Here’s A New One For Me…. A Phishing Email That Uses QR Codes
I get phishing emails all the time. Such as my email address is about to be “deactivated” if I don’t re-authenticate to my server. Or I need to authenticate to my server to “keep my same password”. Since I run my own email server, I find these phishing attempts to be downright hysterical because there’s zero chance that they will work on me. But today I got this phishing attempt which is a bit more “interesting”, I got this email this morning:

Sidebar: Seeing as I am a company of two. The two being my wife and I, it’s funny that the threat actors think that we have an HR department. But I guess that a threat actor has to start someplace to try and phish you.
Now I obscured the QR code as I don’t want anyone scanning it. But in lieu of an attachment with a payload that executes on a target’s computer, or a link that the target clicks on, I got a QR code. Likely because it can evade spam filters and other security software or devices.
If you scan the QR code, which should be clear you should not scan the QR code if you get an email like this, it will take you to a phishing page that you are meant to enter your email address and your email password. This fits some other reports of this type of phishing that I have heard about. Here’s a quick list that I’ve posted on this blog in the past:
Fortra Discovers Sophisticated QR Code Phishing Campaign That Targets Office 365 Users
Abnormal Security Announces Enhanced Capabilities to Detect QR Code Attacks
C-Suite Receives 42x More QR Code Attacks Than Average Employee: Abnormal Security
New Report to Reveal QR Code Phishing Scams: Quishing You a Happy Holiday Season
INKY Discusses How Threat Actors Are Using QR Codes To Harvest Credentials
So what this means is that attacks like this one are becoming increasingly pervasive. Thus this is another attack vector that you need to be aware of to keep you and your organization safe.
October 1, 2025 at 9:40 am
The rise of QR code phishing really highlights how attackers are constantly adapting to bypass filters. It’s a reminder that one careless scan could lead to stolen credentials and, in turn, serious data breaches. From what I’ve seen working with a data breach law firm like https://mydatabreachattorney.com/, many incidents start with something as small as a phishing email, yet end up exposing sensitive information of thousands.
September 22, 2026 at 12:40 am
This is exactly the kind of thing that made us build susQR.
QR codes are convenient, but the scary part is you usually have no idea where one is actually sending you until after you scan it — which makes attacks like this way easier to pull off.
With susQR, you can upload a picture of the QR code instead of opening it directly. It shows you the URL hidden inside and checks the destination for malicious activity before you decide whether you want to visit it.
It’s a free project we’ve been building if anyone wants to check it out: https://susqr.com
Really cool seeing more awareness being brought to quishing. I think this attack method is only going to become more common.