{"id":17905,"date":"2026-08-19T17:37:29","date_gmt":"2026-08-19T17:37:29","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=17905"},"modified":"2026-08-19T17:37:29","modified_gmt":"2026-08-19T17:37:29","slug":"how-qr-code-phishing-can-slip-previous-company-safety-measures","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=17905","title":{"rendered":"How QR-code phishing can slip previous company safety measures"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"sub-title\">Quishing has turn into a preferred various to conventional phishing. Right here\u2019s how companies can shut the hole.<\/p>\n<div class=\"article-authors d-flex flex-wrap\">\n<div class=\"article-author d-flex\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/our-experts\/phil-muncaster\/\" title=\"Phil Muncaster\"><picture><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x45\/wls\/2021\/04\/Phil_Muncaster.jpg\" media=\"(max-width: 768px)\"\/><img decoding=\"async\" class=\"author-image me-3\" src=\"https:\/\/web-assets.esetstatic.com\/tn\/-x45\/wls\/2021\/04\/Phil_Muncaster.jpg\" alt=\"Phil Muncaster\"\/><\/picture><\/a><\/div>\n<\/div>\n<p class=\"article-info mb-5\">\n        <span>17 Aug 2026<\/span><br \/>\n        <span class=\"d-none d-lg-inline\">\u00a0\u2022\u00a0<\/span><br \/>\n        <span class=\"d-inline d-lg-none\">, <\/span><br \/>\n        <span>5 min. learn<\/span>\n    <\/p>\n<div class=\"hero-image-container\">\n        <picture><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x266\/wls\/2026\/08-26\/qr-codes-phishing.jpg\" media=\"(max-width: 768px)\"\/><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x425\/wls\/2026\/08-26\/qr-codes-phishing.jpg\" media=\"(max-width: 1120px)\"\/><img decoding=\"async\" class=\"hero-image\" src=\"https:\/\/web-assets.esetstatic.com\/tn\/-x700\/wls\/2026\/08-26\/qr-codes-phishing.jpg\" alt=\"How QR-code phishing can slip past corporate security measures\"\/><\/picture>    <\/div>\n<\/div>\n<div>\n<p>Familiarity would possibly breed contempt. However on the earth of cybersecurity, it additionally breeds complacency, which is usually a lot extra harmful. So it&#8217;s with QR codes, which have turn into a typical sight on <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/2022\/02\/04\/think-before-scan-how-fraudsters-exploit-qr-codes\/\">menus, lampposts<\/a> and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/scams\/quishing-attacks-targeting-electric-car-owners-slam-on-brakes\/\">parking meters<\/a> \u2013 and, more and more, in emails over current years. The problem is that they\u2019re additionally a good way to disguise malicious hyperlinks, bypass some conventional company safety filters, and to maneuver the interplay from a company laptop to a private cellphone with fewer safety controls.<\/p>\n<p>Attackers will proceed to experiment and innovate with new methods to keep away from detection. And new \u201cquishing\u201d methods to snare unwitting staff. Right here\u2019s what you want to perceive to maintain your group protected.<\/p>\n<h2>Why is quishing so harmful?<\/h2>\n<p>Brief for \u2018Fast Response\u2019, a QR code is a two-dimensional barcode that may encode URLs, fee particulars, contact info and different information, serving to customers get rapidly from A to B \u2013 the vacation spot on this case often being a web site or app. They enchantment to menace actors for a number of causes. Their widespread use, accelerated by the demand for contactless interactions throughout the pandemic, has made scanning them an atypical a part of every day life. Meaning we\u2019re extra prone to get our telephones out to scan them at the moment than just a few years again.<\/p>\n<p>In addition they slot neatly into phishing workflows \u2013 simply change that malicious hyperlink or attachment with a QR code. And they are often generated in seconds. In truth, many phishing kits can have a devoted QR-code generator. Most significantly, they take the sufferer from a comparatively well-protected company setting to a doubtlessly unmanaged cell system, thus bypassing business-grade safety.