QR Code Phishing Attacks Jump Fivefold In Late 2025, Kaspersky Warns Of Ongoing Risk
Written by: APO Group - Africa Newsroom Save to Instapaper
Malicious QR codes have evolved into one of the most effective phishing tools, particularly when hidden in PDF attachments or disguised as legitimate business communications
JOHANNESBURG, South Africa, January 22, 2026/APO Group/ --
Kaspersky (www.Kaspersky.co.za) has reported a spike in phishing emails containing malicious QR codes. Detections for these jumped from 46,969 in August 2025 to 249,723 in November 2025 – a more than fivefold growth – as cybercriminals increasingly exploit QR codes, a trend that will likely continue in 2026. Attackers use QR codes in emails more frequently because they provide a simple and cost-effective way to conceal malicious URLs, evading detection by many protective solutions.
These QR codes are often embedded directly in email bodies or, even more commonly, within PDF attachments – an evolution that both masks phishing links and encourages users to scan them on mobile phones, which may have weaker security than work PCs.
Malicious QR codes commonly appear in mass phishing campaigns as well as targeted ones. Links embedded within them may lead to:
- Phishing forms impersonating login pages for services like Microsoft accounts or internal corporate portals, designed to steal usernames, passwords, and other credentials.
- Fake HR notifications urging employees to review or sign documents, such as vacation schedules, or even view lists of terminated staff, ultimately directing to credential-stealing sites.
- Fraudulent invoices or purchase confirmations in PDF attachments, often combined with vishing (voice phishing) tactics that prompt victims to call provided phone numbers to "cancel" or clarify the transaction, enabling further social engineering attacks.
These tactics exploit trust in routine business communications, leading to credential theft, account takeovers, data breaches, and financial fraud.
"Malicious QR codes have evolved into one of the most effective phishing tools, particularly when hidden in PDF attachments or disguised as legitimate business communications like HR updates. The explosive growth in November 2025 highlights how attackers are capitalising on this low-cost evasion technique to target employees on mobile devices, where protection is often minimal. Without advanced image analysis at the email gateway and safe scanning practices, organisations are left vulnerable to credential compromise and downstream breaches," comments Roman Dedenok, Anti-Spam Expert at Kaspersky.
To defend against this escalating threat, Kaspersky recommends educating employees on cybersecurity and deploying a mail server security solution such as Kaspersky Security for Mail Server (https://apo-opa.co/3YScvl5) that provides trusted and secure corporate email exchange, countering spam, email-borne infections, all forms of phishing, business email compromise (BEC), QR code attacks, and other threats.
Get new press articles by email
We submit and automate press releases distribution for a range of clients. Our platform brings in automation to 5 social media platforms with engaging hashtags. Our new platform The Pulse, allows premium PR Agencies to have access to our newsletter subscribers.
Latest from
- South Africa Launches Comprehensive AI Policy Built On Ethics Innovation And Inclusive Development
- White Star Launches Real Homemakers Initiative To Celebrate Caregivers And Community Champions
- Angola Oil And Gas Conference Returns As Sector Enters New Phase Of Growth And Investment
- Investment Conference Delivers Record Commitments To Fuel Growth Jobs And Economic Recovery
- Brazil Africa Energy Nexus Emerges As Key Driver Of Offshore Investment And Project Delivery
- Standard Bank And National Arts Festival Announce 2026 Young Artist Award Winners
- Air Cargo Demand Climbs Sharply In February As Industry Navigates Fuel Costs And Conflict Risks
- CFAO South Africa Reports Resilient Performance Through Diversification And Cost Focused Strategy
- Caribbean Energy Week Brings Leaders Together To Advance Oil Projects Renewables And Regional Growth
- Pantry Introduces Enhanced Pop Up Experience In Sandton With Focus On Quality And Convenience
- TotalEnergies Invests In West Coast Entrepreneurs Through Training Mentorship And Enterprise Support
- GIBS Highlights Importance Of Human Centred Leadership In Times Of Uncertainty And Change
- Sars Delivers Above Target Revenue Performance Amid Tough Economic And Global Conditions
- Industry Warns Of Growing Illicit Alcohol Trade Amid Rising Costs And Easter Demand Surge
- Khoi Tech Leads Innovation In Africa With Locally Developed Wearables And Integrated Health Platforms
The Pulse Latest Articles
- Bright Beginnings Preschool Celebrates Linden Campus (April 2, 2026)
- Female Founders Announce Launch Of South Africa’s Premium Brand Advisory Firm: Aura (April 2, 2026)
- Ai Fraud Defence Launches In South Africa As Deepfakes Hit Financial Institutions (April 1, 2026)
- Influencers Share Their Favourite Holiday Games (March 26, 2026)
- Procurement Can Buy Pr. It Cannot Buy Judgement. (March 25, 2026)
