← All posts post

The Link You Can't See

QuishingOctober 2026 · 1 min read

Microsoft Threat Intelligence tracked QR code phishing attacks rising from 7.6 million in January 2026 to 18.7 million in March. A 146% increase in one quarter.

Why it works: the QR code is an image. Plenty of email defenses were built to inspect links, not pictures. And the person scanning it is usually doing it on a phone, which is often outside the controls that protect their laptop.

How I'd work a quishing case:

  • Decode the QR yourself. Don't trust the preview.
  • Follow the redirect chain to the real landing page
  • Find out where the page sends what people type into it
  • Pull sign-ins for everyone who received the message

Assume someone scanned it. Someone always scans it.

Sources

  1. Microsoft Security Blog: Email threat landscape, Q1 2026
  2. Cybersecurity Dive coverage