Your Password Manager Is Now the Primary Target. Here Is What Attackers Are Doing Differently in 2026

Security researchers tracking phishing campaigns have recorded a 400 percent increase in attacks that use QR codes as the delivery mechanism in the first six months of 2026. The technique bypasses most email security gateways because the malicious URL is embedded inside an image rather than a clickable text link.

Attackers send a legitimate looking email containing only a QR code and a short instruction such as ‘scan to verify your account’ or ‘scan to complete your delivery’. When the target scans the code on their personal phone the device opens the fraudulent URL outside the corporate security perimeter where endpoint detection tools are typically absent.

Attack Volume by Sector

The following table shows QR phishing attack volumes broken down by targeted industry sector across Q1 and Q2 of 2026 based on aggregated threat intelligence from four major security vendors.

Industry SectorQ1 2026 AttacksQ2 2026 Attacks% Change
Financial Services1,8409,200+400%
Healthcare6202,790+350%
Logistics and Shipping4902,450+400%
Government and Public Sector3101,240+300%
Retail and eCommerce8803,960+350%
All Other Sectors1,1004,400+300%

Table 2: QR phishing attack volumes by sector, H1 2026 (Source: Aggregated threat intelligence, four major security vendors)

Why Traditional Defences Fail Against QR Phishing

Standard email security tools scan hyperlinks in message bodies and attachments. A QR code is a rasterised image and the URL inside it is invisible to text scanning engines. The gateway sees a JPEG or PNG and finds no suspicious link to analyse.

The second problem is device context. Corporate laptops typically run endpoint detection agents. Personal phones used to scan QR codes rarely do. The attack therefore completes outside the perimeter that security teams control.

QR Phishing Attack Flow

QR CODE PHISHING: HOW THE ATTACK BYPASSES DEFENCES
ATTACKER  –>  Crafts email with QR code image embedded (no text link present)
EMAIL GATEWAY  –>  Scans message, finds image only, no malicious URL detected, email delivered
VICTIM (on corporate laptop)  –>  Sees QR code, picks up personal phone to scan it
PERSONAL PHONE  –>  Opens URL outside corporate perimeter, no endpoint agent running
CREDENTIAL PAGE  –>  Victim enters username and password on convincing fake login page
RESULT: Credentials stolen  |  Account compromised  |  No security tool flagged the attack

Diagram 2: QR phishing attack flow showing where traditional defences fail

Defenders should train users to treat any QR code in an unexpected email with the same suspicion they would apply to an unexpected link. Organisations can also deploy mobile device management solutions that route phone browser traffic through a corporate proxy even when the device is off the corporate network.

Leave a Reply

Your email address will not be published.