Portugal reports QR code phishing as seventh most common email threat
ESET’s analysis of email security data from December 2025 to May 2026 shows that fraudulent QR‑code attacks – known as “quishing” – accounted for 4.8% of all detected email threats in Portugal, placing them as the seventh‑most common category nationally. The company recorded an average of roughly 100,000 detections each month, with the highest volume in April 2026, the peak observed since it began tracking the technique independently in September 2025.
Globally, about 11% of phishing emails identified by ESET relied on QR codes to hide malicious links. The method replaces visible URLs with QR symbols that, when scanned on a smartphone, direct victims to counterfeit pages designed to steal credentials, financial information, or other sensitive data. Typical campaigns masquerade as internal HR or payroll communications, or mimic services such as DocuSign, prompting users to scan the code to view documents, verify salary changes, or approve approvals. Ricardo Neves, ESET Portugal’s communications lead, explained that the hidden link “reduces visibility of the attack, moving the interaction to a mobile device where users often lack the same security controls,” increasing the fraud’s success rate.