A PDF lands in your account’s inbox. It looks routine – an invoice from a supplier you’ve worked with for months, formatted the way it always is, with a small QR code near the bottom pointing you to the payment portal. The accounts assistant scans it and, within thirty seconds, is filling in login details on a page that looks identical to your Microsoft 365 sign-in screen. Except it isn’t. It’s a credential harvester, and you won’t find out for another five days.
This is the shape of phishing now. According to Barracuda’s 2026 Email Threats Report, which analyzed more than 3.1 billion emails in January 2026, 70% of malicious PDFs and 56% of malicious Microsoft 365 documents now contain QR codes that lead to phishing sites. More than 10% of HTML attachments in the report’s dataset were malicious. This is called quishing, short for QR code phishing.
Quishing works because of what happens after the scan.
The desktop-to-mobile handoff
When a phishing link sits inside an email, your business email gateway gets a chance to look at it. If something looks off, the message is blocked or flagged.
A QR code skips all of that.
The image is just pixels to an email filter. Until a person scans it, the malicious URL never has to appear in any system that knows how to evaluate it. And when the scan happens, it almost always happens on a personal mobile phone. The phone is rarely covered by the same security stack as the desktop. The link opens, the redirect chain runs (often through three or four intermediate domains to disguise the destination), and the user lands on a near-perfect copy of a sign-in page they trust.
The FBI flagged this technique in a January 2026 cyber alert tied to the North Korean state-sponsored group Kimsuky, describing quishing as a method designed to “force victims to pivot from their corporate endpoint to a mobile device, bypassing traditional email security controls.” When state-sponsored actors are using a technique, it is already widely available to ordinary criminals. The phishing-as-a-service market makes sure of that. Barracuda’s research found that 90% of high-volume phishing campaigns now run on rented kits.
Why PDFs and Office files in particular
First, these are the most trusted file types in business communication. Nobody questions a PDF invoice or a Word document with company branding. Second, they give the attacker a frame. A QR code sitting inside what looks like a normal document layout, whether that’s a payment reminder, a shared file notification, or a multi-factor authentication setup guide, feels like a legitimate part of the workflow rather than something bolted on. The accompanying email can be short, often just one line asking the recipient to scan the code on their mobile device for security purposes, which deflects exactly the kind of suspicion a clickable link might raise.
What it costs when it works
The credentials harvested through quishing are stored, tested, and sometimes sold on. The first sign of compromise is often a quiet rule appearing in the user’s Outlook account that forwards a copy of every incoming message to an external address. Then the attacker watches. They learn the rhythm of the business, who pays whom, when invoices go out, and what the finance team’s sign-off chain looks like. Then, weeks later, a fraudulent invoice lands with the right tone, the right amount, the right contact details, and someone pays it.
That delay is the part that catches businesses off guard. By the time the loss is identified, the entry point is buried under weeks of normal-looking activity. It is one of the reasons we treat layered cybersecurity as a baseline rather than a premium add-on. A single control rarely catches this kind of patient, multi-stage attack.
What to look for, and what to do
The signs of a quishing email are subtle, and they reward people who slow down.
- A QR code appearing in a document where you would not normally expect one. Invoices, internal HR notices, IT messages about MFA, and shared file notifications are the most common suspects.
- An email body that is unusually short and pushes urgency.
- A request to scan with a personal phone rather than continue on the existing device.
- A sender address that looks right at first glance but does not match the supplier’s actual domain on closer inspection.
For your team, three practical rules cut most of the risk:
- Do not scan a QR code inside a document unless you requested it. If you didn’t request it, treat it the same way you would treat an unsolicited link.
- If a code claims to lead to a familiar login page, close it and go to the service directly through your browser or password manager. Genuine providers never need you to come in through an attachment.
- Report the email to IT before deleting it. The artifact matters; it helps identify whether the same campaign has reached others in the business.
Where this leaves you
Email security tools that were good enough in 2023 may not be catching this. Most of the older generation of filters were designed to evaluate links and attachments as text and code, not to read images. The vendors are catching up. QR-aware filtering and image-based URL extraction are now part of the more capable platforms, including the Barracuda stack we work with. But coverage is patchy, and most businesses we speak with don’t have a clear picture of what their current setup sees.
That is the question worth asking inside your own business this week – whether the layers you have can read a QR code embedded in a PDF, follow the redirect chain, and determine whether what is on the other end is safe.
If you are not sure, we can take a look. A short cybersecurity assessment will tell you what your current stack covers, where the gaps sit, and what a sensible next step looks like given the threats in circulation. Get in touch with KKworx to arrange a conversation.
Frequently Asked Questions
What is a scalable backup strategy?
A scalable backup strategy is a data protection approach designed to grow alongside your business. It includes automated backups, clearly defined recovery objectives, hybrid or cloud-first storage, and regular testing to confirm data is always restorable as your data volumes and infrastructure increase.
Why is business continuity planning important for growing SMBs?
Business continuity for growing SMBs goes beyond backup. It ensures your people, processes, and technology can continue operating during and after a disruption. Without a continuity plan, even a recoverable data loss event can result in significant downtime, financial impact, and reputational damage.
What are cloud-first backup solutions, and are they right for my business?
Cloud-first backup solutions store your data off-site in secure cloud environments, often in combination with local backup for faster recovery. They are particularly well-suited to businesses with remote teams, distributed offices, or growing reliance on platforms like Microsoft 365.
What does disaster recovery planning in Illinois look like with KKworx?
KKworx provides tailored disaster recovery planning for Illinois businesses, covering risk assessment, recovery objective setting, backup configuration, and ongoing testing. Plans are built around the specific needs of each client rather than a one-size-fits-all model.
How do KKworx data protection services support long-term business resilience?
KKworx combines backup, disaster recovery, and continuity planning into a cohesive service. Regular testing, infrastructure monitoring, and partner-backed solutions like Barracuda Data Protection mean your strategy stays effective as your business scales, rather than becoming outdated.

