QRishing: what it is and how to simulate it
The QR jumps from email to the personal phone, where your controls do not reach. Simulate QR attacks and measure who scans and who hands over data.
How the campaign is built and what is measured
The lure can travel in an email or in a context the admin defines. The measured gesture is the scan and, if the scenario asks, handing over data on the landing.
A QR image does not get the same verdict as a link. The sandbox does not “click” the phone camera. That is why the channel exists as a native simulation, not a marketing extra.
The employee scans with a personal device or with a corporate handset that does not have the same controls as the laptop. Measurement includes that population, not only whoever lives in Outlook.
The scan is logged and, in scenarios that ask for it, data submitted on the landing. We do not publish a QR benchmark. The number that matters is yours.
The code on the table, not the link in the mail
QRishing is phishing by QR code
The piece is not an underlined link in the body of the mail: it is an image the mail filter does not “open” as a URL. Whoever points the personal-phone camera — outside MDM, outside the gateway — resolves the destination. The click does not happen in Outlook. It happens on a device your endpoint controls do not see.
That is why a QR-code simulation is not decoration on the phishing
It measures another gesture: scanning, not clicking a hyperlink. It measures another perimeter: the pocket. It measures the channel the mail filter does not open as a URL, without repeating the simulated inbox or the four-step assistant.
In real life the QR does not live only in an email
It is on posters, invoices, parking, menus. A program that only simulates the inbox leaves the branch and whoever pays by phone in the dark. We do not invent an industry scan rate.
What it is for when the risk is on the floor
It is for retail, parking, menus, taped invoices, “pay here” posters
It is for when the SOC already filters mail well and the attack moved to the camera. It is for training the gesture of not scanning a QR nobody asked for, not only the gesture of not clicking.
It is not smishing
SMS is another channel and, on this site, is sold as a professional service. That location is resolved in services, not here. Native QRishing is not counted twice as if it were SMS.
How it connects to phishing simulations
Phishing simulations include QRishing as a native vector. Campaign engine, post-fail assignment and analytics are the module’s. If you want to know what QRishing is or how a QR-code simulation works, you are on the right page. Whoever falls can get the contextual course, same as email. The reinforcement format is decided by adaptive training. We do not duplicate that orchestration here.
How this module is used
Questions about QRishing
Does the mail filter detect a QR?
Do you measure the scan or only the click in the mail?
Is MDM required on the phone?
Is it the same as smishing?
Is there a product screenshot here?
Measure the gesture the mail filter never sees
In the demo we build a QR scenario and see who scans. No filler regional rate.