Quish Splash QR Code Phishing Campaign Hits 1.6 Million Users
ID: cf6620a6-5c80-5e86-89c2-9bda5e423a85
STIX ID: report--cf6620a6-5c80-5e86-89c2-9bda5e423a85
Feed Name: HackRead
Threat Score
Researchers uncovered “Quish Splash,” a sophisticated industrialized phishing campaign that delivered over 1.6 million emails between 26 February and 18 March 2026. Attackers hid malicious links inside BMP images as unique QR codes—one per recipient—to evade hash-based detection, configured sending domains to pass SPF/DKIM/DMARC, and used auto-reply confirmations; scanning the QR codes on mobile devices enabled data-theft paths outside corporate controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
