Published on 27 July 2026
QR Code Phishing (Quishing): How to Test Your Team
What quishing is – and why it's rising right now
"Quishing" stands for QR code phishing: fraudulent messages or stickers contain a QR code instead of a clickable link, which leads to a fake page once scanned. Since QR codes have become ubiquitous in everyday life – restaurant menus, parking meters, package notifications, invoices – many employees question a QR code far less critically than a classic link in an email.
Why quishing bypasses classic protective measures
Spam filters and security software primarily analyze text and embedded links – an image containing a QR code often contains no analyzable URL for these systems. On top of that, a QR code is almost always scanned with a personal smartphone, not a company laptop – exactly where many corporate protections like web filters or endpoint security don't apply at all.
The Swiss specifics: fake QR-bills
In Switzerland, an industry-specific scam adds to this: fraudsters send fake invoices with a manipulated QR-bill payment code where the IBAN or amount has been altered – visually almost indistinguishable from a genuine QR-bill. Anyone who scans the QR code directly in e-banking or a banking app without manually double-checking the IBAN and amount afterward risks, in the worst case, transferring money directly to the criminals.
Other typical scenarios
Besides fake invoices, other variants circulate: tampered parking meter stickers that lead to a fake payment page; supposed package delivery notices with a QR code instead of a tracking link; and QR codes on posters or flyers in public spaces where the genuine code has been stuck over. All three exploit the same effect: the QR code itself appears trustworthy because it's embedded in a physical context.
How employees can safely check a QR code
Most smartphone cameras show a preview of the destination URL before opening it – this moment is decisive and yet frequently overlooked. It's important to apply the exact same warning signs there as with a link in an email: does the domain match the claimed sender? Does the ending look unusual? For a payment request, always manually cross-check the IBAN and amount against the original invoice, regardless of what the QR code pre-fills.
How a simulation tests quishing
Because quishing runs through a completely different channel than classic email phishing, a test needs to target exactly that channel: with realistic QR code scenarios that prompt employees to scan, and immediate feedback on which warning sign was missed. Anyone who has already questioned a QR code in a safe simulation does so reflexively again the next time it's real.
Try it yourself
With our free QR Code Checker, you can check a single QR code directly before scanning it – and get a feel for what to look out for yourself.
Test your team today
Try the free demo access yourself or register your company directly.