QR-code phishing, commonly called quishing, reached record levels in ESET’s telemetry during the first half of 2026. The method replaces a visible email link with a scannable square that sends the victim to a fraudulent login or payment page. Because the destination is encoded visually and often opens on a phone, the attack can bypass both human suspicion and security controls built around conventional URLs.
ESET recorded a steady increase early in the year, peaking in April. About 11% of the phishing emails it detected during the six-month period used QR codes, amounting to roughly 100,000 detections a month. The United States represented 19% of detections, Spain 17% and Mexico 6%.
From the inbox to a less protected device
A typical lure imitates a familiar workplace service or department and claims that the recipient must review a payroll, benefits or document notice. Personalized details and urgent language encourage action before the employee confirms the request. Instead of clicking a link, the recipient scans a code embedded in the message or an attachment.
The scan shifts the session from a managed workstation to a mobile browser. Personal phones may lack corporate web filtering, endpoint telemetry and password-manager safeguards. Small screens also make it harder to inspect a full address, while the familiar camera workflow encourages users to continue quickly. A fake sign-in page can then collect an email address, password and, depending on the design, additional sensitive information.
Visual encoding creates inspection gaps
Email gateways traditionally extract text links and compare domains with reputation services. A QR code hides the same destination inside an image, requiring the system to find the code, decode it and examine the result. Attackers can complicate detection further by building a scannable pattern from HTML elements rather than attaching a normal image.
ESET’s QRCode/Phishing detection uses a dedicated scanning layer to identify codes, recover their URLs and evaluate the destinations through phishing, malware and spam systems. Organizations should confirm that their own mail controls perform equivalent analysis in message bodies and attachments. Merely blocking image downloads is not enough when the pattern can be assembled with markup.
Familiarity makes the lure effective
People now encounter QR codes on menus, payment terminals, event tickets and workplace sign-in flows. Criminals exploit that routine behavior: a code may feel like a neutral shortcut even when an unfamiliar hyperlink would trigger caution. Messages about pay or benefits add emotional relevance, making recipients more likely to scan first and evaluate later.
The technique is not limited to commercial credential theft. North Korea-aligned Kimsuky operators have used malicious codes in targeted spearphishing, according to an FBI warning issued in January 2026. Physical-world scams also place fraudulent stickers on parking machines, bicycles or toll notices to capture card details. In each case, the square conceals a destination that deserves the same scrutiny as any unsolicited link.
Layer mobile and email defenses
- Decode and scan QR destinations in both email bodies and attached documents.
- Extend phishing protection and managed-browser policies to corporate mobile devices.
- Train users to preview the complete destination before opening it and never enter credentials from an unexpected code.
- Verify HR, IT and financial requests using a bookmarked portal or trusted contact method.
- Use phishing-resistant multi-factor authentication so a captured password is less useful.
If an employee scans a suspicious code, response teams should determine whether credentials were entered, revoke affected sessions and review mailbox and cloud activity. A stolen account can be used to send convincing internal lures, turning one successful scan into a broader incident.
QR codes are not inherently dangerous, but they should not receive a trust exemption. The best habit is simple: slow down, inspect the decoded address and reach the claimed service through a known route. For defenders, the rise of quishing is a reminder that protection must follow the user from the inbox onto the device where the interaction actually happens.
Leave a Reply
You must be logged in to post a comment.