New channel: QR / quishing

Train your team to question every QR code

Run realistic internal-company quishing simulations in email and on printed materials. Test the moment a QR code hides its destination, measure scans, and teach the warning signs immediately.

Why run quishing simulations

QR code phishing moves the decision away from familiar link checks and onto a phone. Train that scan-first blind spot before an attacker exploits it.

Test the scan-first blind spot

A QR code hides its destination until it is scanned. Measure whether people pause, verify the context, and recognize an unexpected request before continuing.

Simulate QR code lures in email

Send target-specific QR codes inside realistic, AI-assisted phishing emails without exposing a fallback text link that gives the QR phishing exercise away.

Extend training into physical spaces

Create printable QR phishing materials for named locations such as an office, reception area, noticeboard, or event and compare placement-level scans.

Report QR risk clearly

Track QR scans as their own interaction instead of blending them into ordinary link clicks, while keeping email delivery and opens as transport metrics.

Teach at the moment of risk

After a scan, show QR-specific warning signs such as unexpected prompts, hidden destinations, mismatched context, and scan-now pressure.

Use one awareness platform

Quishing runs alongside email phishing and SMS smishing campaigns with the same target lists, scheduling, landing experiences, reporting, and training workflow.

QR code phishing explained

What is quishing?

Quishing — short for QR code phishing — is a phishing attack that uses a QR code instead of a visible link to deliver a malicious destination. Because the URL is packed into a square of dots, the target cannot hover to preview it or spot a misspelled domain. Scanning is an act of trust, and quishing attacks are engineered to exploit exactly that reflex.

A QR phishing attack also jumps devices. The lure often arrives on a work computer, but the scan happens on a personal phone, outside the reach of email gateways, URL rewriting, and endpoint controls. On a small screen a spoofed login page is harder to inspect, so a malicious QR code that would be caught in the browser slips straight through.

QR codes now appear on parcels, invoices, parking meters, restaurant menus, posters, and multi-factor prompts, so a QR code scam blends into everyday behavior. Running quishing simulations turns that scan-first blind spot into measured, teachable moments before a real attacker reaches your people.

Digital and physical delivery

One quishing program, two realistic surfaces

Test targeted inbox attacks and anonymous real-world QR code placements without splitting your awareness data across separate tools.

Email QR code simulations

Each recipient receives an individual QR code embedded in a QR-ready phishing simulation email. Scans can be attributed to the target and continue through the same branded landing and education flow as other AutoPhish campaigns.

Printable location simulations

Generate stable print-ready QR phishing materials for named campaign locations. Anonymous scans remain placement-level signals, so reports do not pretend to identify a person who only scanned a public poster.

Both surfaces, one campaign

Combined email + print simulations

Run emailed QR codes and printed QR posters together in a single quishing campaign. Compare inbox attacks and physical-placement scans side by side, keep target-level and location-level attribution intact, and report on the whole QR phishing picture from one dashboard.

Internal workplace simulations

Credible internal QR code scenarios

Rehearse QR lures from familiar internal teams while keeping every simulation inside your company identity.

Company events & vouchers

An internal invitation or employee reward asks people to scan a QR code to register, confirm attendance, or claim a benefit.

MFA & password resets

An internal IT or Security message claims you must re-enroll multi-factor authentication or reset a password, routing the QR scan to a spoofed single sign-on page.

Workplace policy & training

An HR, Compliance, or Learning message asks employees to scan a QR code to acknowledge a policy, enroll in training, or retrieve a certificate.

Visitor registration

An internal Reception or Facilities notice asks employees to scan a QR code to register or confirm an expected visitor or contractor.

HR & benefits portals

A QR code in an HR or payroll email offers a benefits update or e-signature, then captures corporate credentials through a cloned login.

Guest Wi-Fi & onboarding

An internal IT or Facilities guest-access notice in reception asks employees to scan for Wi-Fi or onboarding and leads somewhere unsafe instead of the real network.

From QR idea to measurable learning

Build, place, and evaluate a QR code phishing simulation in the same campaign workflow as your other awareness channels.

1

Choose the scenario and surfaces

Create a quishing campaign, select a realistic QR call to action, add a target list for email, and define any printable locations you want to test.

2

Preview QR-ready material

Review the email without raw fallback links and generate print-ready QR material for each saved location before the campaign reaches learners.

3

Launch, measure, and train

Track target-attributed and location-level QR scans separately, review channel-aware reports, and reinforce the exact quishing warning signs learners missed.

Safe simulation destinations by design

Quishing exercises should teach caution without introducing an uncontrolled QR redirect or misleading person-level data.

QR code destinations use opaque AutoPhish simulation links rather than arbitrary external URLs.

Invalid, deleted, expired, draft-only, or inactive QR links fail safely.

Target scans and anonymous print-location scans are reported as different kinds of evidence.

Likely automated scanner traffic can be separated from human interactions.

Company-owned campaign and scan data remains tenant-scoped.

EU-hosted infrastructure supports GDPR-ready awareness programs and reporting.

Quishing simulation FAQ

What is quishing?
Quishing is QR code phishing — a phishing attack that uses a QR code to hide or deliver the malicious destination. The code may appear in an email, poster, document, parcel notice, or sign. Scanning moves the person onto a phone, where the destination is harder to inspect before opening.
How is quishing different from regular phishing?
Traditional phishing shows a clickable link the recipient can hover over and inspect. A QR code phishing attack replaces that link with a scannable image, so the URL is invisible until scanned, the action usually moves to a personal phone, and it often bypasses email link scanning and endpoint controls.
Are QR codes dangerous?
A QR code is only as safe as the destination it encodes. Malicious QR codes can lead to credential-harvesting pages, fraudulent payment portals, or hostile app and profile installs. Quishing awareness training teaches people to verify context and destination before acting on any scan.
How does a quishing simulation work in AutoPhish?
AutoPhish generates an opaque simulation QR link, places it in a QR-ready email or printable material, records valid scans, and routes the learner through the existing simulation landing and education flow.
Can I test both emailed and printed QR codes?
Yes. A quishing campaign can send target-specific QR codes by email and generate printable QR phishing materials for named locations. The two surfaces share one campaign while preserving the right attribution model for each.
How can employees prevent QR code phishing?
Treat unexpected QR codes like unexpected links: check who is really asking, be wary of urgency and payment or login prompts, confirm the destination domain before entering credentials, and use a scanner that previews the URL. Regular quishing simulations turn that guidance into reliable habits.
Can a poster scan identify an employee?
Not by itself. A print-location scan is anonymous and reported at campaign and placement level. It does not become a person-level outcome unless the learner later identifies themselves through the simulation flow.
What does quishing reporting measure?
Reports expose QR scans as a dedicated metric, keep email delivery and opens as transport metrics, separate target-attributed scans from print-location activity, and support channel filters for email, SMS, and quishing.
Can I automate quishing campaigns through the API?
Yes. AutoPhish public API v1 supports creating and updating quishing campaigns, generating print materials, and retrieving QR-aware reports, subject to the company's plan entitlement and API permissions.

Still have questions? Talk to our team.

Add QR code phishing to your awareness program

Test the inbox and the physical workplace from one platform, then turn every risky scan into measurable learning.