Hackers Use QR Codes in Phishing Emails to Steal Login Credentials
Brief
Hackers are putting QR codes in phishing emails to steal login credentials. Known as quishing, the method hides a dangerous web address inside a square and persuades recipients to scan it with a phone.
The tactic exploits a habit: people distrust suspicious links but may view a QR code as a routine shortcut. A convincing message can claim an urgent payroll update, benefits notice, or document requiring review.
The QR-code phishing reached record levels in its H1 2026 telemetry. Researchers recorded a steady rise from the start of the year, with the highest volume in April.
ESET said in a report shared with Cyber Security News (CSN) that the impact can extend beyond one stolen password. A scan may expose work email, cloud files, payment data, and other sensitive accounts, giving an attacker a foothold for further fraud or internal phishing.
