← SecureAZ Blog

Threats · 7 min read · Published 5 May 2026 · Reviewed 17 August 2026

QR Code Phishing (Quishing) in NZ: The 2026 Threat Every Business Should Train For

QR code phishing — quishing — is now one of the fastest-growing attack vectors targeting NZ businesses. Email filters miss it. Here is what your staff need to know.

QR code phishing — known as quishing — has moved from a niche tactic in 2023 to one of the most reported phishing variants in New Zealand by 2026. The reason is simple: QR codes bypass nearly every email security control your business has invested in. The link is encoded as an image, so URL scanners cannot inspect it. The user reads the QR with a personal mobile phone, so it leaves your endpoint protection entirely. By the time the credential is harvested, your security stack never saw it happen.

CERT NZ's threat reports have logged a sharp rise in QR-based phishing through 2025 and into 2026, with NZ Post parcel delivery scams, fake parking fine notices, and IRD impersonation among the most common lures.

How quishing actually works

The mechanics are straightforward, which is exactly why it works:

  1. Attacker sends an email — usually impersonating a known brand (NZ Post, Spark, IRD, a bank, or an internal IT request) — containing a QR code as an embedded image.
  2. The email body has minimal text — often just "Scan to verify your delivery" or "Scan to update your details." Email security gateways have nothing to scan because the malicious URL is inside the image.
  3. The user scans with their personal phone — moving the interaction off your corporate network and onto a device you do not control.
  4. A credential harvesting page loads — visually identical to a legitimate login page (Microsoft 365, RealMe, IRD, a bank).
  5. Credentials are submitted and exfiltrated — often within seconds. If the user has MFA, the attacker prompts for that too.

The defining feature of quishing is the device pivot. Even with best-in-class email security and well-configured endpoint protection on every laptop in your office, you cannot scan a QR code on an employee's personal mobile. That gap is the attack surface.

Why NZ businesses are being targeted

Three factors make NZ a high-value target:

  • High mobile penetration and trust in QR codes — NZ saw rapid normalisation of QR check-ins during COVID, and that habit persists. Staff are conditioned to scan QR codes from official-looking communications.
  • NZ Post and IRD impersonation works — almost every adult expects parcels and tax correspondence. The lures are universal.
  • Many NZ SMEs run lean security teams — without dedicated phishing simulation programmes, staff have never seen a quishing example in a controlled environment.

What staff training should cover

Awareness alone does not solve quishing — but staff who have seen a quishing simulation are dramatically more likely to pause before scanning. Effective phishing training for employees in 2026 must include QR-based phishing scenarios, not just email links.

The core training points:

  • Treat unsolicited QR codes as suspicious — particularly in emails, on flyers in shared spaces, or stuck over legitimate signage (a known tactic on parking meters and EV chargers).
  • Never enter credentials on a page reached via QR scan — open the official app or type the URL manually.
  • Verify the destination URL before tapping — modern phones preview the URL when you scan; staff need to be trained to read it carefully.
  • Report suspicious QR emails to IT — and do not forward them, as the image survives forwarding.

Compliance angle: NZISM and the Privacy Act

For NZ government agencies and Crown entity suppliers, NZISM Control 3.2.18.C.01 requires ongoing security awareness training that reflects current threats. Quishing is now a current threat — training programmes that have not been updated since 2023 do not meet the spirit of the control.

For private-sector NZ businesses, the Privacy Act 2020 requires reasonable security safeguards. A successful quishing attack that leads to a credential compromise and personal information breach is a notifiable privacy event under section 114. Demonstrating documented, current training is part of a defensible position.

| Threat vector | Email gateway catches it? | Endpoint protection catches it? | Staff training catches it? |

|---|---|---|---|

| Traditional URL phishing | Often | Sometimes | Yes |

| Attachment-based phishing | Usually | Usually | Yes |

| Quishing (QR code) | No | No (off-device) | Yes |

| Voice phishing (vishing) | No | No | Yes |

How SecureAZ trains for quishing

SecureAZ phishing simulation campaigns include QR code lures alongside traditional email phishing. The training content is NZ-localised — NZ Post parcel notifications, IRD tax season scams, myIR credential pages — so staff see realistic examples rather than generic US bank templates.

Combined with NZ-specific phishing simulations and continuous monitoring, you build the only control that actually works against quishing: a workforce that pauses before scanning.

Start a 45-day SecureAZ trial — NZ-localised content, NCSC NZ approved supplier status, and full compliance documentation for NZISM, NCSC, and the Privacy Act.

External references: