Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Glossary graphic explaining quishing — QR code phishing — on dark navy background

ESET’s H1 2026 Threat Report flagged a record it would rather not hold: roughly 11% of all phishing emails detected in the first half of 2026 contained a QR code instead of a traditional link. The technique has a name — quishing — and it’s worth understanding because it sidesteps the defences most businesses already have in place.

What Is Quishing?

Quishing is phishing delivered via QR code. Instead of embedding a malicious URL as a clickable link in an email, attackers drop the link inside a QR code image. The victim scans the code with their phone and lands on a credential-harvesting page — often a convincing replica of a Microsoft 365 or banking login screen.

The reason it works is simple: most email security gateways inspect text and URLs, not images. A QR code passes through filters that would have caught the same link in plain text. And because scanning shifts the action to a mobile device, the victim loses the browser-based protections — like endpoint detection and corporate DNS filtering — that would normally flag the destination.

Why It Matters for Australian Businesses

Australian venues, particularly in hospitality, leaned heavily into QR codes during COVID for menus, check-ins, and payments. That normalised the behaviour of scanning codes without thinking twice. Attackers know this. A printed QR code on a fake parking fine, a sticker slapped over a legitimate menu code at a café, or a PDF invoice with an embedded code all exploit that trained trust.

We’ve seen this pattern across client environments on the Northern Beaches and in the Central West — staff scanning QR codes from what look like supplier invoices, only to hand over their Microsoft 365 credentials on a spoofed login page. The attack doesn’t need to be sophisticated. It just needs to reach someone who’s in a hurry.

What to Do About It

Treat QR codes the same way you’d treat any unsolicited link. Before scanning, check whether the source is expected. After scanning, look at the URL in your phone’s browser bar before entering any credentials. If your business prints QR codes for customers — on menus, signs, or invoices — audit them periodically to make sure nobody has tampered with or covered them.

On the technical side, modern email security platforms can now inspect QR code images and extract the embedded URL for analysis. If your gateway doesn’t do this, it’s a gap worth closing. Pair that with staff cyber awareness training that specifically covers QR-based phishing, and you’ve addressed both the technical and human sides.

If you’re unsure whether your current email filtering catches QR-based threats, get in touch — we can check.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →