Skip to content
R42 / Technology / 00202

Microsoft Detected 145 Million QR-Code Phishing Attacks in One Year

The 2026 report also highlights abuse of valid accounts and a shrinking gap between vulnerability discovery and weaponization.

05.10.26 Gabriel Silva 3 MIN
WhatsApp X Facebook LinkedIn Telegram Email

R42 / SUMMARY

Microsoft says Defender for Office 365 detected more than 145 million QR-code phishing attacks between July 2025 and June 2026. The figure reflects the company’s own telemetry rather than the entire market, but it reinforces that identities and credentials remain major entry points for intrusions.

KEY POINTS

  1. 01Defender for Office 365 detected more than 145 million QR-code phishing attacks over twelve months.
  2. 02The figures reflect Microsoft’s observed customer base and are not a global count of every attack.
  3. 03User execution and valid accounts together made up half of the initial access observed by one Microsoft team.
  4. 04Passkeys and other WebAuthn-based methods reduce reliance on codes that can be relayed to fraudulent pages.

Microsoft says it detected more than 145 million QR-code phishing attacks between July 2025 and June 2026. The figure appears in the Microsoft Digital Defense Report 2026 and comes from telemetry collected by Defender for Office 365.

The number shows the scale reached by so-called quishing, but it has an important boundary: it represents activity visible through Microsoft’s products, not every attack across the internet. The company says it processes more than 165 trillion security signals each day, a broad dataset that is still tied to its own services and customers.

QR codes move the attack to another device

In these campaigns, a code commonly appears in an email body or an attachment such as a PDF or office document. Scanning it moves the session from a computer to a phone, where the victim may encounter a counterfeit login page. That device shift can make the destination harder for email filters to inspect and can also reduce the user’s view of the complete web address.

The underlying goal remains familiar: steal credentials or persuade someone to perform an action. According to the report, between 89% and 95% of the email phishing attachments Microsoft observed led to a credential-theft attempt. The company also counted more than 46 million business contact impersonation attacks over twelve months.

Those figures do not mean QR codes have replaced other techniques. A more useful conclusion is that they have joined a larger collection of methods designed to exploit trust, identity and legitimate access. In Microsoft Defender Experts data, user execution accounted for 30% of observed initial access, while valid accounts represented another 20%.

Automation speeds attacks without removing human operators

The report connects part of this shift to increasing use of automation and artificial intelligence in reconnaissance, social engineering, vulnerability discovery and post-compromise activity. Microsoft says it has observed AI-orchestrated activity and demonstrated a 32-stage attack chain in a controlled environment. It also cautions that fully autonomous complex attacks are not yet the norm and that meaningful human direction remains common in real-world intrusions.

The speed gap is another central finding. Nearly 40,000 CVEs were published in the first half of 2026 alone, according to the company. Median time from a vulnerability’s discovery in the wild to weaponization has fallen below 24 hours, while enterprises may take 30 to 60 days to remediate critical external vulnerabilities.

Protection has to resist credential relay

The practical response is not to abandon QR codes, which have many legitimate uses, but to reduce the value of a stolen password. NIST’s digital identity standard distinguishes ordinary two-step verification from authentication that is genuinely phishing-resistant. Manually entered one-time codes can be captured and relayed by a fraudulent page, so NIST does not put them in the resistant category.

WebAuthn- and FIDO2-based methods, including compatible passkeys and physical security keys, cryptographically bind authentication to the correct domain. That prevents a credential created for one service from being accepted by an impostor site. For organizations, Microsoft also recommends least privilege, reviews of persistent access, protection for both human and agent identities, and priority remediation for internet-facing systems.

For individuals, the main behavioral change is to treat a QR code like any other link: confirm who sent it, inspect the destination domain before signing in, and avoid supplying a password or temporary code after an unexpected request. Microsoft’s figure does not make every QR code dangerous, but it shows that the format is now part of phishing’s everyday infrastructure.

Written by

Gabriel Silva

Responsible for reporting and writing this story at Rota42.

R42 / FAQ

How many QR-code phishing attacks did Microsoft detect?

Microsoft says Defender for Office 365 detected more than 145 million between July 2025 and June 2026.

Does that number represent every attack worldwide?

No. The count covers events observed through Microsoft products and services. It shows scale and direction within that dataset, not a worldwide census.

How does QR-code phishing work?

The code sends a victim to a fraudulent page, usually opened on a phone, to capture a password, session or other data. Moving to another device and using visual content can complicate traditional email inspection.

Does two-factor authentication stop this attack?

It depends on the method. Manually entered codes can still be stolen and relayed. NIST considers properly configured domain-bound cryptographic methods such as WebAuthn and FIDO2 phishing-resistant.

Does the report say fully autonomous attacks are already common?

No. Microsoft reports more automation and artificial intelligence across parts of the attack chain, but says complex real-world intrusions still tend to involve meaningful human direction.

Continue reading

View archive

We use necessary storage for operation and security. With your permission, we enable audience measurement, personalization and optional advertising features.

Necessary Always active for security, session, language, theme and recording your choice. Analytics Allows audience, navigation and performance measurement to improve content and experience. Personalization Allows content, preferences and experiences to be adapted based on your choices. Marketing Allows advertising storage, ad personalization and full measurement.

Install Rota42

On iPhone or iPad, open Rota42 in Safari and follow these steps:

  1. Tap Share in the Safari menu.
  2. Choose “Add to Home Screen”.
  3. Enable “Open as Web App”, then tap Add.