I love it when people come up to me and say they are “wicked paranoid” about QR codes. I have been trying to educate people on the risks of QR codes for years and that gives me satisfaction that I have prevented that person from becoming a victim of a malicious QR code. QR codes have become ubiquitous since the pandemic, starting with menuless menus. I ask for a paper menu, and surprisingly, most restaurants still have them.

Here’s another example to bolster my case. Bleeping Computer reported that the Socket Threat Research Team has identified “a malicious package, ‘fezbox’, published to npmjs.com, the world’s largest open-source registry for JavaScript and Node.js developers….which contains hidden instructions to fetch a JPG image containing a QR code, which it can then further process to run a second-stage obfuscated payload as a part of the attack.” What does this mean? If scanned, the payload will read a cookie with document.cookie. If there is a username and password in the stolen cookie, it can steal that information directly from the victim’s server. The threat actor then has the victim’s credentials to access the victim’s data, including sensitive and proprietary data.

According to Bleeping Computer,  “we have seen countless cases of QR codes deployed in social engineering scams…but these require human intervention…scanning the code and being led to a phishing website, for example…but this week’s discovery by Socket shows yet another twist on QR codes: a compromised machine can use them to talk to its command-and-control (C2) server in a way that, to a proxy or network security tool, may look like nothing more than ordinary image traffic.” Because the threats of malicious QR codes are not well-known yet, I anticipate that threat actors will continue to figure out ways to embed malicious code into them for various goals, including phishing, smishing, and credential stealing, and it will be hard to get out in front of the risk. One way to mitigate is to never scan a public QR code, never click on a QR code in an email, and be wicked paranoid about any QR code presented to you.

We have repeatedly warned our readers about malicious QR codes and their use by threat actors.

Threat actors are now using these codes to disguise packages as gifts. Upon opening the package, recipients find a note with instructions to scan a QR code to identify the sender. The code launches a website that asks for credentials to get more information about the “gift” and provides instructions for returns. The website could also ask for credit card or personal information.

It has become such a problem that the Federal Trade Commission (FTC) has issued a scam alert.

According to the FTC:

“If you scanned the QR code and entered your credentials, like your username and password, into a website, change your password right away. Create a strong password that is hard to guess, and turn on two-factor authentication.

If you’re concerned someone has your personal information, get your free credit report at AnnualCreditReport.com. Look for signs that someone is using your information, like accounts in your name you don’t recognize. (You can get a free credit report every week.)

Also review your credit card bills and bank account statements and look for transactions you didn’t make. And consider taking other steps to protect your identity, like freezing your credit or putting a fraud alert on your credit report.

If you think someone stole your identity, report it, and get a personal recovery plan at IdentityTheft.gov.”

This week is Identity Theft Protection Week. Sign up for the free resources provided by the Federal Trade Commission at ftc.gov and stay safe.

The recent increase in smishing and vishing schemes is prompting me to remind readers of schemes designed to trick users into providing credentials to perpetrate fraud. We have previously written on phishing, smishing, vishing, and QRishing schemes to increase awareness about these methods of intrusion.

HC3 recently warned the health care sector about vishing schemes designed to impersonate employees in order to access financial systems. See previous blog on this topic here.

The City of New York was recently forced to take its payroll system down for more than a week after a smishing scheme that was designed to steal employees’ pay. The attack targeted the city’s Automated Personnel System Employee Self Service users. The threat actor sent fake text messages with multi-factor authentication to employees with a link to insert their self-service credentials, including usernames, passwords, and copies of driver’s licenses. The scheme was designed to steal the information so the payroll system could be accessed in order to divert payroll to the threat actor’s account. 

Phishing, vishing, smishing, and QRishing continue to be successful ways for threat actors to perpetrate fraud. Applying a healthy dose of paranoia whenever you receive any request for credentials, whether by email, phone, text or through a QR code is warranted and wise.

I hate to say, “I told you so,” but I did. I have repeatedly warned against scanning QR codes. Following the pandemic and scanning QR codes at restaurants, people have become very comfortable with scanning QR codes, don’t think twice about it, and don’t fully grasp the risk associated with a malicious QR code. Find previous blog posts pertaining to QR codes here.

It is important to understand that just like malicious code embedded in a link or an attachment in an email or text (which we have been trained not to click on), a threat actor can embed malicious code into a QR code with the same results. Unfortunately, they are starting to do just that.

According to Dark Reading threat actors recently “sent more than 1,000 emails armed with malicious QR codes aimed at stealing Microsoft credentials” to an energy company, and other industries, including manufacturing, insurance, technology, and financial services.

The email phishing campaign with malicious QR codes was discovered by Cofense. According to Cofense, “This campaign makes use of a PDF or image file attachment with the QR code embedded into it… This makes it easier for the emails to bypass Secure Email Gateways.” The campaign is ongoing and “spreading quickly.” The bottom line is to train employees not to scan QR codes, received by email or text, and to alert the IT department if one is received. Everyone should treat QR codes with a high degree of suspicion, just like a suspicious text or email.

