QRishing: what it is and how to simulate it

The QR jumps from email to the personal phone, where your controls do not reach. Simulate QR attacks and measure who scans and who hands over data.

How it works

How the campaign is built and what is measured

The piece carries a QR, not a hyperlink

The lure can travel in an email or in a context the admin defines. The measured gesture is the scan and, if the scenario asks, handing over data on the landing.

The mail filter does not see the URL

A QR image does not get the same verdict as a link. The sandbox does not “click” the phone camera. That is why the channel exists as a native simulation, not a marketing extra.

The phone is often unmanaged

The employee scans with a personal device or with a corporate handset that does not have the same controls as the laptop. Measurement includes that population, not only whoever lives in Outlook.

Metrics: who scans and who hands data over

The scan is logged and, in scenarios that ask for it, data submitted on the landing. We do not publish a QR benchmark. The number that matters is yours.

The code on the table, not the link in the mail

QRishing is phishing by QR code

The piece is not an underlined link in the body of the mail: it is an image the mail filter does not “open” as a URL. Whoever points the personal-phone camera — outside MDM, outside the gateway — resolves the destination. The click does not happen in Outlook. It happens on a device your endpoint controls do not see.

That is why a QR-code simulation is not decoration on the phishing

It measures another gesture: scanning, not clicking a hyperlink. It measures another perimeter: the pocket. It measures the channel the mail filter does not open as a URL, without repeating the simulated inbox or the four-step assistant.

In real life the QR does not live only in an email

It is on posters, invoices, parking, menus. A program that only simulates the inbox leaves the branch and whoever pays by phone in the dark. We do not invent an industry scan rate.

What it is for

What it is for when the risk is on the floor

It is for retail, parking, menus, taped invoices, “pay here” posters

It is for when the SOC already filters mail well and the attack moved to the camera. It is for training the gesture of not scanning a QR nobody asked for, not only the gesture of not clicking.

It is not smishing

SMS is another channel and, on this site, is sold as a professional service. That location is resolved in services, not here. Native QRishing is not counted twice as if it were SMS.

In the cycle

How it connects to phishing simulations

Phishing simulations include QRishing as a native vector. Campaign engine, post-fail assignment and analytics are the module’s. If you want to know what QRishing is or how a QR-code simulation works, you are on the right page. Whoever falls can get the contextual course, same as email. The reinforcement format is decided by adaptive training. We do not duplicate that orchestration here.

Questions

Questions about QRishing

Does the mail filter detect a QR?
Not the way it detects a link. The QR travels as an image. The gateway verdict does not replace the gesture on the phone.
Do you measure the scan or only the click in the mail?
We measure who scans and, if the scenario includes it, who hands over data. It is not the same metric as a hyperlink click.
Is MDM required on the phone?
Part of the value of the exercise is that the scan happens outside your management. We do not ask for an agent on the phone to simulate QR.
Is it the same as smishing?
No. SMS is another channel. On this site smishing is run as a professional service. QRishing is native to the module.
Is there a product screenshot here?
No. Book a demo to see the console.

Measure the gesture the mail filter never sees

In the demo we build a QR scenario and see who scans. No filler regional rate.