Hackers Use QR Codes in Phishing Emails to Steal Login Credentials
ID: 68e95f02-f08a-57ce-bf71-a25dac071a55
STIX ID: report--68e95f02-f08a-57ce-bf71-a25dac071a55
Feed Name: cybersecurityNews.com
ESET and other researchers reported a sharp rise in QR-code phishing (“quishing”) during H1 2026: attackers embed QR codes in emails (or attachments) that send victims to fraudulent sign-in or payment pages, enabling credential theft and follow-on fraud. The technique exploits mobile device weaknesses and user trust of QR codes, produced roughly 100k monthly detections (11% of phishing) with notable activity in the US, Spain, and Mexico; the FBI also warned that North Korea‑aligned Kimsuky has used quishing in spearphishing. The report recommends decoding and scanning QR destinations, extending email/mobile protections, and user verification of suspicious requests.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
