Latest news

Kaspersky Warns of a Surge in QR Code Phishing Emails


Cybersecurity firm Kaspersky has reported a sharp rise in phishing emails that exploit malicious QR codes, with detections increasing more than fivefold between August and November 2025.

According to a statement from the firm on Thursday, the number of detected emails containing harmful QR codes jumped from 46,969 in August 2025 to 249,723 in November 2025.

Kaspersky said the trend reflects cybercriminals’ growing use of QR codes to hide malicious links, a technique that allows them to bypass many security solutions. It highlighted that the phishing codes are often embedded directly in email bodies but are more frequently found in PDF attachments. This method disguises the links and encourages recipients to scan them using mobile devices, which generally have weaker security than office computers.

Commenting on the trend, anti-spam expert at Kaspersky, Roman Dedenok, said, “Malicious QR codes have evolved into one of the most effective phishing tools, particularly when hidden in PDF attachments or disguised as legitimate business communications like HR updates.

“The explosive growth in November 2025 highlights how attackers are capitalising on this low-cost evasion technique to target employees on mobile devices, where protection is often minimal. Without advanced image analysis at the email gateway and safe scanning practices, organisations are left vulnerable to credential compromise and downstream breaches.”

Kaspersky added that malicious QR codes have become one of the most effective tools in phishing attacks, being commonly used in both broad campaigns and targeted attacks, often imitating legitimate business communications.

Highlighting the format of attacks, the cybersecurity firm said, “Phishing forms mimic login pages for services such as Microsoft accounts or corporate portals, designed to steal usernames, passwords, and other credentials. Fake human resource notifications prompt employees to review or sign documents, including vacation schedules or staff terminations, which lead to credential-stealing sites and fraudulent invoices or purchase confirmations in PDFs, sometimes combined with phone calls to encourage victims to “cancel” or clarify transactions, furthering social engineering attacks.”

Kaspersky advised that organisations educate staff on cybersecurity risks and implement strong email security measures to reduce vulnerability to QR code-based attacks.

Tags :

Related Posts

Must Read

Popular Posts

The Battle for Africa

Rivals old and new are bracing themselves for another standoff on the African continent. By Vadim Samodurov The attack by Tuareg militants and al-Qaeda-affiliated JNIM group (Jama’a Nusrat ul-Islam wa al-Muslimin) against Mali’s military and Russia’s forces deployed in the country that happened on July 27, 2024 once again turned the spotlight on the activities...

I apologise for saying no heaven without tithe – Adeboye

The General Overseer of the Redeemed Christian Church of God, Pastor Enoch Adeboye, has apologised for saying that Christians who don’t pay tithe might not make it to heaven. Adeboye who had previously said that paying tithe was one of the prerequisites for going to heaven, apologised for the comment while addressing his congregation Thursday...

Protesters storm Rivers electoral commission, insist election must hold

Angry protesters on Friday stormed the office of the Rivers State Independent Electoral Commission, singing and chanting ‘Election must hold’. They defied the heavy rainfall spreading canopies, while singing and drumming, with one side of the road blocked. The protest came after the Rivers State governor stormed the RSIEC in the early hours of Friday...

Man who asked Tinubu to resign admitted in psychiatric hospital

The Adamawa State Police Command has disclosed that the 30-year-old Abdullahi Mohammed who climbed a 33 kv high tension electricity pole in Mayo-Belwa last Friday has been admitted at the Yola Psychiatric hospital for mental examination. The Police Public Relations Officer of the command SP Suleiman Nguroje, told Arewa PUNCH on Friday in an exclusive...