Monday, January 12, 2026

QR Phishing Attacks Rise Fivefold in Second Half of 2025, Kaspersky

Islamabad :   Kaspersky reports a spike in phishing emails containing malicious QR codes. Detections for these jumped from 46,969 in August to 249,723 in November – a more than fivefold growth – as cybercriminals increasingly exploit QR codes. Attackers use QR codes in emails more frequently because they provide a simple and cost-effective way to conceal malicious URLs, evading detection by many protective solutions.

These QR codes are often embedded directly in email bodies or, even more commonly, within PDF attachments – an evolution that both masks phishing links and encourages users to scan them on mobile phones, which may have weaker security than work PCs.

Malicious QR codes commonly appear in mass phishing campaigns as well as targeted ones. Links embedded within them may lead to phishing forms impersonating login pages for services like Microsoft accounts or internal corporate portals, designed to steal usernames, passwords, and other credentials. Fake HR notifications urging employees to review or sign documents, such as vacation schedules, or even view lists of terminated staff, ultimately directing to credential-stealing sites.

Fraudulent invoices or purchase confirmations in PDF attachments, often combined with vishing (voice phishing) tactics that prompt victims to call provided phone numbers to “cancel” or clarify the transaction, enabling further social engineering attacks.

These tactics exploit trust in routine business communications, leading to credential theft, account takeovers, data breaches, and financial fraud.

“Malicious QR codes have evolved into one of the most effective phishing tools this year, particularly when hidden in PDF attachments or disguised as legitimate business communications like HR updates. The explosive growth in November highlights how attackers are capitalizing on this low-cost evasion technique to target employees on mobile devices, where protection is often minimal. Without advanced image analysis at the email gateway and safe scanning practices, organizations are left vulnerable to credential compromise and downstream breaches,” comments Roman Dedenok, Anti-Spam Expert at Kaspersky.

To defend against this escalating threat, Kaspersky recommends deploying a mail server security solution such as Kaspersky Security for Mail Server that provides trusted and secure corporate email exchange, countering spam, email-borne infections, all forms of phishing, business email compromise (BEC), QR code attacks, and other threats.

Field Correspondent Sohail Majeed
+ posts

Sohail Majeed is a Special Correspondent at The Diplomatic Insight. He has twelve plus years of experience in journalism & reporting. He covers International Affairs, Diplomacy, UN, Sports, Climate Change, Economy, Technology, and Health.

Hot this week

Uraan Pakistan’ drives green buses, mangrove revival, and resilient healthcare, FM

Climate-Smart, Health-Responsive Infrastructure Now a National Priority Islamabad: Federal Minister...

URAAN Pakistan a strategic initiative by Planning Commission built on 5Es

PIDE Sparks Dialogue on Growth Beyond IMF Limits Islamabad –...

Urgent need for industrial policy to boost sector performance, Haroon

Belgian-British economist and Haroon Akhtar khan Highlight Urgent Industrial...

BCCI agrees to add Pakistan’s name on their jersey

India has confirmed its compliance with the International Cricket...

National Summit for Malaria Elimination in early 2026, Dr. Mukhtar

Pakistan reveals key findings from first G6PD pilot to...

Pakistan a culturally rich nation with a strong democratic spirit, Lt Gen Sjafrie

Rawalpindi : A high level defence delegation of Indonesia...

Chinese Chaoniu EV Motorcycle Company Explores Investment and Localization Opportunities in Pakistan

Islamabad  -  Following the Prime Minister–led Pak–China B2B Investment...

FM Maritime announces climate-resilient Port Qasim Industrial Complex

Islamabad,  — Federal Minister for Maritime Affairs Muhammad Junaid...

Gilani Strongly Condemns  Blast Targeting Armored Vehicle in district Tank

Islamabad  :   Chairman  Senate Syed Yousaf Raza Gilani, has...

AIOU Launches partner Admission Portal for International Students

Islamabad _  Allama Iqbal Open University(AIOU)  has formally launched...

Happiness came from fortune, not from bravery

The Life List By Fatima Asim Islamabad :-  When Eleanor...

Related Articles

Popular Categories