Last updated: July 2026 · By the susQR security team · All statistics sourced below
Quishing — phishing attacks delivered through QR codes — has become one of the fastest-growing cyber threats. This page collects sourced statistics on QR code phishing to help security teams, journalists, and researchers understand the current threat landscape.
Key statistics at a glance
Rise in QR phishing in Q1 2026 (Microsoft)
Malicious QR codes detected per day (Unit 42)
Of Americans scan QR codes without verifying them
Unique malicious QR codes found in email attachments in 2025
Growth trajectory
QR code phishing was rare before 2023. The COVID-19 pandemic accelerated QR code adoption for contactless interactions — menus, payments, check-ins — and attackers followed.
- 2022: QR code phishing appears primarily in corporate email campaigns. FBI IC3 issues first public warning about QR code tampering.
- 2023: Check Point Research documents a 587% increase in QR-based phishing attacks compared to the prior year. Most attacks target corporate credentials via fake MFA enrollment pages.
- 2024: Industry reports indicate QR codes are used in approximately 22% of all phishing attacks, up from under 5% in 2022 (Abnormal Security, 2024). Physical QR code tampering in public spaces becomes widespread.
- 2025: QR phishing attacks grow roughly fivefold over the year. Attackers pivot from email links to text messages impersonating DMVs, toll authorities, and courts — the FTC issues a consumer alert about fake "overdue traffic ticket" texts (July 2025). ZenSec identifies 1.7 million unique malicious QR codes in email attachments alone.
- 2026: Microsoft reports a 146% rise in QR code phishing in Q1 2026 across the 8.3 billion email phishing threats it analyzed. Malicious QR codes increasingly hide inside PDF attachments to slip past link-rewriting and sandboxing (Hoxhunt). A nationwide wave of fake traffic-violation texts uses QR code images instead of links — routing victims through a CAPTCHA to fake DMV/court payment pages. Scammers also adopt professionally designed "branded" QR codes with logos and brand colors, making fakes harder to spot (N.C. Department of Information Technology, Feb 2026).
Who is targeted
- Corporate employees: 67% of enterprise quishing targets Microsoft 365 and Google Workspace credentials (Cofense, 2024)
- Mobile users: 76% of quishing attacks are designed to exploit mobile devices, which have smaller URL previews and often auto-open links from QR codes
- Financial sector: Banking and payments are the most impersonated category in QR phishing, accounting for 34% of attacks
- Healthcare: Patient portal login pages are increasingly targeted, especially through QR codes in waiting rooms and appointment reminders
Attack vectors
Digital delivery
- Phishing emails with QR code images (bypasses URL scanners)
- SMS/text messages with QR codes
- Social media posts and direct messages
- Fake ads on websites
Physical placement
- Parking meters and pay stations
- Restaurant tables and menus
- EV charging stations
- Public transit, flyers, mail
Why QR phishing works
Several factors make QR codes an effective phishing vector:
- No visible URL: Users can't preview the destination before scanning
- Bypasses email security: URLs embedded in images evade traditional text-based scanners
- Inherent trust: People associate QR codes with legitimate businesses
- Mobile targeting: Phones show truncated URLs and have weaker phishing warnings than desktop browsers
- Physical credibility: A QR code on a parking meter or official-looking sign appears trustworthy
Detection challenge
Traditional security tools struggle with QR-based phishing for specific technical reasons:
- Email security gateways scan text-based URLs but not URLs encoded in QR code images
- Mobile devices often lack enterprise security tools that would catch phishing on desktops
- QR codes can encode URLs that require multiple redirects, making the final destination hard to pre-screen
- Shortened URLs (bit.ly, t.co) further obscure the destination from users and security tools
How susQR addresses this
susQR was built specifically for the QR code threat vector. Unlike email scanners or antivirus tools, we decode the QR code, follow all redirects, and check the final destination against 90+ security vendors and threat databases. See how our risk scoring works.
Sources & references
- Microsoft Threat Intelligence: 146% rise in QR code phishing, Q1 2026 (via TechRadar Pro, 2026)
- Palo Alto Networks Unit 42: telemetry averaging 11,000+ malicious QR detections per day (2025–2026)
- ZenSec: 1.7 million unique malicious QR codes detected in email attachments (2025)
- NordVPN / CNBC survey: 73% of Americans scan QR codes without verification
- Hoxhunt: quishing payloads shifting into PDF attachments (2026)
- FTC Consumer Alert: "That text about an overdue traffic ticket is probably a scam" (July 2025)
- N.C. Department of Information Technology: alert on branded "fancy" QR codes (February 2026)
- Check Point Research: "Quishing: QR Code Phishing" — 587% attack increase (2024)
- Abnormal Security: "QR Code Phishing Trends Report" — 22% of phishing uses QR codes (2024)
- Cofense Phishing Intelligence: Enterprise quishing targeting statistics (2024)
- FBI IC3 Public Service Announcement: "Cybercriminals Tampering with QR Codes" (2022)
- FTC Consumer Alert: "Scammers hide harmful links in QR codes" (2023)
Note: Statistics are compiled from published research reports and public advisories. Individual statistics may vary by reporting methodology. Last verified July 2026.