メインコンテンツにスキップ

Detect QR Code Attacks

The Attack Your Filters Can't Read

Quishing emails carry no link, no attachment, no payload — just a QR code that ferries your user to a credential phishing site from their personal phone, completely off your platform.

0%

Of attacks bypassing native spam filters use QR codes as the payload

Abnormal Threat Intelligence

0%

Of QR code attacks are credential phishing impersonating Microsoft, Google, or DocuSign

Abnormal Threat Intelligence

<0s

API deployment, no MX changes, no mail rerouting

Abnormal Platform

The Challenge

Why URL Filters Can't See QR Code Attacks

QR Codes Hide Malicious URLs Inside Images

Email URL filters scan text — QR codes are images, so the malicious destination never gets inspected before delivery.

Users Scan from Personal Phones, off Your Stack

Once the user lifts their phone to scan, the attack leaves your managed device entirely — no EDR, no proxy, no DNS filter.

Attackers Wrap QR Codes in MFA and IT Pretexts

Quishing emails impersonate Microsoft, Okta, and DocuSign — exactly the QR-prompted workflows users are trained to trust.

Sandbox Post-Click Detection Arrives Too Late

Sandboxes that detonate URLs after delivery never see the QR scan because the click happens off-device.

Image OCR Is Easy to Defeat with Format Tricks

Attackers split QR codes across multiple images, rotate them, or embed them in PDFs to evade basic OCR scanners.

Real Incident

AAquishingquishingemailemailimpersonatingimpersonatingMicrosoftMicrosoftMFAMFAenrollmentenrollmentlandedlandedinin280280inboxes,inboxes,harvestedharvested4747setssetsofofcredentials,credentials,andandtriggeredtriggeredthreethreeaccountaccounttakeoverstakeoverseveryeveryemailemailpassedpassedSPF,SPF,DKIM,DKIM,andandDMARC.DMARC.

Based on a real customer incident

The Solution

An Abnormal Approach to Stopping QR Code Attacks

  1. Scores sender behavior, recipient targeting, and credential-reset content against per-identity baselines, catching most quishing before any QR code is even parsed.
  2. Decodes QR codes hidden in images, PDFs, and attachments, then evaluates the destination URL with the same engine that inspects text-based links.
  3. Recognizes the MFA-enrollment and password-reset pretexts attackers rely on, flagging them against the sender's true identity graph.

Fortune 500企業の25%以上が、Abnormal AIの自動化されたセキュリティ判断を信頼して採用しています

CVS Health
PepsiCo
Marriott
Hasbro
Lowe's
Liberty Mutual
Hitachi Energy
Unilever
Valvoline
Nestlé
Chipotle
Bristol Myers Squibb
Xerox
Texas

FAQ

See the Quishing Your Filters Are Missing

Deploy in 60 seconds via API. No MX changes. Decode the QR-based attacks your gateway can't read.