The Observation
AI has wiped out the obvious typos and bad formatting that used to give phishing away, pushing click-through rates to a massive 54 percent. Attackers are now weaponising QR codes, a tactic called quishing, to slip past standard email security gateways.
The Analysis
Between August and November 2025, researchers flagged 1.7 million unique malicious QR codes. Quishing now makes up about 25 percent of all email phishing, with 89.3 percent of those attacks aimed directly at Microsoft 365 credentials. Since these codes are images, they dodge traditional text-based link scanners. Once an employee scans one with their phone, it routes them to an AI-optimised, hyper-personalised page built to harvest credentials and bypass standard security barriers.
The Tactical Step
Upgrade your email defences to include computer vision and behavioural analysis that can actually spot malicious QR codes inside messages. Ditch password-only or SMS-based authentication. Deploy phishing-resistant Multi-Factor Authentication, like FIDO2 hardware keys, to cryptographically bind logins to the real domain and kill credential theft at the source.
Question for the network
Are your employees scanning unverified QR codes on corporate devices, and can your current email gateway even detect them?
References
- Vectra AI: AI phishing explained
- Kaspersky Research: QR code threat tracking 2025
By Michael Lennard Gnaedinger. © 2026 Gnaedinger Consultancy. All rights reserved.
If any of this sounds familiar.
I work with a small number of founders and CEOs each year. The conversation starts here.

