Home » QR Code Phishing Surges Fivefold — Kaspersky

QR Code Phishing Surges Fivefold — Kaspersky

By Ayomide Otitoju 

Kaspersky has reported a sharp rise in phishing emails containing malicious QR codes, warning that the trend is likely to continue into 2026 as cybercriminals increasingly exploit the technology to evade detection.

According to the cybersecurity firm, detections of phishing emails with malicious QR codes surged from 46,969 in August 2025 to 249,723 in November 2025, representing more than a fivefold increase within three months. Attackers are turning to QR codes because they offer a simple and low-cost way to conceal malicious URLs, often bypassing traditional email security controls.

Kaspersky noted that the QR codes are frequently embedded directly in email messages or, more commonly, hidden within PDF attachments. This approach not only masks phishing links but also encourages recipients to scan the codes using mobile devices, which may have weaker security protections than workplace computers.

The company said malicious QR codes are being used in both large-scale phishing campaigns and targeted attacks. Once scanned, the embedded links may redirect victims to fake login pages designed to steal credentials for Microsoft accounts or internal corporate systems. Other campaigns impersonate human resources communications, urging employees to review or sign documents such as vacation schedules or termination lists, ultimately leading to credential-harvesting websites.

In other cases, attackers distribute fraudulent invoices or purchase confirmations via PDF attachments, sometimes combined with vishing tactics that prompt victims to call a phone number to dispute a transaction. These calls can then be used to carry out further social engineering attacks.

Such methods exploit trust in routine business communications and can result in credential theft, account takeovers, data breaches and financial losses.

“Malicious QR codes have evolved into one of the most effective phishing tools, particularly when hidden in PDF attachments or disguised as legitimate business communications like HR updates,” said Roman Dedenok, Anti-Spam Expert at Kaspersky. He added that the sharp increase recorded in November 2025 shows how attackers are leveraging the technique to target employees on mobile devices, where security controls are often limited.

To mitigate the growing threat, Kaspersky advised organisations to strengthen employee cybersecurity awareness and deploy robust mail server security solutions capable of detecting spam, phishing, business email compromise, QR code attacks and other email-borne threats.

Comments (0)

Your email address will not be published. Required fields are marked *