Blog de WatchGuard

QR Code Attacks Surge 146% in Two Months

QR code phishing—or “quishing”—is on the rise and bypassing defenses. We analyze the risk and look at why endpoints are critical for detection.

One particularly concerning trend in the recent evolution of phishing is the rise of QR code-based attacks. It doesn't rely on new malware or sophisticated exploits. Instead, it takes advantage of something much simpler: the trust users place in QR codes every day. Over the last few months, QR codes have become one of the most popular tactics for steering users toward malicious sites on mobile devices or in browser environments, where the visibility of many security tools is very limited. 

The data confirms this is far from a passing trend. According to Microsoft Threat Intelligence, quishing campaigns skyrocketed from 7.6 million in January to 18.7 million in March 2026, a 146% increase in just two months. The most telling part isn't the number itself, but what it reveals about how threat actors are shifting tactics: attackers are finding QR codes to be an increasingly effective way to bypass traditional phishing defenses and reach users through trusted workflows. 

And for organizations hoping to protect their networks and data, this represents a growing challenge. How do we take steps to ensure our employees and users remain safe? 

Why Attackers Are Turning to QR Codes 

The growth of these campaigns reflects a clear shift in how phishing attacks are designed. While credential theft remains the primary objective, attackers are changing how they operate. Instead of relying on easily spotted warning signs, they aim to blend into the user's everyday routines on autopilot. 

QR codes are an especially effective target because they are a common part of our daily lives. We use them to access digital services, make payments, and complete authentication steps. Because they are so familiar, we rarely subject them to the same level of scrutiny as a link in an email.   

Aside from that, these campaigns typically follow a predictable playbook: 

  • Leverage familiar tools and formats to build trust.
  • Redirect users to convincing phishing sites. 
  • Harvest credentials or authentication tokens. 
  • Move the attack out of the email environment, where visibility is limited. 

For victims, the experience feels completely normal, even when the source is a phishing campaign. 

A Growing Challenge for Security Teams 

In these types of attacks, the QR code is just the entry point. The real risk emerges later, when the user interacts with the malicious site. 

For security teams, it is no longer enough to just flag suspicious messages, because critical activity occurs in environments where immediate context is much harder to obtain. 

And when credentials are compromised, threat actors can gain access to corporate applications, sensitive data, and internal services without needing complex malware.  

These teams, therefore, should no longer be asking how the attacker got in, but rather what happens after the user interacts with it. 

Why Visibility Has Become the New Phishing Battlefield 

This is why the endpoint remains one of the most critical layers in modern defense. When a QR-based attack succeeds, the device is usually the first place where signs that something is wrong appear. Consequently, as an attack progresses, visibility into what is happening on the device becomes paramount. 

Traditional endpoint protection, which focuses solely on prevention, is no longer enough. Organizations need modern endpoint security solutions that combine prevention, detection, and response with continuous visibility into endpoint activity. By analyzing behaviors, not just known indicators, they can identify suspicious activity, automatically correlate related events, and provide the context teams need to distinguish routine activity from a real attack. 

This delivers key capabilities such as: 

  • Faster detection of nefarious activity on a device. 
  • Deeper visibility into what happens after the initial interaction. 
  • Reduced noise through automated incident correlation. 
  • Rapid response to contain incidents before they spread. 

It’s also important to emphasize the critical role of threat hunting. As attackers get more effective at blending into seemingly legitimate activity, the ability to proactively hunt for indicators of compromise (IoCs) shifts from a nice-to-have to an absolute necessity. For smaller organizations that don’t have the internal resources to manage this, partnering with an MDR provider can help fill this gap. 

This visibility helps teams detect unauthorized access, lateral movement, and early IoCs much faster, shrinking the window between intrusion and response. 

One of the most interesting things about quishing incidents is that they show threat actors no longer need extraordinarily sophisticated techniques to succeed. They simply exploit everyday habits, capitalizing on the times we let our guard down. 

As a result, the needs shift to the ability to monitor what happens after the initial interaction. It is at that juncture, when activity looks legitimate, that the line is drawn between a routine event and the start of a security breach. 

Quishing demonstrates the new normal: attackers don't always need sophisticated malware to succeed. By exploiting trusted user behaviors, they can bypass traditional defenses and shift the attack to areas with limited visibility. That's why organizations must ensure they have strong endpoint protection in place. The ability to observe endpoint activity, correlate events, and respond quickly is increasingly what determines whether an attack remains an isolated incident or becomes a full-scale breach.