Logicalis warns of the rise of quishing, a threat capable of hiding malicious links and transferring the attack to the user’s mobile phone. The act of scanning the QR code on a restaurant menu, paying for parking or consulting tourist information has become an everyday gesture. But that familiarity is also being taken advantage of by cybercriminals.

QR code phishing, known as quishing

Phishing using QR codes, known as quishing, has become one of the fastest growing attack vectors. In fact, Microsoft detected 18.7 million attacks of this type in March 2026, compared to the 7.6 million registered in January, which represents an increase of 146% in just three months.

In this sense, Logicalis Spain and Áudea, its specialist cybersecurity unit, warn that the apparent simplicity of a QR code is precisely one of the advantages that attackers exploit.

The data reveals a relevant evolution for companies and users. During the first quarter of 2026, Microsoft identified around 8.3 billion phishing threats delivered via email and identified QR code phishing as the fastest growing attack vector during that period.

“Unlike what happens with a conventional link, the user cannot see at a glance the web address hidden behind the code and, in addition, the scanning is usually carried out from a mobile phone, moving the interaction outside the corporate computer and, in many cases, outside the main security controls of the organization” explains Andrés Cartes Guilarte, Cybersecurity Culture Consultant at Áudea.

In this way, the attacker incorporates a QR code and upon scanning it, the victim is taken to a fraudulent page that can imitate corporate services, banking platforms or authentication pages with the aim of obtaining credentials, personal data or financial information.

PDFs concentrated around 70% of QR attacks

According to Barracuda’s Email Threats Report 2026, 70% of the malicious PDFs analyzed contained QR codes leading to phishing pages, while this percentage reached 56% in malicious Microsoft 365 documents. In addition, PDFs accounted for around 70% of QR attacks recorded in March 2026, while codes inserted directly into the body of email messages increased by 336%. during that same month.

The risk is not limited to email. QR codes have been integrated into restaurants, shops, transportation, parking, events and tourist services, making it possible for a digital attack to start on a seemingly harmless physical element.

In fact, INCIBE alerted this past August 4, 2026 of a real case that occurred in Spain after a user scanned the QR code used by a restaurant to consult its menu. After accessing the link and accepting a pop-up window, an unsolicited premium subscription was activated. INCIBE also confirmed that other clients of the establishment had experienced similar situations.

75% of restaurants worldwide use QR codes

The high penetration of this technology expands the potential terrain for this type of fraud. Data collected by QR TIGER indicates that around 75% of restaurants worldwide already use QR codes to facilitate access to digital menus, while the use of this technology in marketing and advertising grew by 323% between 2021 and 2023.

“It is no longer enough to teach the user not to click on a suspicious link. Phishing is evolving towards formats that eliminate precisely that link from our sight. Security must accompany the user from the email to the identity and the device from which they finally access the service,” concludes Cartes.