TL;DR: 17% of all advanced attacks in its study used malicious QR codes, according to Abnormal AI, while its webinar argues that image processing and behavioral signals are needed because static link and attachment controls miss the threat hidden inside the image.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “How to Stop QR Code Phishing Attacks”.
By the numbers:
- 17% of all advanced attacks identified in an Abnormal study utilized malicious QR codes.
Key questions
Q: Why do QR code attacks bypass many legacy email controls?
A: They bypass many legacy controls because those controls are built around visible URLs, file attachments, or text-based indicators.
Q: How should security teams detect phishing before users click malicious links or decode QR codes?
A: Security teams should focus on pre-delivery signal analysis rather than link execution.
Practitioner guidance
- Expand inspection to QR-bearing messages Classify messages containing QR codes as high-risk visual payloads and send them through deeper analysis before delivery to end users.
- Decode images before trust decisions Add image parsing that extracts encoded destinations from QR codes, screenshots, and flyers so the security stack can evaluate the target URL or consent flow.
- Correlate sender behaviour with visual payloads Use behavioural signals to identify unusual sender patterns, repeated QR delivery, or mismatches between message context and encoded destinations.
Bottom line: QR code phishing is not just a user-awareness problem because it moves the malicious destination into an image layer that legacy filters often do not inspect well.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
QR code phishing creates a detection blind spot because the threat is embedded in the image layer, not the message layer. Legacy email controls were built around visible links, file reputation, and attachment inspection. When the actionable destination is hidden in a QR code, the control surface shifts and those assumptions no longer hold. Practitioners should treat visual payloads as first-class attack carriers, not cosmetic message elements.
A few things that frame the scale:
- Roughly 1 in 3 phishing payloads are delivered outside email, through channels such as social media, search ads and messaging apps.
A question worth separating out:
Q: Should organisations connect email security with identity controls for QR phishing?
A: Yes. QR phishing often leads into authentication, consent, or token-harvesting flows, so mailbox detection alone is insufficient. Organisations need downstream identity checks, stronger session monitoring, and response paths that assume a scan can become an account compromise event.
👉 Read our full editorial: QR code phishing is exposing a behavioral detection gap