Microsoft's Q1 2026 Email Report Is the Source of the 146% Quishing Figure
The headline number, a 146% surge with 18.7 million in March, comes from Microsoft's Email threat landscape: Q1 2026 report, published April 30 by Microsoft Threat Intelligence and the Microsoft Defender Security Research Team. It is the most solid statistic in the story, but it measures attack volume in Microsoft's own email telemetry. It does not count victims, successful compromises, or losses, and it isn't a global census of QR fraud. Calling the 18.7 million figure "cases," as the QRCodePress piece does, overstates it.
The quarter did not rise in a straight line. Microsoft says volume first fell 35% in January, carrying over a downtrend from late 2025. It then grew 59% in February and another 55% in March, reaching its highest monthly level in at least a year. Microsoft also named QR-code phishing the fastest-growing attack vector in its email data by the end of the quarter. That is narrower than the QRCodePress claim that quishing is the fastest-growing scam format overall.
The wider context helps with scale. Microsoft detected about 8.3 billion email-based phishing threats in the quarter, and 78% of email threats were link-based. Against that total, 18.7 million QR attacks in one month is a small but fast-growing share. Credential theft is the main goal across these campaigns.
PDFs and Word Files Carry Most Malicious QR Codes
Microsoft's delivery breakdown is useful for mail administrators. PDF attachments carried most malicious QR codes throughout the quarter, rising from 65% of QR attacks in January to 70% in March. DOC and DOCX files grew in absolute volume every month, but their share fell from 31% to 24%.
Microsoft pointed to one late-quarter development: QR codes placed directly in the email body, with no attachment, jumped 336% in March. They were still only 5% of the total. Microsoft said the change is worth watching because it removes the need for an attachment.
The mechanism is the same in each case. The attacker puts the malicious URL inside an image, either in the body of the message or inside a document. That targets a weakness of text-based scanning engines, which look for URLs as text and can't read a link encoded as pixels. Microsoft says the aim is to send victims to phishing sites on unmanaged mobile devices.
Kaspersky's late-2025 data points the same way but measures a different population. The company said phishing emails with malicious QR-code links rose from 46,969 in August 2025 to 249,723 in November, more than fivefold. It added that the codes appeared in email bodies and, more often, in PDF attachments. The QRCodePress piece credits those August and November figures to Cofense, but Kaspersky's press release is where they come from. Kaspersky's counts and Microsoft's also shouldn't be added together or compared directly, because they come from different vendors, customer bases and detection methods.
Kimsuky's QR Campaigns Show the PC-to-Phone Handoff
The strongest reason Windows administrators should care comes from the FBI. On January 8, 2026, the bureau issued a FLASH alert titled "North Korean Kimsuky Actors Leverage Malicious QR Codes in Spearphishing Campaigns Targeting U.S. Entities." The FBI released it to alert NGOs, think tanks, academia, and other foreign policy experts with a nexus to North Korea of evolving tactics employed by the North Korean state-sponsored cyber threat group Kimsuky. As of 2025, Kimsuky actors have targeted think tanks, academic institutions, and both U.S. and foreign government entities with embedded malicious Quick Response (QR) codes in spearphishing campaigns.
The FBI's definition makes the enterprise problem clear. It describes quishing as a technique in which adversaries embed malicious URLs inside QR codes to force victims to pivot from their corporate endpoint to a mobile device, bypassing traditional email security controls. MITRE ATT&CK tracks it as technique T1660. A Windows laptop enrolled in Intune with Defender for Endpoint and a web proxy can do nothing about a URL the user opens on a personal iPhone over cellular data.
The lures were specific. BleepingComputer, summarizing the alert, reports that the attackers pretended to be foreign investors, embassy employees, think tank members, and conference organizers. In one documented case, in June 2025 Kimsuky actors sent a strategic advisory firm a spearphishing email inviting recipients to a non-existent conference. The email contained a QR code that directed the user to a registration landing page with a button to register, which took visitors to a fake Google account login page for credential harvesting.
The alert also covers what happens after the scan. According to the American Hospital Association's summary, after scanning the malicious code, victims are routed through attacker-controlled redirectors that collect device and identity information for harvesting and use in additional malicious actions. The FBI also warned, as quoted by The Hacker News, that "quishing operations frequently end with session token theft and replay, enabling attackers to bypass multi-factor authentication and hijack cloud identities without triggering typical 'MFA failed' alerts."
That passage needs precise reading. Scanning a code does not by itself compromise a phone or defeat MFA. The damage comes when the user signs in to a fake page that relays the session, and a stolen session token lets the attacker skip the MFA prompt the user already completed. This is why the FBI's recommendations include a specific requirement to require phishing-resistant MFA for all remote access and sensitive systems. The same thread runs through Microsoft's report, which describes the Tycoon2FA phishing-as-a-service platform as using adversary-in-the-middle techniques against MFA that isn't phishing-resistant.