The FBI’s Internet Crime Complaint Center (IC3) recently issued a warning alerting consumers that scammers are using malicious QR Codes to reroute unsuspecting customers to malicious sites to try to steal their data.

Also known as QRishing, [view related post] criminals are taking advantage of our familiarity with QR codes after using them at restaurants and other establishments during the pandemic, to use them to commit crimes. The criminals embed malicious codes into QR codes to redirect a user to a malicious site and then attempt to get the user to provide personal information, financial information or other data that the criminals can use to perpetrate fraud or identity theft.

Embedding malicious code into a QR code is no different than embedding it into a link or attachment to a phishing email or a smishing text. Consumers are not as alert to question QR codes as we are to spot malicious emails and texts.

Hence, the alert from IC3. IC3 is warning consumers to check and re-check any URL generated by a QR code and to be cautious about using them for any form of payment.

QR codes should be viewed as suspiciously as emails and texts. Be cautious when asked to scan a QR code, and refuse to provide any type of personal information or financial information after scanning one.

We have previously alerted you to vishing and smishing schemes [view related post]. A new scheme, using QR codes, is called QRishing or quishing. According to security company Abnormal, between September 15 and October 13, 2021, it identified a new way for hackers to try to get around security measures put in place to keep users from clicking on malicious links or attachments. The phishing campaign they detected was designed to collect Microsoft credentials using QR codes.

According to Abnormal, the threat actors used compromised email accounts to send QR codes that looked like a missed voice mail to users.  Although the threat actors were unsuccessful in getting users to click on the QR code or take a picture of it and send it to their email account in order to click on it, the point is that attackers are getting increasingly more creative and embedding malicious code behind QR codes, which became widely used by restaurants and other establishments during COVID. Many people had never heard of a QR code or used one until COVID hit, and no one seems particularly concerned about taking a picture of a QR code when instructed to do so.

The tip here is to be cautious of QR codes, especially in an email or text, and specifically if someone is asking you to click on it or it is linked to a missed voicemail message. If QR codes are emailed, they might not be detected by the email security system, which is exactly what the attacker has designed it to do so it is delivered to your email box, giving you the chance to click on it and compromise your Outlook credentials. The new mantra is don’t click on suspicious links, attachments, or QR codes.

In a recently released report titled Cybersecurity in Global Sport: Threats, Signals, and Strategic Implications for a Digitized Industry, cybersecurity firm Darktrace has outlined “the current challenges the global sporting sector faces and…forward-looking views on future challenges as AI increasingly becomes adopted across the sector.”

The Report’s conclusions were the result of a survey to 875 IT cybersecurity professionals across sports organizations located in the U.S., U.K., Australia, and Germany.

Because the global sports industry “has undergone a rapid and continuous digital transformation” (including digital ticketing platforms, broadcasting, mobile applications, and third-party vendor support), and sports organizations are adopting generative AI and agentic AI tools, emerging cybersecurity threats are targeting these organizations.

The Report’s key takeaways include:

  • 84% of professional sports organizations surveyed have experienced at least one cyber incident in the past 12 months, with more than half (57%) hit multiple times. This underscores that cyber risk is already an operational issue for the sector.
  • 34% of respondents cited stadium operations as the most critical function to protect during a live event, reinforcing that cyber resilience in sport is defined by high-visibility moments where downtime is least acceptable.
  • Sports sector customers received 19% more phishing emails than non-sports sector customers, reinforcing that email and identity remain dominant attack vectors for sports organizations.
  • 21% of phishing emails targeting sports sector customers were sent to VIPs, while 37% contained novel social engineering techniques, highlighting how attackers are focusing on high value identities and adapting tactics to exploit urgency, trust, and operational complexity in the sports sector.
  • 47% of respondents cited AI prompt risks and attacks and AI development risks and deployment as top concerns for AI use within their organizations.
  • 72% of IT cybersecurity professionals from sports organizations surveyed believe AI will increase cyber risk over the next 12 months as adoption grows in high stakes areas including stadium operations, ticketing and fan engagement, and business operations.

Sports organizations have been victimized by various threats including: “client-side payment skimming, ransomware outbreaks, and compromise of ecommerce infrastructure through third-party scripts. Fan platforms and mobile applications have been accessed via exposed keys and weak API security, placing large user populations at risk.”

