Cyber Experts Warn of New QR Code Phishing Scams
Cybersecurity firm ESET is alerting users to the growing threat of "Quishing," a phishing technique that exploits QR codes. These codes, now ubiquitous in daily life from restaurant menus to digital payments, are used by attackers because people tend to scan them without suspicion. Unlike traditional phishing, which uses links or files, Quishing hides malicious web addresses within QR codes, making them harder for both users and security systems to detect. The address is not visible as readable text, and standard email filters struggle to identify and inspect it. Sometimes, these codes are embedded within PDF or JPEG files.
Or Isaac, support manager at Comsecure, the exclusive distributor of ESET in Israel, explained that the danger escalates when an employee scans the code with a smartphone. This action moves the user from a secured corporate network to a mobile device, which is often less protected and may not be managed by the organization. This allows a successful email attack to quickly transfer to a more vulnerable environment, enabling the attacker to act more easily.
Quishing goes beyond simple password theft. ESET reports that attackers use this method to steal authentication codes, direct users to download unofficial applications, attempt account takeovers, and even redirect them to legitimate payment apps with pre-filled recipient details. Attackers can leverage regular services and apps as part of the scam, not relying solely on suspicious-looking fake websites. They also use URL shorteners to further obscure the destination and can incorporate links or contact information that lead to phishing sites later. This technique blends well with social engineering tactics, as messages impersonating service updates, signature requests, or account verification can create a sense of urgency, making the QR code appear as part of a legitimate process.
State-sponsored groups are also employing Quishing. In January 2026, the FBI warned that the North Korean hacking group Kimsuky used QR codes in targeted spear-phishing messages sent to research institutions, academic bodies, and government entities in the US and other countries. In some instances, attackers tried to trick recipients into believing that scanning the code would lead to a questionnaire, registration page, or secure drive, thereby prompting them to initiate the attack themselves.
Isaac advises organizations to incorporate QR code attacks into employee phishing training and drills. He recommends avoiding scanning codes from unexpected messages and verifying unusual requests with the sender through independently found contact information. Additionally, he suggests using security solutions for mobile devices, enabling phishing-resistant multi-factor authentication, and keeping operating systems and security tools updated.