Kaspersky reports 430% increase in three months
According to Kaspersky, the number of malicious QR codes in emails increased from 46,969 to 249,723 detected cases between August and November 2025 – more than a fivefold increase.
Kaspersky study documents rise in QR code phishing
Russian cybersecurity firm Kaspersky documented an increase in QR code phishing, known as quishing, in a recent study. According to the company, the number of malicious QR codes in emails rose by more than 430 percent between August and November 2025.
"Malicious QR codes have become a particularly effective phishing tool in 2025," said Roman Dedenok, anti-spam expert at Kaspersky. The company cited the comparatively weak protection of mobile devices as one reason.
Common attack patterns identified in the study
According to Kaspersky, attackers are steadily refining their methods. The study identifies three common attack patterns:
Fake Login Pages
According to the study, QR codes lead to imitation Microsoft login pages or internal company portals.
Fake HR Communications
Emails about vacation plans, layoffs, or salary changes with QR codes leading to phishing sites.
Fake Invoices + Vishing
Fake invoices with QR codes, combined with phone contact attempts (Voice Phishing).
QR codes increasingly embedded in PDF attachments
According to the study, attackers are increasingly embedding malicious QR codes in PDF attachments. Kaspersky said the approach offers two advantages:
- Professional Impression: PDF documents create the impression of business correspondence and increase recipient trust.
- Bypassing Security Filters: Many email security systems cannot analyze QR codes in PDF documents – the malicious links remain undetected.
Mobile devices are the main target
The attacks mainly target mobile devices, according to Kaspersky. Smartphones are typically less protected than corporate computers.
Vulnerabilities of Mobile Devices:
What Kaspersky recommends
- Check Attachments: Do not open PDF attachments from unknown senders – especially if they contain QR codes.
- Check URLs: After scanning, check the URL for typos or suspicious domains before visiting the page.
- Multi-Factor Authentication: Enable MFA for all important accounts – even if login credentials are stolen, this provides additional protection.
- Security Solutions: Use comprehensive security solutions that can also check QR codes for phishing.
QR code checking with QRTrust
Many email filters do not detect QR codes in PDF attachments. QRTrust checks the destination URL of a QR code against multiple databases before it is opened and displays the result.
How QRTrust Protects Against Quishing:
- Checks destination URLs against PhishTank, Google Safe Browsing and proprietary AI analysis
- Real-time warning before the destination URL is opened
- Redirect tracking: detects hidden redirects to phishing sites
- GDPR compliant – data is processed only in Germany
Context: fivefold increase in three months
According to Kaspersky, the number of malicious QR codes in emails more than quintupled within three months. The company attributed the development to embedding in PDF attachments, a focus on mobile devices and increasingly targeted attack methods.
Kaspersky advises checking QR codes from emails and PDF attachments before opening them, including the destination URL.
Sources
- datensicherheit.de: "Quishing: Kaspersky reports significant increase in QR code phishing"
- Kaspersky Security Report 2025
About QRTrust
QRTrust is Germany's first QR code security platform, developed in Dortmund. AI-powered real-time detection, a local threat database and multi-layered security checks protect citizens, authorities and businesses from quishing attacks. GDPR compliant, hosted in Germany.
