logo

Hackers Use QR Codes in Phishing Emails to Steal Login Credentials

ID: 68e95f02-f08a-57ce-bf71-a25dac071a55

STIX ID: report--68e95f02-f08a-57ce-bf71-a25dac071a55

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-09-03

Date Updated: 2026-09-16

Author: Tushar Subhra Dutta

...
...

ESET and other researchers reported a sharp rise in QR-code phishing (“quishing”) during H1 2026: attackers embed QR codes in emails (or attachments) that send victims to fraudulent sign-in or payment pages, enabling credential theft and follow-on fraud. The technique exploits mobile device weaknesses and user trust of QR codes, produced roughly 100k monthly detections (11% of phishing) with notable activity in the US, Spain, and Mexico; the FBI also warned that North Korea‑aligned Kimsuky has used quishing in spearphishing. The report recommends decoding and scanning QR destinations, extending email/mobile protections, and user verification of suspicious requests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.