Quishing: The QR Code That Bypasses Email Security

Quishing: The QR Code That Bypasses Email Security

The QR code that walks straight past your email filter

Quishing, the practice of hiding a phishing link inside a QR code, grew by 146% between January and March 2026. That number should worry any business owner who has invested in email security, because quishing is designed specifically to make that investment irrelevant. The attack works by turning a link into a picture, and pictures do not get scanned the way text does.

For a European SMB, this matters more than the raw statistic suggests. Most small and medium businesses in Italy and across the EU have built their defenses around one assumption: dangerous things arrive by email, and the email gateway will catch them. Quishing quietly breaks that assumption without triggering a single alert.

The result is an attack that reaches the inbox intact, then leaves the corporate network entirely before the victim ever clicks anything. Understanding why requires looking at what a security filter actually does when it inspects a message.

Why QR code phishing defeats email security

A traditional email filter reads the text of a message. It extracts URLs, checks them against reputation databases, follows redirects, and analyzes the destination page. If the link points somewhere known to be malicious, the message is quarantined before anyone sees it. This process is fast, automated, and reasonably effective.

A QR code is an image file. To the filter, it is a block of pixels attached to a message, no different from a company logo or a scanned invoice. There is no URL string to extract, no domain to check, no redirect chain to follow. The malicious destination is encoded in a visual pattern that most gateways simply do not decode.

Attackers have refined this further. Many quishing campaigns now embed the QR code inside a PDF attachment, adding a second layer of obfuscation. Others use QR codes that resolve to a legitimate URL shortener, which then redirects to the actual phishing page, so even a filter that does decode the image sees a clean first hop.

The effect is that a corporate QR code attack arrives with a near perfect delivery rate. The security control that stops the overwhelming majority of ordinary phishing has no meaningful role to play here.

The attack moves to a device you do not control

The second reason quishing works so well is behavioral rather than technical. When an employee sees a QR code on their laptop screen, they do not scan it with the laptop. They pick up their phone.

That single movement takes the attack outside every protection your business has deployed. The corporate DNS filter that would block the malicious domain is on the company network, and the phone is on 4G. The endpoint protection agent that would flag the credential harvesting page is installed on the workstation, not on a personal device. The browser isolation, the web proxy, the URL rewriting in the mail client: none of it applies.

Mobile browsers also make phishing pages harder to spot. The address bar is short and often truncated, so a domain like microsoft-login-verify.secure-portal.io displays as something that looks plausible at a glance. There is no easy way to hover over a link to preview it, and the visual cues people are trained to check are compressed or hidden.

Personal phones add a further complication. On a BYOD device, the employee is usually already logged into personal accounts, is more relaxed, and is operating in a context they associate with private life rather than work. The mental guard that goes up when reviewing a suspicious email at a desk tends to be lower when checking something quickly on a phone.

What the lures actually look like

Quishing campaigns aimed at businesses have converged on a small set of highly effective pretexts. Multi-factor authentication enrolment is the most common: an email claiming that IT requires re-registration of the authenticator app, with a QR code to scan. This is devastatingly credible, because scanning a QR code is genuinely how MFA enrolment works.

Shared document notifications are the second family. A message styled as a Microsoft 365 or SharePoint alert says a colleague has shared a file, and the QR code supposedly opens it on mobile. Payroll and HR notices, delivery confirmations, and expiring password warnings fill out the rest.

Attacks also arrive on paper. Fake parking fines with QR codes for payment have been documented across several European countries, and stickers placed over legitimate QR codes on restaurant tables, payment terminals, and public transport posters are an established technique. For a business, the physical variant matters when employees use company cards or expense accounts.

The Italian context adds a specific risk surface. QR codes are now routine for electronic invoicing workflows, PagoPA payment notices, and public administration communications. An employee who scans QR codes several times a week as part of normal work has no instinctive reason to treat one more as suspicious.

How to protect against quishing in an SMB

The honest starting point is that no single product solves this. Quishing succeeds by routing around technical controls, so the defense has to combine technology where it still helps with human judgment where technology has stepped out of the way.

Strengthen what technology can still do

Ask your email provider or IT partner whether your gateway performs QR code decoding. Several vendors, including Kaspersky, have added image analysis that extracts and reputation checks embedded URLs, and enabling it removes a meaningful share of campaigns before delivery. It will not catch everything, particularly codes wrapped in attachments, but it raises the cost for the attacker.

Move to phishing resistant authentication where you can. Hardware security keys and passkeys built on FIDO2 are cryptographically bound to the legitimate domain, which means a stolen password entered on a fake login page is worthless. This is the strongest single control available, and for a small business the cost of keys for the ten or fifteen accounts that matter most is modest. Push notification MFA, by contrast, offers far less protection, since attackers using real time proxy toolkits simply relay the prompt.

Apply conditional access policies that restrict logins from unmanaged devices or unexpected locations. Review which accounts genuinely need access to financial systems and email forwarding rules, and shorten session lifetimes for privileged users. When credentials are eventually stolen, and some will be, these controls limit what the attacker can do with them.

Train the reflex, not just the rule

Since the decisive moment happens on a personal phone with no software watching, the employee is the control. That makes structured, continuous security awareness training the highest return investment against quishing, provided it is built around behavior rather than an annual slide deck.

The specific habits worth building are simple. Never scan a QR code that arrives by email: if IT needs you to enrol in MFA, go to the known internal portal directly. Always check the domain in the address bar after scanning, before typing anything. Treat any request for credentials that follows a scan as suspicious by default. Report the message rather than deleting it, so the security team can check whether colleagues received it too.

Platforms such as Kaspersky ASAP deliver this in short adaptive modules that adjust to how each person actually performs, which fits SMBs where nobody has an afternoon to spare for training. Simulation programmes from providers like Cyber Guru go further by sending controlled quishing tests, so employees encounter the attack in a safe setting and build the reflex before a real campaign arrives.

Include the physical dimension in the training. Employees should know to check whether a QR code on a poster or payment terminal is a sticker applied over the original, particularly when the code leads to a payment.

What this means for compliance and cost

For businesses subject to NIS2, which now covers a substantial number of medium sized Italian companies in manufacturing, food production, waste management, and digital services, awareness training is not optional. The directive requires cyber hygiene practices and training as part of the risk management measures management bodies are accountable for, with personal liability attached. A documented programme that addresses current attack techniques is part of demonstrating compliance.

GDPR obligations follow the same logic. A quishing attack that harvests Microsoft 365 credentials typically leads to mailbox access, and a compromised mailbox in an SMB usually contains personal data of clients, employees, and suppliers. That is a notifiable breach with a 72 hour clock, and the assessment of whether you had appropriate technical and organizational measures in place will look directly at your training records.

The financial exposure is more immediate than the regulatory one. Quishing attacks against businesses are frequently the first stage of business email compromise, where the attacker sits inside a mailbox, studies invoicing patterns, and then intercepts a payment by substituting bank details. Italian SMBs have lost six figure sums to exactly this sequence, and the money is rarely recoverable.

The uncomfortable summary is that a 146% increase in three months reflects attackers finding a gap and pouring resources into it. The gap is real, it sits between your email filter and your employees’ phones, and it will not be closed by buying another appliance. It closes when the people receiving these messages recognize the pattern, and that only happens if you deliberately teach them.

💬

Need support on this topic?

Let’s assess your company’s situation together. First consultation is free.

Contact us
📩

Stay updated every week

Cybersecurity, AI and technology for SMBs. No spam, only useful content.

Subscribe to newsletter

Content on this blog is written and reviewed by the editorial team of 10punto10 s.r.l., which holds editorial responsibility for the published content.