Attack type comparisons

Quishing vs phishing: what is the difference?

Quishing is phishing in which the malicious link is carried inside a QR code rather than as clickable text. The purpose is to move the click from a managed corporate device onto a personal phone, where email filtering, URL rewriting and device controls usually do not apply.

A conventional phishing link can be hovered, inspected, rewritten by a gateway or blocked outright. A QR code is an image, so it passes text-based scanning, and the destination is invisible until it has already been resolved.

The second difference is physical. A QR code can be printed on a sticker and placed on real-world infrastructure, which means it reaches people who received no message at all.

Documented cases

The control that breaks it

  • Treat a printed code on public infrastructure as untrusted and pay through the operator app or website instead.
  • On a phone, read the URL preview before opening it.
  • For enterprise MFA enrolment, only ever complete it from a flow an administrator initiated through a known internal system, never from a code arriving in a message.