<\/p>\n<p>One vital benefit for the attacker is concealment. The vacation spot is encoded in a visible sample, not displayed as readable textual content, which hides the malicious URLs behind them in order that some conventional e mail filters can\u2019t extract and examine them. Typically they\u2019re additional obfuscated by being embedded in PDF or JPEG attachments. Meaning they\u2019re extra prone to find yourself in your staff\u2019 inboxes. And once they do, your workers might battle to discern an actual message from a malicious one. There\u2019s usually not a lot textual content to investigate for typos or grammatical errors. And since the hyperlink is successfully encoded in a visible sample, it\u2019s invisible to the human eye.<\/p>\n<p>If used together with a trusted model \u2013 say, a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/scams\/personal-data-fraudsters-docusign-scam-emails\/\">DocuSign e mail<\/a> or an <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/2022\/10\/24\/5-reasons-keep-software-devices-up-to-date\/\">replace from Microsoft<\/a> \u2013 the quishing assault leverages comparable social engineering ways as traditional phishing messages. Trusted branding reassures the sufferer that they will click on by. And a way of urgency is usually created by the pretext. Malicious QR codes are incessantly embedded in alerts urging customers to safe their account, or authenticate to verify their particulars.<\/p>\n<p>In truth, in keeping with the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/web-assets.esetstatic.com\/wls\/en\/papers\/threat-reports\/eset-threat-report-h12026.pdf#page=14\">ESET Menace Report H1 2026<\/a>, malicious QR codes had been embedded in no fewer than 11 % of all phishing e mail within the first half of 2026. \u201cESET tracks quishing emails below the detection title QRCode\/Phishing. This detection works by a devoted layer of the ESET e mail scanner, designed to determine QR codes within the overwhelming majority of file varieties, and to decode the URLs in them. The extracted URLs are scanned utilizing ESET anti-phishing, anti-malware, and anti-spam engines; any dangerous URLs are blocked, and the related emails flagged or deleted,\u201d says the report.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"QRCode\/Phishing detection trend from September 2025 to May 2026, seven-day moving average (source: ESET Threat Report H1 2026)\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/08-26\/phishing-qr-codes-telemetry.png\" alt=\"phishing-qr-codes-telemetry\" width=\"\" height=\"\"\/><figcaption><em>QRCode\/Phishing detection development from September 2025 to Might 2026, seven-day shifting common (supply: <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/web-assets.esetstatic.com\/wls\/en\/papers\/threat-reports\/eset-threat-report-h12026.pdf#page=15\" target=\"_blank\" rel=\"noopener\">ESET Menace Report H1 2026<\/a>)<\/em><\/figcaption><\/figure>\n<h2>Menace actors proceed to innovate<\/h2>\n<p>As with every menace panorama development, malicious actors proceed to hone their efforts for max impression. Quishing assaults are getting used not solely to put in malware and steal credentials but additionally <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/cybercrime\/eviltokens-phishing-doesnt-steal-password\/\">harvest MFA tokens<\/a>. Safety researchers have additionally seen them in assaults designed to:<\/p>\n<ul>\n<li>Bypass app retailer safety by direct app downloads the place malware is disguised as reputable apps<\/li>\n<li>Take the consumer to not a malicious\/phishing web site however hyperlink on to a reputable social media, fee or different app. This might be utilized in numerous situations similar to:<\/li>\n<li>Account takeover, the place the sufferer is directed to authenticate the attacker of their account<\/li>\n<li>Monetary fraud, the place the sufferer is directed to a fee app with pre-filled payee info<\/li>\n<li>Contact\/calendar poisoning, the place malicious assembly hyperlinks or new contact info are embedded in utility apps and redirect customers to phishing websites when clicked on<\/li>\n<li>Malicious Wi-Fi, which the sufferer is mechanically linked to a menace actor\u2019s rogue entry level<\/li>\n<li>Obfuscate safety instruments by utilizing QR code shorteners, which convert lengthy, malicious internet addresses to small hyperlinks and embed them in QR codes<\/li>\n<\/ul>\n<figure class=\"image\"><img decoding=\"async\" title=\"Example of a phishing email detected by ESET products as QRCode\/Phishing (source: ESET Threat Report H1 