into a square of dots, the target cannot hover to preview it or spot a misspelled domain. Scanning is an act of trust, and quishing attacks are engineered to exploit exactly that reflex.
A QR phishing attack also jumps devices. The lure often arrives on a work computer, but the scan happens on a personal phone, outside the reach of email gateways, URL rewriting, and endpoint controls. On a small screen a spoofed login page is harder to inspect, so a malicious QR code that would be caught in the browser slips straight through.
QR codes now appear on parcels, invoices, parking meters, restaurant menus, posters, and multi-factor prompts, so a QR code scam blends into everyday behavior. Running quishing simulations turns that scan-first blind spot into measured, teachable moments before a real attacker reaches your people.
One quishing program, two realistic surfaces
Test targeted inbox attacks and anonymous real-world QR code placements without splitting your awareness data across separate tools.
Email QR code simulations
Each recipient receives an individual QR code embedded in a QR-ready phishing simulation email. Scans can be attributed to the target and continue through the same branded landing and education flow as other AutoPhish campaigns.
Printable location simulations
Generate stable print-ready QR phishing materials for named campaign locations. Anonymous scans remain placement-level signals, so reports do not pretend to identify a person who only scanned a public poster.
Combined email + print simulations
Run emailed QR codes and printed QR posters together in a single quishing campaign. Compare inbox attacks and physical-placement scans side by side, keep target-level and location-level attribution intact, and report on the whole QR phishing picture from one dashboard.
Credible internal QR code scenarios
Rehearse QR lures from familiar internal teams while keeping every simulation inside your company identity.
Company events & vouchers
An internal invitation or employee reward asks people to scan a QR code to register, confirm attendance, or claim a benefit.
MFA & password resets
An internal IT or Security message claims you must re-enroll multi-factor authentication or reset a password, routing the QR scan to a spoofed single sign-on page.
Workplace policy & training
An HR, Compliance, or Learning message asks employees to scan a QR code to acknowledge a policy, enroll in training, or retrieve a certificate.
Visitor registration
An internal Reception or Facilities notice asks employees to scan a QR code to register or confirm an expected visitor or contractor.
HR & benefits portals
A QR code in an HR or payroll email offers a benefits update or e-signature, then captures corporate credentials through a cloned login.
Guest Wi-Fi & onboarding
An internal IT or Facilities guest-access notice in reception asks employees to scan for Wi-Fi or onboarding and leads somewhere unsafe instead of the real network.
From QR idea to measurable learning
Build, place, and evaluate a QR code phishing simulation in the same campaign workflow as your other awareness channels.
Choose the scenario and surfaces
Create a quishing campaign, select a realistic QR call to action, add a target list for email, and define any printable locations you want to test.
Preview QR-ready material
Review the email without raw fallback links and generate print-ready QR material for each saved location before the campaign reaches learners.
Launch, measure, and train
Track target-attributed and location-level QR scans separately, review channel-aware reports, and reinforce the exact quishing warning signs learners missed.
Safe simulation destinations by design
Quishing exercises should teach caution without introducing an uncontrolled QR redirect or misleading person-level data.
QR code destinations use opaque AutoPhish simulation links rather than arbitrary external URLs.
Invalid, deleted, expired, draft-only, or inactive QR links fail safely.
Target scans and anonymous print-location scans are reported as different kinds of evidence.
Likely automated scanner traffic can be separated from human interactions.
Company-owned campaign and scan data remains tenant-scoped.
EU-hosted infrastructure supports GDPR-ready awareness programs and reporting.
Quishing simulation FAQ
What is quishing?
How is quishing different from regular phishing?
Are QR codes dangerous?
How does a quishing simulation work in AutoPhish?
Can I test both emailed and printed QR codes?
How can employees prevent QR code phishing?
Can a poster scan identify an employee?
What does quishing reporting measure?
Can I automate quishing campaigns through the API?
Still have questions? Talk to our team.
Add QR code phishing to your awareness program
Test the inbox and the physical workplace from one platform, then turn every risky scan into measurable learning.