In a concerning trend, cybercriminals are increasingly embedding QR codes in phishing emails to capture sensitive login information. This technique, known as ‘quishing’, tricks recipients into scanning a QR code that leads to a fraudulent website.
The Rise of Quishing
QR codes, commonly used for convenience, are now a tool for deception. Hackers exploit the trust users place in QR codes, contrasting it with their caution towards suspicious links. Often, these scams come disguised as urgent requests, such as payroll updates or critical document reviews, motivating recipients to act hastily.
According to a mid-year 2026 report by ESET, the use of QR codes in phishing attempts has surged, peaking in April. This method not only compromises a single password but also exposes various other sensitive accounts, potentially leading to extensive fraud.
How QR Code Phishing Works
Typically, these attacks originate in the victim’s work email. The emails mimic legitimate corporate communications and use persuasive language to push immediate action. Instead of including a clickable link, a QR code is provided, which when scanned, redirects to a counterfeit login page designed to harvest credentials.
Importantly, QR codes can bypass security checks that focus on text-based content. By embedding these codes directly in emails, attackers avoid detection by traditional security tools that expect image-based QR codes. ESET has identified these as QRCode/Phishing, actively scanning and decoding URLs to block malicious ones.
Widespread Impact and Prevention
The prevalence of QR codes in everyday life, from menus to transactions, contributes to their effectiveness in phishing campaigns. ESET’s data from the first half of 2026 shows 11% of phishing emails used QR codes, with significant detections in the United States, Spain, and Mexico.
Attackers also target physical spaces, placing fraudulent QR codes on public interfaces like parking meters and fake tickets. Such schemes lead users to fraudulent payment sites, harvesting financial details. Users should remain vigilant, treating QR codes with the same caution as unknown links.
Organizations are advised to implement comprehensive email protection strategies capable of detecting and analyzing QR codes. Additionally, extending security measures to mobile devices and educating employees about the risks of compromised email accounts are crucial steps in preventing broader threats.
To counter these threats, individuals should verify unexpected QR codes independently before scanning. Using secure communication channels to confirm the legitimacy of urgent emails purportedly from trusted sources can also prevent unauthorized access to sensitive data.