2026)\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/08-26\/phishing-qr-codes-email-phishing.png\" alt=\"phishing-qr-codes-email-phishing\" width=\"\" height=\"\"\/><figcaption><em>Instance of a phishing e mail detected by ESET merchandise as QRCode\/Phishing (supply: <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/web-assets.esetstatic.com\/wls\/en\/papers\/threat-reports\/eset-threat-report-h12026.pdf#page=16\" target=\"_blank\" rel=\"noopener\">ESET Menace Report H1 2026<\/a>)<\/em><\/figcaption><\/figure>\n<p>Even state-sponsored APT teams are utilizing quishing as a part of their tradecraft. <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.ic3.gov\/CSA\/2026\/260108.pdf\">An FBI discover<\/a> from January 2026 warned that the North Korean Kimsuky outfit focused suppose tanks, educational establishments, and US\/overseas authorities entities with embedded QR codes in spearphishing emails. The lures diverse. The emails in query variously claimed that scanning the code would lead customers to questionnaires, registration touchdown pages, and safe drives.<\/p>\n<h2>Protecting your corporation protected from QR phishing<\/h2>\n<p>Luckily, a well-judged mix of individuals, course of and know-how changes will help to drastically scale back the quishing threat to your group.<\/p>\n<p>Begin with individuals. Construct quishing into consumer consciousness coaching programs and simulation workout routines. Encourage staff to keep away from scanning QR codes in unsolicited emails and report something suspicious. In the event that they imagine it\u2019s from a trusted supply, they need to verify again with the sender, utilizing contact particulars sourced individually from the e-mail.<\/p>\n<p>Subsequent, take into account technical controls, together with e mail safety from a good vendor to reduce the danger of quishing emails ending up in customers\u2019 inboxes. Add a cell safety resolution to worker gadgets to dam entry to malicious websites and different threats. And require phishing-resistant multi-factor authentication (MFA) on all delicate accounts, in order that even when customers are tricked, adversaries received\u2019t have the ability to achieve a foothold into company methods. Cellular system administration (MDM) instruments will help you to make sure all gadgets are protected consistent with company coverage.<\/p>\n<p>Cut back the assault floor, implement least privilege and just-in-time entry. Preserve all cell working methods and company software program updated \u2013 together with your safety instruments. And conduct steady monitoring for suspicious exercise. Follow incident response plans within the occasion of a worst-case situation.<\/p>\n<h2>A novelty no extra<\/h2>\n<p>QR codes have developed from one thing of a novelty to an everyday sight within the enterprise. And so has quishing. Familiarity needn&#8217;t breed complacency. Simply as workers have grown used to being suspicious of conventional e mail and SMS-based phishing, they are often educated to identify the warnings indicators of a attainable quishing try. Underneath the best circumstances, familiarity can construct safety.<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Quishing has turn into a preferred various to conventional phishing. Right here\u2019s how companies can shut the hole. 17 Aug 2026 \u00a0\u2022\u00a0 , 5 min. learn Familiarity would possibly breed contempt. However on the earth of cybersecurity, it additionally breeds complacency, which is usually a lot extra harmful. So it&#8217;s with QR codes, which have [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":17907,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[1668,3845,261,10229,211,10230],"class_list":["post-17905","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-corporate","tag-measures","tag-phishing","tag-qrcode","tag-security","tag-slip"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17905","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17905"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17905\/revisions"}],"predecessor-version":[{"id":17906,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17905\/revisions\/17906"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/17907"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17905"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17905"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17905"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-08-19 19:50:48 UTC -->