Close-up of a smartphone scanning a suspicious QR sticker placed over a payment terminal in dim red and cyan light
AI & Digital Execution

The quishing surge: why QR codes are bypassing enterprise security

AI & Digital ExecutionMarket Intelligence & Macro Trends

The Observation

AI has wiped out the obvious typos and bad formatting that used to give phishing away, pushing click-through rates to a massive 54 percent. Attackers are now weaponising QR codes, a tactic called quishing, to slip past standard email security gateways.

The Analysis

Between August and November 2025, researchers flagged 1.7 million unique malicious QR codes. Quishing now makes up about 25 percent of all email phishing, with 89.3 percent of those attacks aimed directly at Microsoft 365 credentials. Since these codes are images, they dodge traditional text-based link scanners. Once an employee scans one with their phone, it routes them to an AI-optimised, hyper-personalised page built to harvest credentials and bypass standard security barriers.

The Tactical Step

Upgrade your email defences to include computer vision and behavioural analysis that can actually spot malicious QR codes inside messages. Ditch password-only or SMS-based authentication. Deploy phishing-resistant Multi-Factor Authentication, like FIDO2 hardware keys, to cryptographically bind logins to the real domain and kill credential theft at the source.

Question for the network

Are your employees scanning unverified QR codes on corporate devices, and can your current email gateway even detect them?

#CyberSecurity#Phishing#RiskManagement#ZeroTrust#InfoSec

References

  • Vectra AI: AI phishing explained
  • Kaspersky Research: QR code threat tracking 2025

By Michael Lennard Gnaedinger. © 2026 Gnaedinger Consultancy. All rights reserved.

If any of this sounds familiar.

I work with a small number of founders and CEOs each year. The conversation starts here.

Begin the conversation
← Back to all insights