Hackers Use QR Codes in Phishing Emails to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Hackers are putting QR codes in phishing emails to steal login credentials. Known as quishing, the method hides a dangerous web address inside a square and persuades recipients to scan it with a phone.

The tactic exploits a habit: people distrust suspicious links but may view a QR code as a routine shortcut. A convincing message can claim an urgent payroll update, benefits notice, or document requiring review.

The QR-code phishing reached record levels in its H1 2026 telemetry. Researchers recorded a steady rise from the start of the year, with the highest volume in April.

ESET said in a report shared with Cyber Security News (CSN) that the impact can extend beyond one stolen password. A scan may expose work email, cloud files, payment data, and other sensitive accounts, giving an attacker a foothold for further fraud or internal phishing.

Hackers Use QR Codes in Phishing Emails

A typical attack begins in a work inbox. The email imitates a trusted corporate service and is often personalized, while urgent wording pushes the recipient to act before checking the request through another channel.

Instead of a clickable link, the message places a QR code in its body or an attachment. The victim scans it, sees a decoded link, and is sent to a fraudulent sign-in page designed to collect credentials or sensitive information.

The visual format can conceal the destination from people and text-focused security checks. Imageless QR code attacks show that criminals can construct a scannable code from email markup, removing the image object some defenses expect to inspect.

Phishing email detected as QRCode - Phishing (Source - ESET)
Phishing email detected as QRCode – Phishing (Source – ESET)

Moving the interaction to a mobile device adds an advantage. A personal or unmanaged phone may lack the protections of a company computer, and users cannot inspect a QR destination as easily as they can hover over a normal email link.

ESET tracks these messages as QRCode/Phishing, using a scanning layer that finds QR codes, decodes their URLs, and checks destinations against anti-phishing, anti-malware, and anti-spam systems. Harmful links can trigger a block, flag, or deletion.

About 11% of phishing emails detected by ESET in H1 2026 used QR codes. The company saw roughly 100,000 detections monthly; the United States accounted for 19%, Spain 17%, and Mexico 6%.

Why Familiar QR Codes Work

QR codes appear on menus, payment terminals, hotel check-ins, and workplace workflows. That familiarity drives the lure, because a recipient may scan first and consider the destination only after the browser opens it.

Campaign themes also exploit attention and emotion. ESET observed emails posing as corporate HR communications, including messages about pay and benefits, subjects that can prompt people to respond quickly and overlook warning signs.

The problem is not limited to inboxes. Attackers have placed fraudulent codes on parking machines, bicycles, fake tickets, and toll notices, directing victims to payment pages that collect card details. Readers should treat these QR code security blindspots with the same caution as unsolicited links.

PromptSpy’s execution flow (Source - ESET)
PromptSpy’s execution flow (Source – ESET)

State-aligned actors have adopted the method too. The FBI warned in January 2026 about North Korea-aligned Kimsuky using malicious codes in spearphishing, as covered in Kimsuky QR code campaigns targeting organizations in the United States.

The practical response starts with slowing down. Do not scan an unexpected code because an email claims urgency. If a scan is necessary, inspect the full displayed address before opening it and avoid entering passwords or payment details on a site reached from an unsolicited code.

When a message appears to come from HR, IT, a bank, or a known organization, confirm it outside the suspicious email thread using trusted chat, phone, or a bookmarked official site. That step can stop an attack even when the branding appears credible.

Organizations should use layered email protection that can detect and decode QR codes, including those in attachments, and scan extracted destinations.

They should also extend controls to mobile devices and train staff that compromised email account campaigns can turn a stolen login into a broader internal threat.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

The post Hackers Use QR Codes in Phishing Emails to Steal Login Credentials appeared first on Cyber Security News.