logo

QR Phishing. Fact or Fiction?

ID: 1d32f114-1b43-5af8-8b11-e3e50ed6d026

STIX ID: report--1d32f114-1b43-5af8-8b11-e3e50ed6d026

Feed Name: Pen Test Partners Blog

Date Published: 2024-02-15

Date Updated: 2026-03-26

Author: Tony Gee

...
...

The report analyzes “Quishing” (QR code phishing), where attackers embed base64 QR codes in emails to evade URL scanning and entice users to scan on mobile devices with weaker defenses, then leverage AiTM proxies to capture M365 credentials and session tokens for broader access (e.g., VPN). It critiques widely cited volume statistics, notes that while vendors claim detection capabilities the technical controls remain immature, and recommends prioritizing user awareness and training while calibrating risk relative to traditional URL phishing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.