QR Code Phishing Hits 11% of Brazil Email Attacks, Experts Warn of Rapid Rise
Cybercriminals are increasingly exploiting QR codes to deliver phishing scams, a technique known as “quishing.” According to ESET’s Threat Report H1 2026, roughly 11 % of all phishing emails detected in Brazil now contain QR codes, amounting to about 100 000 detections each month with a peak in April. The share grew from 0.8 % of phishing attacks in 2021 to nearly 12 % in 2025, and incidents reported in the first quarter of 2026 rose about 146 % year‑on‑year.
The surge is linked to the widespread everyday use of QR codes for payments, menus and tickets—86 % of Brazilian consumers regularly scan QR codes, most often with the Pix instant‑payment system. Researchers such as Jonathan Ramos of ESET say the visual simplicity of QR codes “creates a sense of legitimacy” that attackers exploit. Because QR codes are images, traditional email‑filtering tools that scan text URLs often miss the malicious payload, which appears only after the code is scanned on a mobile device.
Similar observations appear in Chilean media, highlighting that the technique is spreading globally and that up to 73 % of users scan QR codes without verifying the destination. Security experts advise users to treat unsolicited QR codes with suspicion, verify the opened URL, and employ security solutions that can detect malicious links before they are scanned.