Evaluate whether employees scan QR codes from unverified sources in physical or digital environments.
Simulate QRishing attacks (phishing via QR) without putting the organization at risk.
Generate a QR code ready to print or distribute, without needing external tools.
Measure the campaign's impact from the Campaign Detail (Analytics and Events tab).
Download the generated QR directly from the platform.
Navigation: Awareness → Simulaciones → Nueva Simulación → QR
Step 1 — Select campaign type
Go to Awareness → Simulaciones.
Click Nueva Simulación (top right button) or access from Dashboard → Launch Schedule.
Select the QR type among the available options: Email, QR, Smishing, USB Drop.
Step 2 — Basic data
The creation form opens in two steps: Basics and Configuration.
In the first step, you must fill in the simulation name field
The name should be recognizable to the team in future reports.
Required field — the "Continue" button is enabled only when there is text.
Test toggle (top right corner of the card): allows marking the simulation as an internal test.
Click Continue to move to the Configuration step.
Step 3 — Configuration
In the Configuration step, configure the Simulation Results section.
Select the destination URL to which the user is redirected after scanning the QR and interacting with the fake page. It is chosen from a dropdown with preconfigured destinations (e.g., "Motomel sorteo").
Next, you must select the recommendations page shown to the user upon finishing the simulation. It is chosen from a dropdown (e.g., https://recommendations.whalemate.com/...).
Preview toggle: when activated, it shows a preview of the complete flow the employee will see when scanning the QR (including the destination page and the simulated form).
Click Review and save.
Step 4 — Review and save
A modal appears with the final information:
Simulation name.
The QR code automatically generated by the platform.
Two available actions:
Download QR — downloads the QR as a PNG image ready to use.
Save — saves the simulation and adds it to the campaign list.
Upon saving, the campaign appears in the Simulaciones list with a distinctive QR icon and the reached employees counter at 0 until there are interactions.
QR campaigns do not have a predefined audience since the QR can be scanned by any user.
The reached employees metric reflects the organization's total.
Only events from identified users who are part of the Whalemate platform will be recorded.
From the Simulations list — options menu (⋮)
Each QR campaign in the list has a contextual menu with the options:
Details — accesses the Campaign Detail.
Statistics — directly accesses the Analytics tab of the Campaign Detail.
QR Code — downloads the generated QR code again.
Edit — edits the campaign configuration.
Delete — deletes the campaign (destructive action, in red).
Campaign Detail
When accessing the Campaign Detail (Insights → Analítica de Simulaciones → Explorador de Campañas → Detalle de Campaña), three tabs are shown:
Details— start date and number of employees.
Analytics — campaign interaction metrics.
Events — individual event log.
The "Preview" field within the Setup shows the destination page as the user will see it.
After finishing the configuration and clicking "Review and save," the QR is automatically generated. From the modal, you can download it with the Download QR button. You can also download it from the ⋮ menu in the simulations list, QR Code option.
QR campaigns do not have a defined audience. Anyone who scans the code can interact with the simulation.
This is the URL to which the user is redirected after completing the interaction with the fake page. It is chosen from preconfigured options on the platform.
This is the page the user sees when finishing the simulation, generally with awareness or training content about the risk of QRishing.
Have feedback or want to request improvements? Let us know at roadmap.whalemate.com/roadmap