Darktrace suggests that organizations treat cyber risk “as an operational and governance challenge” to be resilient against attacks. This includes:

1.         Threat modeling for emerging technologies, including AI misuse;

2.         Rigorous supply chain governance and vendor access control;

3.         Strong segmentation across IT, OT, and fan-facing systems;

4.         Identity-centric security with anomaly detection and universal multi-factor authentication (MFA);

5.         Phishing resilience across all channels, including QR-based vectors; and

6.         Operational playbooks aligned to live event constraints.

The Report is a must read for those in the sports sector

Critical infrastructure operators at the water treatment plant in Minot, North Dakota, were forced to resort to manual processes when its Supervisory Control and Data Acquisition (SCADA) system became inoperable as a result of a March 14, 2026, ransomware attack. The attackers are unidentified, but it comes in the wake of the war in Iran, and both Iran and China are known to lead cyber-attacks against water utilities, which often have vulnerabilities that make them easy targets. Last month, the Water Information Sharing and Analysis Center, along with information sharing organizations for the auto, aviation, food, health, IT, national defense, oil and natural energy, and retail and hospitality industries issued a Joint Advisory to their members, including water facilities, warning them of increased cyberattacks from Iranian hackers, as well as physical attacks against critical infrastructure entities. The warning concluded by stating that “the threat environment is likely to remain highly volatile.”

Minot’s water system provides water to approximately 80,000 users. Although the water supply and quality were not affected by the attack, operators were required to manually read gauges for 16 hours while they uninstalled the compromised SCADA system. It has taken Minot over two weeks to spin up a new server.  

Since water facilities are a target for nation state cyber actors, the state of New York recently introduced cybersecurity standards for both drinking and wastewater treatment facilities. Other states will hopefully follow suit so the water supply and quality available will be less vulnerable to attack.

Critical infrastructure operators should be aware of the heightened risk, prepare for an attack, and test their incident response processes through a cybersecurity tabletop exercise that is designed to address a shut down so processes can be improved and services restored as efficiently as possible. We all depend on the basic necessities of food, water, electricity, and access to financial services, all of which could be downed by an attack and dramatically impact our lives. We depend on critical infrastructure operators to have measures in place to prevent and mitigate the effects of an attack.

Cybersecurity firm Darktrace recently issued its Annual Threat Report, which offered some startling statistics and findings. The Threat Report provides a “comprehensive assessment of the global cyber threat landscape and the trends shaping cyber risk in 2026.”

Findings are summarized below, but we strongly encourage read the whole report.

  • Email attacks are getting more sophisticated (which we know). Darktrace analyzed 32 million phishing emails and determined that threat actors are using AI to create content and evade detection, in addition to a marked increase in “identity-targeting techniques.”
  • QR-code phishing attacks increased 28% between 2024 and 2025. A new technique, dubbed “splishing” (“in which a QR code is split into two distinct images”) and QR code “nesting” (“where a legitimate QR code is embedded with a malicious one”) are designed to bypass link-scanning tools and re-route victims to malicious sites.
  • Newly created domains are on the rise. 1.6 million phishing emails “relied on newly created domains spun up specifically for malicious activity.”
  • “70% of phishing emails passed DMARC authentication, helping them appear legitimate to both users and automated controls.”
  • Critical national infrastructure is being targeted.

The report is consistent with what we see on a day-to-day basis. It provides valuable insight into the threats facing companies and individuals and what the trends will be in 2026, all of which can be used to build a cybersecurity strategy and education for your organization.

As we have warned before, threat actors using QR codes in attacks against victims continue to rise. To illustrate the risk, on January 8, 2026, the FBI issued a FLASH alert, entitled “North Korean Kimsuky Actors Leverage Malicious QR Codes in Spearphishing Campaigns Targeting U.S. Entities.”

The alert warns that North Korean state-sponsored actors (Kimsuky) are conducting spearphishing campaigns leveraging QR codes (Quishing) to compromise U.S. entities. These attacks target organizations including think tanks, academic institutions, NGOs, and government contractors.

The threat attackers are embedding malicious QR codes in email attachments or graphics through spearphishing emails impersonating trusted contacts (e.g., advisors, embassy staff). When victims receive the QR code, they scan them using mobile devices, which allows the threat actor to bypass corporate email security and endpoint monitoring. After scanning the QR code, the victim is routed through “attacker-controlled redirectors that collect device and identity attributes” and serve phishing pages mimicking Microsoft 365, Okta, VPN portals, or Google login screens.

The threat actor is then able to steal credentials to enable unauthorized access to cloud services. Since the attacks originate from unmanaged mobile devices,  threat detection is difficult.

The FBI recommends:

  • Employee Awareness: Train staff to avoid scanning unsolicited QR codes.
  • Verify Sources: Confirm legitimacy before interacting with QR codes.
  • Mobile Device Management (MDM): Enforce security controls on all mobile endpoints.
  • Phishing-Resistant MFA: Implement for sensitive systems and remote access.
  • Access Reviews: Apply least privilege and conduct regular audits.
  • Incident Reporting: Notify the FBI Cyber Division or IC3 immediately if suspicious activity is detected.

As we have previously noted, employees are particularly vulnerable to Quishing campaigns as many don’t understand the technology and QR codes are now ubiquitous. When we conduct employee training, this lack of understanding is reinforced. We strongly recommend that you educate your employees about Quishing. If you are interested in learning more about our cybersecurity training, please contact us.