Microsoft Threat Intelligence tracked QR code phishing attacks rising from 7.6 million in January 2026 to 18.7 million in March. A 146% increase in one quarter.
Why it works: the QR code is an image. Plenty of email defenses were built to inspect links, not pictures. And the person scanning it is usually doing it on a phone, which is often outside the controls that protect their laptop.
How I'd work a quishing case:
- Decode the QR yourself. Don't trust the preview.
- Follow the redirect chain to the real landing page
- Find out where the page sends what people type into it
- Pull sign-ins for everyone who received the message
Assume someone scanned it. Someone always scans it.