← All resources
Scams

QR-code phishing: what MSPs should tell clients about quishing

A QR code moves the attack from a managed device to an unmanaged one. That single property is what makes it effective, and what makes it awkward to defend.

Scams · 6 min read · By SafeToOpen · July 2026

QR-code phishing — quishing, if you must — is not a new attack. It is an old attack with a delivery change, and that change happens to defeat several controls at once.

Why a QR code is effective

Consider what a QR code does to an email-borne attack.

There is no link to scan. Email security that inspects and rewrites URLs has nothing to work with. The destination is encoded in an image. To a filter that reads text and links, the message contains neither.

The attack leaves the managed device. This is the important one. The user is at their desk, on a laptop your policies control, running the browser protection you deployed. They raise their phone — personal, unmanaged, outside your policy — and the attack completes there. Every control you configured is still running, on the wrong device.

The pretext is plausible. QR codes have become normal for MFA enrolment, parking, restaurant menus and document access. A code claiming to be a required security update does not look out of place the way an unexpected attachment does.

The defining characteristic of quishing is not the code. It is the device switch. Any defence that only exists on the corporate endpoint has been designed out of the attack by the delivery mechanism.

What clients usually get wrong

The common response is an awareness campaign: tell staff not to scan QR codes in emails. This is not useless, but it degrades quickly, because it asks people to maintain suspicion of something they use legitimately several times a week.

The second common response is to block images in email. This works in a narrow sense and creates a great deal of friction for a small reduction in risk. Few clients tolerate it for long.

What actually helps

Three things, in order of practical value.

Protection that survives the device switch. If phishing protection exists on the phone’s browser as well as the laptop’s, the device switch stops being an escape route. This is the only defence that addresses the actual mechanism rather than working around it. For clients who allow personal devices to access work accounts — which is most clients — it is worth raising explicitly.

Analysis of the destination, not the message. Since the email contains no link to inspect, the meaningful assessment has to happen when the page loads. A credential-harvesting page reached by QR code is the same page it would have been reached by a link; the mechanism that judges it on sight works either way.

A reporting path that people use. Staff who scan something and then feel uneasy need somewhere to send it that takes ten seconds. Most reporting processes are slow enough that people skip them, and the organisation loses its earliest signal.

How to raise it with a client

QR-code phishing is a useful conversation for a managed service provider because it exposes an assumption most clients hold without examining it: that protecting the corporate endpoint protects the user. It does, right up until the user picks up a different device.

You do not need to alarm anyone. The point is narrow and concrete: here is a common attack, here is why the controls we have deployed do not see it, and here is what would. That is a straightforward conversation to have, and it tends to lead naturally into the broader question of where else protection is device-bound.

Protecting a client base?

A short introduction covering multi-tenant management, deployment and how the partner model works.

Book a partner introduction →