Docento.app
Code editor on a laptop screen
All Posts

QR Code Phishing in PDFs (Quishing): How to Spot and Stop It

By The Docento.app TeamPublished 3 min read
Try Docento's free PDF editor — No sign-up, 100% private — sign, annotate, and stamp PDFs in your browser.Open the editor

Email security tools are good at catching suspicious links. So attackers stopped sending links. Instead, they send a PDF with a QR code in it: "Scan to review your updated benefits", "Your password expires today, scan to keep it", "Scan to sign the document". Security vendors have tracked a steady rise in these quishing attacks since 2023, and PDF attachments are one of the most common delivery methods.

Why QR codes in PDFs work so well for attackers

  • Filters cannot easily read them. A QR code is an image. Many email scanners check links in text, not inside pictures in an attachment.
  • The phone is a softer target. You scan with your personal phone, which often has fewer protections than a work laptop and may not show the full URL.
  • It looks official. Company logos, a DocuSign-style layout or an HR letterhead make the PDF feel legitimate.
  • It moves you off the managed device. Once on your phone, the attacker's fake login page is outside your company's security tools.

Common lures

  • Multi-factor authentication "re-registration".
  • Salary, bonus or benefits documents "awaiting signature".
  • Voicemail or fax notifications.
  • Parcel delivery problems.
  • Shared documents from a colleague or vendor.

Red flags

  1. An unexpected PDF whose main content is a QR code. Legitimate HR or IT messages rarely ask you to scan a code from an attachment.
  2. Urgency: "within 24 hours", "account will be suspended".
  3. A generic greeting or slightly wrong company details.
  4. The QR code leads to a login page. Any request for your password or MFA code after scanning is a strong signal.
  5. The URL preview looks odd when your camera shows it: misspelled domains, URL shorteners, or unrelated domains.

Safe habits

  • Do not scan QR codes from unexpected emails or attachments. Go to the service directly by typing its address or using the app.
  • Preview before opening. Most phone cameras show the URL before you tap it. Read it.
  • Ask through a separate channel. If HR "sent" a document, check with HR by phone or chat.
  • Report it using your organisation's phishing button.

For IT and security teams

  • Use email security that decodes QR codes in images and attachments.
  • Train staff on quishing specifically, with realistic examples.
  • Use phishing-resistant MFA such as passkeys or security keys, so a stolen password alone is not enough. See passkeys and secure document portals.
  • Extend mobile device protection to phones used for work.

If you already scanned and entered details

  1. Change the password immediately from a trusted device, by going to the real site directly.
  2. Sign out of all sessions and review MFA settings.
  3. Tell your IT or security team straight away. Speed matters.
  4. Watch for unusual activity on the account.

Takeaway

A QR code in a PDF is a link you cannot see. Treat it with more suspicion than a normal link, not less. For other PDF threats, see malicious PDFs and how to stay safe and invoice fraud and business email compromise.

Try Docento's free PDF editor

No sign-up, 100% private — sign, annotate, and stamp PDFs in your browser.

Open the editor

Related Posts