QRishing Simulation

Test your workforce againstQR code phishing attacks.

QR codes are everywhere. Attackers are using them too. Safely simulate QR code phishing and measure whether employees scan, verify and report.

Request a Consultation
The QR code looks harmless

The destination may not be.

Employees have learned to be cautious with suspicious links. A QR code changes the interaction: they scan an image on their mobile device, often without knowing where it will take them.

Attackers can use QR codes in

  • Emails and newsletters
  • PDF documents
  • Microsoft Word documents
  • Meeting invitations
  • Account verification messages
  • MFA and password-reset lures
  • Delivery and payment notifications
  • Internal-looking communications

PhishPrep turns this emerging threat into a measurable security behavior test.

Simulate realistic QRishing attacks

Everything you need to test QR code behavior.

  • Realistic QR Code Simulations

    Create phishing scenarios containing QR codes that mirror the lures employees may encounter in real-world attacks.

  • Credential Phishing Scenarios

    Test whether employees recognize QR codes that lead to fake Microsoft 365, SSO, banking, or document-sharing login pages.

  • Mobile-Based Attack Simulation

    Measure behavior when employees move from their corporate computer to a mobile device to scan a QR code.

  • Trusted Brand Impersonation

    Use familiar services, brands, and business scenarios to test whether employees verify before scanning.

  • Urgency & Social Engineering

    Simulate password expiration, MFA verification, document access, payments, deliveries, or urgent account actions.

  • Behavioral Analytics

    Track employee interaction with QRishing simulations and identify recurring risky behaviors.

  • Targeted Awareness Training

    Deliver relevant awareness intervention based on employee behavior rather than another generic course.

  • Campaign Automation

    Run recurring QRishing simulations to continuously measure and reinforce employee awareness.

Realistic QRishing scenarios

Lures employees actually see.

  • Lure 01
    “Scan the QR code to verify your account and avoid losing access.”

    Microsoft 365 Password Is Expiring

  • Lure 02
    “Scan the QR code to complete your security verification.”

    MFA Verification Required

  • Lure 03
    “Scan the QR code to confirm a recent business transaction.”

    Payment Confirmation Required

  • Lure 04
    “Scan to reschedule your delivery or confirm your address.”

    Package Delivery Update

  • Lure 05
    “Scan the QR code to register for an event.”

    Events / Meeting Registration

  • Lure 06
    “QR codes embedded in messages that appear to come from inside the organization.”

    Internal-Looking Communications

How QRishing simulation works

Awareness shouldn't end when a campaign ends.

QRishing isn't about teaching employees to fear every QR code. It's about building the habit to pause, verify and think before scanning.

PhishPrep · Simulate

01 / 05

Campaign: M365 password expiry

Running

Lure preview · email

Your password expires today

Recipients

1,340

Delivered in

Email · PDF

Waves

3

Randomized

Unique QR codes

1,340

Per-user tracking

FAQs

Questions about
QRishing simulation

Find quick answers, or talk to our team.

Request a Consultation

QRishing, also called quishing, is a form of phishing that uses malicious QR codes to direct users to phishing websites or other harmful content.

Don't assume your employees will recognize a malicious QR code.

Build QRishing resilience across your workforce. Simulate it. Measure it. Reinforce it. Retest it.

PhishPrep QRishing simulation alongside email, SMS, Teams and voice channels