DOI: 10.3390/jcp6040134 ISSN: 2624-800X

Quishing: A Sociotechnical Framework for Understanding QR-Code Phishing Risks and User-Centered Protection Strategies

Pedro-David Filio-Aguilar, Rubén Mil-Martínez, Lourdes López-García

The widespread use of Quick Response (QR) codes increases exposure to QR-code-based phishing, or quishing. This study examines the mechanisms, user behaviors, and contextual conditions that shape QR-mediated risk from a sociotechnical perspective. A structured literature review and narrative synthesis were conducted using four documented search strings. Following deduplication, screening, retrieval, and full-text assessment, 27 studies were included from 71 identified records. Two reviewers independently evaluated methodological quality using six criteria. The corpus comprised 16 technical-detection studies, five user-centered or behavioral studies, two attack demonstrations or simulations, and four reviews or preventive frameworks. The mean consensus quality score was 10.04 out of 12; 19 studies were classified as high quality and eight as moderate quality. The synthesis indicates that quishing exploits the interaction of contextual legitimacy, routine scanning, limited destination visibility, and insufficient verification before navigation or disclosure of sensitive information. These findings informed an attack lifecycle, a sociotechnical model, a user security decision flow, a risk–protection mapping, and multilevel recommendations. These literature-derived artifacts are conceptual and heuristic rather than empirically validated. Effective mitigation therefore requires QR-specific verification mechanisms combined with behavioral and technical safeguards for users, interfaces, organizations, and platforms, followed by expert, usability, and experimental validation.

More from our Archive