QR code scams hit record high

Published August 28, 2026

Scammers are hiding phishing links inside QR code images instead of clickable links, so email filters miss them and the scam reaches your phone instead of your work laptop. Scanning the code can lead to a fake Microsoft 365, Google, or bank login page built to steal your password.

Report priority
Medium

How it works

Email security tools scan visible links but often do not decode and check the web address hidden inside a QR code image, so attackers put the malicious link there instead, commonly inside PDF attachments or fake invoice, voicemail, and login-verification emails.

What to do

Be suspicious of any email or PDF that asks you to scan a QR code to sign in, approve a payment, or view a secure file, especially ones about Microsoft 365, Google Workspace, Okta, or banking.

Do not scan QR codes from unsolicited email or PDF attachments, and if you must access the linked service, open it directly through your normal bookmark or app instead of scanning. Organizations should adopt email security tools that decode and check QR code links before delivery.

Technical details

ESET telemetry shows QR codes in roughly 11% of detected phishing emails in the first half of 2026, averaging about 100,000 quishing detections a month with a peak in April; the US accounted for 19% of detections, Spain 17%, Mexico 6%. Microsoft separately reported a 146% rise in QR phishing in Q1 2026, from 7.6 million detections in January to 18.7 million in March, out of 8.3 billion phishing threats processed that quarter. By March, about 70% of QR phishing arrived via PDF attachments, while QR images embedded directly in email HTML grew 336% in March. Many chains route victims through URL shorteners and CAPTCHA gates before a credential-harvesting page styled like Microsoft 365, Google Workspace, Okta, or a bank.