What are vishing and quishing?
Vishing and quishing are phishing's younger siblings: the same goal (tricking victims out of login credentials, money or access), but via phone and QR codes instead of email. Both are growing for the same reason: Mail filters and awareness training have made classic phishing harder, so attackers move to where the filters do not exist.
Vishing: fraud over the phone
In vishing (voice phishing), the fraudster calls up in person. The classic scenarios:
- "The bank": There is suspicious activity on the account: "just approve it in MitID (Denmark's national digital ID) to stop it". The approval turns out to be the fraudster's own transfer.
- "Microsoft support": The computer is infected: "install this remote access program and we'll fix it". Now the attacker has full access.
- "The IT department": An update is being rolled out: "just read out the MFA code you receive by text". The code is the login to the victim's own account.
- MFA bombing: The victim is flooded with approval notifications until they tap yes, and then "IT" calls to "help".
The number on the display can be spoofed, so the call appears to come from the bank or a colleague. And with deepfake voices, even a familiar voice can be fake. The rule is therefore simple: Information, codes and approvals are never given in an incoming call.
Quishing: fake QR codes
Quishing exploits the fact that a QR code is unreadable to humans: Nobody can tell from the square where it leads. The attacks typically arrive as emails with QR codes ("scan to read the secure message" or "update your MFA"), where the code leads to a fake login page. Because the link sits inside an image, it often slips past mail filters. In the physical world, stickers with fake codes are placed over genuine ones, for example on parking meters and posters. Extra insidious: If the code is scanned with a personal phone, the attack happens entirely outside the company's security systems.
How employees respond correctly
- Hang up, and call back yourself: End the conversation and call back on a number from the bank's/colleague's official page. Never on a number the caller provides.
- Never hand over codes: No legitimate party (not the bank, not Microsoft, not your own IT) asks you to read out MFA codes over the phone.
- Do not scan QR codes in unexpected emails: If you need to log in somewhere, type the address into the browser yourself.
- Never approve MFA requests you did not trigger yourself, and tell IT immediately if they come pouring in.
- Report once too often rather than once too little: A quick "I got a strange call" to IT can stop a campaign against the whole company.
The phishing family: an overview
The attacks share DNA but each uses its own channel: phishing (email, broad), spear phishing (email, targeted), whaling/CEO fraud (against or in the name of management), smishing (SMS), vishing (phone), quishing (QR codes) and spoofing (forged senders and numbers that carry all the others). Training that only covers emails therefore only covers part of the surface. The reflexes need to hold across channels.
How MI Support IT can help
MI Support IT trains employees in the entire phishing family through security awareness training with simulated attacks and concrete reflexes, so the right response is second nature when the phone rings. Contact us for a conversation about your preparedness.