The rapid adoption of Quick Response (QR) codes across digital services, electronic payments, public infrastructure, and everyday interactions has significantly expanded the attack surface for QR-code-based phishing attacks, commonly referred to as quishing. This study examines quishing from a sociotechnical perspective, analyzing how technological mechanisms, contextual trust environments, and user behavior interact to facilitate successful attacks. A qualitative and analytical methodology was used, combining a structured review of cybersecurity literature with the conceptual analysis of documented quishing attack scenarios. The study identifies the principal stages involved in quishing attacks and examines the sociotechnical conditions that increase user susceptibility, particularly the presence of seemingly trustworthy environments, routine low-risk user actions, and the limited visibility of verification mechanisms prior to QR-code interaction. Based on these findings, the study develops a sociotechnical model of quishing attacks, a user security decision flow model, and an integrated conceptual framework linking attack dynamics, user decision processes, and protective strategies. Additionally, a Decalogue of Essential Protection Against Quishing is proposed, providing practical user-centered recommendations aimed at reducing vulnerability to malicious QR codes. The findings suggest that mitigating emerging QR-code-based phishing threats requires not only technological countermeasures but also behavioral awareness, verification practices, and user-centered cybersecurity strategies capable of addressing both digital and physical interaction contexts.