Microsoft reports a 146 % increase in phishing via unfamiliar QR codes and warns of their danger

Microsoft reports a 146 % increase in phishing via unfamiliar QR codes and warns of their danger

44 hardware

Microsoft reports a sharp rise in QR‑phishing and other new attacker tactics

*QR‑phishing (phishing via QR codes) increased by 146 % in Q1 2026.*

These figures are based on an analysis of 8.3 billion phishing emails that Microsoft’s protection detected from January to March. In addition to QR‑phishing, there was a rise in attacks through compromised corporate email (BEC), CAPTCHA bypasses, and phishing messages with attachments/links.

1. QR‑Phishing Trend
- Total volume: fluctuated over the quarter, but Microsoft notes a clear shift toward using QR codes.
- Reason: attackers adapt to enhanced scanning defenses. Text emails are quickly detected, while QR codes remain a “wire” outside the protected work‑computer environment. The risk rises if the victim uses a personal smartphone.
- Delivery methods:
- At the start of the quarter, PDFs were the main channel.
- In March, the number of codes embedded directly in email text without attachments rose by 336 %.
- CAPTCHA bypasses: after a downward trend in January and February, their count spiked more than 125 % in March. Attackers use CAPTCHAs as a “gateway” to malware, forcing victims to interact with a site before downloading.

2. Variety of Delivery Methods
Microsoft notes that attackers are not limited to one method:
- HTML attachments
- SVG files
- PDF documents
- DOC/DOCX files
- Embedded phishing links in emails

These options allow bypassing various protection layers.

3. Successes Against the Tycoon2FA Platform
In March, Microsoft and Europol jointly dismantled the Tycoon2FA infrastructure – “phishing as a service” (PhaaS).
- Reduced attacks linked to the group by 15 %.
- However, the group quickly rebuilds its infrastructure: by the end of March, 41 % of Tycoon2FA domains were registered in the .RU zone.

4. Corporate Email – A New Target
Microsoft identified 10.7 million phishing emails aimed at corporate accounts:
- Attackers use a “bait” (e.g., a message “Are you there?”) to start a dialogue and then send a malicious file in a separate email.
- During tax season, they send requests to update payment details for payroll processing.
- In February, the number of such attacks rose by 15 %.

5. Protection Recommendations
1. Check Exchange Online Protection and Microsoft Defender for Office 365 settings – ensure recommended security parameters are enabled.
2. Enable in Defender for Office 365:
- Zero‑hour auto purge (ZAP)
- Safe Links
3. On endpoints, activate Network Protection in Microsoft Defender.
4. Ensure multi‑factor authentication: 2FA, FIDO2 keys, or biometric data.
5. Conduct regular phishing simulation training for employees.

Thus, Microsoft records a significant rise in QR‑phishing and other new tactics, while actively dismantling attacker infrastructure and recommending specific protective measures for corporate users.

Comments (0)

Share your thoughts — please be polite and stay on topic.

No comments yet. Leave a comment — share your opinion!

To leave a comment, please log in.

Log in to comment