GBHackers

QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes


QR code phishing, widely known as “quishing,” has reached record levels as threat actors increasingly conceal malicious URLs within scannable images rather than placing clickable links directly in emails.

The shift is helping attackers bypass traditional secure email gateways and move victims from managed corporate devices to less-protected smartphones.

The company recorded an average of 100,000 QR phishing detections per month, peaking in April. The United States accounted for 19% of detections, followed by Spain at 17% and Mexico at 6%.

The technique exploits a fundamental inspection gap. Conventional email defenses are designed to extract, rewrite, reputation-check, and detonate visible hyperlinks.

A QR code, however, is an image containing encoded data. If a gateway does not decode that image and analyze the destination URL, the malicious redirect chain may reach the recipient intact.

Attackers commonly embed QR codes in PDF attachments, invoice-themed emails, document-sharing alerts, authentication notices, and fake voicemail messages.

The lure directs users to scan the image with a mobile phone, often claiming that the recipient must view a secure file, reauthenticate a Microsoft 365 account, approve a payment, or access an encrypted message.

The number of AI skills is growing sharply. Between March and May 2026,the number of unique skills scanned by ESET systems increased from an initial 60,000 to almost 900,000.

Once scanned, the QR code can send the victim through URL shorteners, traffic-distribution systems, CAPTCHA gates, or browser-check pages before landing on a credential-harvesting portal.


QRCode/Phishing detection trend (Source : ESET).
QRCode/Phishing detection trend (Source : ESET).

ESET Researchers said that, telemetry for the first half of 2026 found that QR codes appeared in approximately 11% of detected phishing emails, with the campaign volume reaching record levels.

The final page is frequently optimized for mobile browsers and designed to mimic Microsoft 365, Google Workspace, Okta, banking, or enterprise single sign-on interfaces.

QR Code Attacks

Microsoft observed a 146% rise in QR-code phishing during the first quarter of 2026, with detections growing from 7.6 million in January to 18.7 million in March.

Top 10 malware detections in H1 2026 (Source : ESET).

The company processed 8.3 billion phishing threats over the quarter, illustrating the scale at which phishing operators are testing newer delivery formats.

PDF files have become a particularly effective quishing vehicle. By March, reports based on Microsoft data indicated that 70% of QR phishing activity was delivered through PDF attachments.

Direct QR images embedded in email HTML grew even faster, surging 336% during March, although they represented a smaller share of overall QR phishing volume.

QR phishing is not simply a visual variation of email phishing. It changes where security controls and user decisions occur.

The initial email may arrive on a corporate laptop protected by endpoint detection, browser isolation, DNS filtering, and managed identity policies.

Scanning the code transfers the interaction to a personal phone, where those enterprise safeguards may be absent.

The approach also takes advantage of user behavior. QR codes have become routine in restaurants, payments, package tracking, login flows, event registration, and document access.

That familiarity lowers suspicion, while the small screen of a mobile device makes it harder for users to inspect the complete URL, notice lookalike domains, or detect subtle branding flaws.

In many campaigns, the QR code is only the first stage. Threat actors may use a CAPTCHA page to filter security scanners, fingerprint the visitor’s device, and deliver the credential page only to likely human targets.

This delays detection and reduces the likelihood that automated analysis systems will observe the final phishing content.


Top 10 Ransomware detections in H1 2026 (Source : ESET).
Top 10 Ransomware detections in H1 2026 (Source : ESET).

Organizations should treat QR codes as URLs, not harmless images. Email security platforms need image optical analysis and QR decoding capabilities that extract the embedded destination before delivery.

The decoded URL should then be subjected to reputation checks, sandboxing, redirect-chain analysis, domain-age checks, and phishing-page detection.

Security teams should also enforce phishing-resistant multifactor authentication, preferably FIDO2 security keys or passkeys.

A stolen password has far less value when account access requires a hardware-bound or device-bound authentication factor.

User training should focus on the behavioral trigger: employees should avoid scanning QR codes sent unexpectedly by email, especially when the message demands urgent authentication, payment approval, or document access.

Staff should open the trusted application or type the organization’s known login address manually instead of following a QR-initiated path.

The growing volume shows that quishing is now a mainstream phishing delivery method rather than an edge-case tactic.

As attackers hide links inside images and shift victims to mobile devices, email security programs will need to extend URL inspection, identity protection, and user awareness beyond the inbox.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.



Source link