Social Engineering Examples

Quishing (QR Code Phishing)

Quishing hides a malicious link inside a QR code instead of a clickable URL, which lets it slip past email link-scanners and puts the burden of spotting the scam on whoever's phone camera opens it. It shows up on physical stickers over legitimate codes as often as it does inside email, which is what makes it distinct from ordinary phishing.


7 Cases
QU
Confirmed

UK Council Car Park QR Code ("Quishing") Scams - Cheltenham, Swindon & Somerset

Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset, tricking drivers into paying "parking fees" on cloned sites that harvested full card details or signed them up for hidden subscriptions.

Incident 2024Read →
QU
Confirmed

Orlando Downtown ParkMobile QR Parking Meter Sticker Scam (2025)

Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters, redirecting drivers who scanned them to a phishing site that harvested personal and payment information.

Incident 2025Read →
QU
Confirmed

LevelBlue MTDR SOC "Quishing" Case Study - Fake Microsoft MFA-Setup QR Code Harvests Employee Credentials (2023)

LevelBlue's MDR SOC documented a real client quishing case in which a PDF impersonating a Microsoft MFA-setup notice, hiding a malicious QR code, drove multiple employees to a fake Microsoft login page that harvested several employees' credentials before the attack was fully remediated with no confirmed data loss.

Incident 2023Read →
QU
Confirmed

Hornetsecurity QRishing Attack on US-Based MSP (2023)

Hornetsecurity documented a QR-phishing (quishing) email sent to a single employee at a US-based MSP that spoofed an MFA-reactivation notice with a QR code leading, via a .ru-hosted fake "security scan" page behind Cloudflare, to a freshly registered Microsoft 365 credential-harvesting login page; Hornetsecurity's write-up documents this technical chain but does not confirm the employee scanned the code or that any downstream step actually occurred.

Incident 2023Read →
QU
Confirmed

FTC Consumer Alert: QR Code Scams (Quishing)

The FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters and phishing emails/texts using QR codes to steal credentials or install malware.

Incident 2023Read →
QU
Confirmed

FBI/USPIS/FTC "Brushing 2.0" Quishing Package Scam Advisories (2025)

The FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that, when scanned, send recipients to phishing sites or malware instead of the promised gift-sender reveal or return instructions.

Incident 2025Read →
QU
Confirmed

Abnormal Security "Missed Voicemail" QR Quishing Campaign (2021)

Between September 15 and October 13, 2021, attackers sent nearly 200 emails disguised as missed-voicemail notifications with embedded QR codes that routed victims to a Microsoft-credential phishing page hosted on a legitimate enterprise survey service, using compromised Outlook accounts to bypass secure email gateways entirely, one of the earliest vendor-documented "quishing" campaigns.

Incident 2021Read →