The Kimsuky campaign is targeted espionage against a defined set of organizations. It doesn't show that consumer QR scams share a source, and the FBI doesn't say they do.
Parking Meters and Unsolicited Packages Are the Consumer Side
The QRCodePress piece also covers physical tampering, and here the government warnings are aimed at the public. The FTC has warned consumers that scammers have covered legitimate parking-meter QR codes with their own, sending people to fake payment sites built to take money or personal information. The FTC's advice is to check the decoded URL for misspellings or swapped letters, keep the phone's operating system and apps up to date, and use strong passwords and MFA. If someone has already entered credentials, the FTC says to change that password everywhere it was reused, check bank and card statements, and report the fraud.
A separate FBI public service announcement from July 31, 2025, covers unsolicited packages that contain a QR code. The bureau says scanning can lead to requests for personal or financial information, or to downloads of malicious software that steals data from the phone. It calls the tactic a variation of a "brushing scam," and it states plainly that the scheme is not as widespread as other fraud schemes. That caveat belongs next to any mention of package-based quishing.
The FBI's package advice lines up with the enterprise guidance. Be wary of packages with no sender information, be careful when granting phone permissions, and don't scan codes of unknown origin. If you think you're a target, the FBI suggests securing your online accounts and pulling a free credit report from Equifax, Experian or TransUnion.
Many Quishing Statistics in Circulation Can't Be Traced
The QRCodePress piece piles up figures that the primary records located for this story don't support. They include QR payloads going from 0.8% of phishing in 2021 to 10.8% in 2024, 73% of Americans scanning without checking, 39% of consumers able to spot a malicious code, average corporate losses above $1 million per incident, executives targeted 42 times more often than other staff, and training that improves detection by 87% in three months. The payment-volume totals and scanning-population estimates are also unverified.
Some of these may come from real datasets, but without the original methods and definitions they shouldn't guide a security budget or a training decision. The executive-targeting and loss figures in particular sound precise, and nothing here backs them up. The figure worth quoting in a board slide is Microsoft's 146% quarterly increase, described correctly as email attack volume in Microsoft's telemetry.
The piece's main argument is sound: the QR format is neutral, and the danger is the destination. The FBI's own definition supports that. The code carries a URL, and the attack is ordinary credential phishing. Where the piece goes wrong is its suggestion that a three-second pause is "all the protection most people need." For a consumer at a parking meter, checking the URL and paying through the operator's known app is a strong defense. For an organization, where the code is used deliberately to move the user off a managed endpoint, it isn't enough.
What this means for you
Mail administrators and identity teams should act now. Home users mainly need one habit. The evidence points to three gaps: QR codes hidden in PDF and Word attachments, sign-ins completed on unmanaged phones, and MFA methods that a relayed session can bypass.
For organizations, the FBI's layered approach is the template. The FBI recommends organizations adopt a multi-layered security strategy to address the unique risks posed by QR code-based spearphishing, including a way for users to report suspicious QR codes alongside phishing-resistant MFA. Microsoft's Q1 report comes with Defender detections and mitigation recommendations for customers of Defender for Office 365 and Defender for Endpoint. Detection coverage depends on licensing and configuration, so check what your tenant actually inspects rather than assuming image-based URLs are scanned. Awareness training should also say plainly that a QR code in a work email is a link to be verified before use.
For individuals, the habit is simple. Read the URL your camera app shows before you open it. Check whether a public code is a sticker placed over another one. If a code asks you to sign in, pay or download something, go to the service's known app or type its address yourself.
- In Microsoft's Q1 2026 telemetry, QR-code phishing rose from 7.6 million attacks in January to 18.7 million in March, a 146% increase in email attack volume rather than a count of victims.
- PDFs carried 70% of malicious QR codes in March, Word files 24%, and codes embedded directly in email bodies 5% after a 336% jump.
- The FBI's January 8, 2026 FLASH alert on Kimsuky shows QR codes being used to move targets from managed PCs to phones, where fake Microsoft 365, Okta, Google or VPN sign-in pages can harvest credentials and session tokens.
- Phishing-resistant MFA is the FBI's stated defense against session-token replay, which can get around conventional MFA prompts.
- The FTC's parking-meter warning and the FBI's brushing-package warning cover consumer scams, and the FBI calls the package version less widespread than other fraud.
- Figures such as "73% scan without checking," "$1 million per incident" and "42 times more executive targeting" had no traceable primary source and shouldn't drive policy.
The QR code will stay in parking meters, restaurant menus and boarding passes, and nothing in the record suggests abandoning it. It does make a phishing URL harder to see and moves it onto a device the security team doesn't control. Microsoft's own data shows attackers using that more each month. The next sign will be Microsoft's second-quarter email threat report, which will show whether the March peak and the jump in body-embedded codes kept going. Organizations that close the gap between the PC and the phone before then will be less exposed whatever that report shows.