With the rapid development of technology, cybercriminals are constantly innovating to deceive users and gain access to their confidential information. Among these new phishing techniques, ‘quishing’ is gaining in popularity. But what exactly is it, and how can you protect yourself?
What is “quishing”?
The term ‘quishing’, a combination of ‘QR’ (Quick Response) and ‘phishing’, refers to the manipulation of fake QR codes to trick users into divulging private information. These QR codes are often placed in emails, advertisements or even on physical signs to redirect victims to a malicious website. The ultimate aim of this scam is to steal banking information, login details, personal data, etc.
Why is it so efficient?
Quishing is effective for a number of reasons. Firstly, users tend to trust QR codes, which have become commonplace in our daily lives, particularly since the pandemic when they were featured on restaurant menus, payments and much more. Unlike suspicious links in an email, victims cannot easily preview the URL of a QR code before scanning it, increasing the risk that they will be redirected to a malicious site without realizing it.
And as cellphones are generally less protected than computers against cyber attacks, most people are often less vigilant when using their mobile device. This makes them an ideal target for cybercriminals.
A few statistics on the rise of quishing
Quishing incidents have increased dramatically in recent years. A study by PhishLabs revealed a 471% increase in these frauds in 2022 compared with the previous year. What’s more, according to Cybersecurity Ventures, cyber attacks that include elements of quishing are likely to continue to grow as users become increasingly familiar with QR codes in their daily lives.
How do you protect yourself against quishing?
The best way to prevent this deception is to adopt vigilance and protection measures:
- Always check the authenticity of QR codes: before scanning a QR code, make sure it comes from a reliable source. If you receive one in an email or unsolicited message, be suspicious.
- Use a secure QR reader application: some applications can authenticate the URL before redirecting you with a preview of the link in question.
- Update your security software: cellphones also need to be protected with security software. Make sure your device is equipped with the latest updates.
- Educate employees: in a professional setting, train your teams to recognize the signs of a quishing attempt and to avoid unauthorized scanning.
Cyber attacks are evolving, but it’s possible to stay on guard. At MicroAge, we offer advanced security solutions and support to help you protect your data and avoid pitfalls like quishing. Contact us and find out how we can help you.

Google’s Chrome 68 Web Browser Will Flag All HTTP Sites “Not Secure”
In Google's eyes, websites using HTTP are not secure, so it is marking them as such, starting in the Chrome 68 web browser. Find out why Google is taking this stance.
When It Comes to Diagnostic Data, Windows 10 Is a Chatterbox
By default, Windows 10 sends a large amount of diagnostic data to Microsoft. If you are concerned about the types of data being sent, you might want to take advantage of the Diagnostic Data Viewer. Learn how to use this tool and what you can do if you do not like what you see.
Find Out What Data Microsoft Is Saving about You
If you use Windows 10 and have a Microsoft account, you can easily see the types of data that Microsoft has stored about you. Learn where you can find this data and how to delete it.
Why Using Gmail’s Confidential Mode Is Not a Good Idea for Businesses
As part of Gmail's redesign in 2018, Google introduced the Confidential Mode to protect sensitive information sent by email. Learn how it works and why you should avoid using it in your business.
What You Need to Know about Google Tracking Your Location
Google is tracking the whereabouts of billions of its customers, even when they tell the tech giant not to. Here is what you need to know about this practice, including how to minimize the amount of data being stored about you.