Avatier

Phished or stolen credentials

Quishing

Also called: QR code phishing

Quishing is phishing that hides a malicious link inside a QR code. The code arrives in an email, document, flyer or sticker, and scanning it opens a fake login or payment page on the victim's phone. Because the link is an image, it can slip past email filters that inspect written URLs.

How it works

The attacker embeds a QR code in a message that asks the target to scan it to view a document, verify an account or join a meeting. Scanning moves the victim from a managed work computer to a personal phone, where security controls are often weaker and the full web address is harder to check before typing a password.

A real example

In a January 2026 FLASH, the FBI said North Korean Kimsuky actors had targeted think tanks, academic institutions, and US and foreign government entities with malicious QR codes embedded in spearphishing campaigns.

Source: North Korean Kimsuky Actors Leverage Malicious QR Codes in Spearphishing Campaigns Targeting U.S. Entities (AC-000001-MW) — Federal Bureau of Investigation (FBI), 2026-01-08

The Identity Attack Ledger holds 31 cited incidents for phished or stolen credentials in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.

How to stop it

Phishing-resistant MFA bound to the real site's domain keeps a phone-captured password from working. Apply the same sign-in policies to mobile devices as to managed laptops.

Related terms

Sources

  1. North Korean Kimsuky Actors Leverage Malicious QR Codes in Spearphishing Campaigns Targeting U.S. Entities (AC-000001-MW) — Federal Bureau of Investigation (FBI), 2026-01-08

Last reviewed Oct 2, 2026