[REVISION HISTORY]
Global rise in QR-code phishing attacks
Updated 5 times since CLSTR started tracking revisions of this situation.
What changed
2026-08-25 12:52 UTC → 2026-08-27 15:12 UTC ·
added
removed
In late July 2026, law-enforcement agencies across Europe, North America and Asia warned that the worldwide surge in QR-code phishing—often called “quishing”—had expanded beyond the parking-meter stickers first reported in Zug, Switzerland. Criminals are now swapping legitimate QR stickers on a range of public fixtures, including restaurant tables, ticket machines and information boards, directing users to concealed fraudulent sites that harvest banking credentials and install malware such as Hook v3 and RedHook. By mid-August, security experts warned that these attacks are increasingly “MFA-resilient,” capable of bypassing multi-factor authentication by stealing tokens, initiating malicious downloads, or manipulating Wi-Fi connections. This tactic aims to lure victims from protected desktop environments to private mobile devices where security measures are often less effective. The FBI has specifically identified the North Korean hacker group Kimsuky (APT43) for using QR codes in spearphishing attacks against organizations in the United States, often employing device fingerprinting to steal credentials. Regional vulnerabilities continue to emerge. In Argentina, the rapid adoption of QR payments has created risks, with the BA-CSIRT noting primary danger occurs when users enter sensitive data after scanning. In Spain, the Cybersecurity Agency of Catalonia identified a scam involving unsolicited packages containing QR codes that promise gifts. Additionally, reports from Wales highlight the exploitation of parking meters, where scanning fraudulent codes has led to unauthorized bank withdrawals. Data from Report Fraud indicates a 700% increase in QR code-related scam reports over the last four years. In late August, new tactics were identified in Lithuania. According to data from Tele2, cybersecurity firm Interneto apsauga blocked over 107 million threats in July. Scammers in the region are reportedly presenting QR codes on computer screens under the guise of “robot verification” or video playback requirements. Scanning these codes redirects mobile users to unsafe websites.
Versions
- 2026-08-27 15:12 UTC Global rise in QR-code phishing attacks
- 2026-08-25 12:52 UTC Global rise in QR-code phishing attacks
- 2026-08-18 05:33 UTC Global rise in QR-code phishing attacks
- 2026-08-13 21:36 UTC Global rise in QR-code phishing attacks
- 2026-08-03 00:14 UTC Global rise in QR‑code phishing attacks
- 2026-07-30 04:08 UTC Global rise in QR‑code phishing attacks
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.