Close Menu
The Financial News 247The Financial News 247
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
What's On

Why JPMorgan has given up predicting what the oil markets will do next

September 25, 2026

How Businesses Can Manage The Risks Of Quishing

September 25, 2026

Inside Kalshi CEO Tarek Mansour’s testy relationship with Indian casinos — and how it could pose an existential threat: ‘Lying little twerp’

September 25, 2026

New York sues Polymarket, accuses company of running illegal gambling operation

September 24, 2026

Starbucks to close another 250 stores after CEO axed hundreds of white-collar jobs

September 24, 2026
Facebook X (Twitter) Instagram
The Financial News 247The Financial News 247
Demo
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
The Financial News 247The Financial News 247
Home » How Businesses Can Manage The Risks Of Quishing

How Businesses Can Manage The Risks Of Quishing

By News RoomSeptember 25, 2026No Comments5 Mins Read
Facebook Twitter Pinterest LinkedIn WhatsApp Telegram Reddit Email Tumblr
Share
Facebook Twitter LinkedIn Pinterest Email

Benjamin Claeys is CEO of QR TIGER, MENU TIGER and GiftLips. He also hosts Stay QRious, a podcast about QR code best practices.

​The most dangerous QR code is not necessarily the one that fails to scan. It’s the one that scans perfectly and takes the user somewhere they were never meant to go.

​Microsoft’s Q1 2026 email threat report reveals that between January and March 2026, QR code phishing, or “quishing,” attack volume jumped from 7.6 million to 18.7 million, increasing by 146%. March, in particular, had the highest incident volume.

​These findings deserve special attention. It offers both a challenge and an opportunity to give users confidence that the QR code—and the destination behind it—can be trusted.

The Cost Of QR Code Phishing

The first quarter of 2026 saw a significant increase in the use of QR codes in email phishing attacks. According to Microsoft, cybercriminals commonly embed QR codes with malicious URLs directly in the body of emails or within attachments.

​Since the URL is encoded inside an image, it requires decoding before the destination can be evaluated. This can make QR-based attacks harder for some conventional text-based security systems to detect. The attack becomes even more dangerous as victims use their personal smartphones or apps, where organizational security controls may be less restrictive.

​While Microsoft’s data captures the attack on digital ecosystems, the quishing attacks happening in physical spaces are equally as troubling.

​Recent Action Fraud reports from April 2024 to April 2025 recorded 784 reports of quishing, with almost £3.5 million lost. These attacks have appeared in familiar settings, including parking meters, railway stations, restaurant menus and parcels.

​In 2022, the FBI received reports of QR code scams in cryptocurrency transactions. Some also deliver these scams through gift cards.

​But the cost of quishing is not limited to financial losses for both businesses and customers. It can also erode the trust customers place in the businesses and organizations that use QR codes.

​According to my company’s findings on consumers’ perception of QR codes, four in 10 users hesitate to scan QR codes due to security concerns. In particular, over 50% skip scanning when they receive them via email or messages.

​Even when the business itself is not responsible for a malicious QR code, a negative scanning experience can still affect how customers perceive the brand.

​This puts the business in the uncomfortable position of owning reputational risk for an attack surface they don’t fully control. And it’s a big reason governance can’t be optional.

Designing Security Into The QR Experience

In my conversation with Masahiro Hara, the inventor of the QR code himself, he acknowledged the security challenge now surrounding the technology and pointed to the importance of authentication.

​It leads us to a broader issue: QR code security doesn’t end with the code itself. It extends to the identity, destination and controls surrounding it. Quishing isn’t simply a problem of malicious QR codes. It’s a problem of trust across the QR code lifecycle.

​Establishing a governance process enables businesses and organizations to take control of the entire lifecycle of a QR code—from creation and authorization to deployment, destination management, monitoring and retirement.

​Ownership And Access

A QR code should never become a “set it and forget it” asset. Organizations need appropriate access controls and internal processes for managing destinations.

​They should know who created the QR code, who can edit its destination, where it has been published, what destination it currently leads to, when the destination was last changed and whether the destination is still active and legitimate.

​Infrastructure And Controls

Businesses should be selective about the platforms they use to generate and manage QR codes. Beyond marketing, a QR code generator is part of the digital infrastructure of organizations for running user authentication, payments, product information, digital product passports and other sensitive experiences.

​Security should be evaluated alongside customization, analytics, integrations and pricing. Look for providers that offer appropriate account protections, secure infrastructure, access controls, white labeling for destination URLs, monitoring and mechanisms to detect or respond to abuse.

​Context And Authenticity

Scanning a QR code is an intentional act. A person often finds a few signals before scanning one: a benefit or value, relevance to their context, the authority of the QR code’s source and the urgency to scan it.

​Cybercriminals feed on these signals well. They don’t merely put malicious URLs into QR codes. They create a reason for the victim to want to scan them through an email request to verify an account, resolve a payment issue, complete multifactor authentication, sign a document or access an important notification—actions that feel legitimate before the user ever sees the destination.

​Context and authenticity, in this case, should go beyond branding, like the logo, colors, surrounding copy and even the overall layout. A business’s QR code should always be accompanied by clear context, explaining why it’s there and what happens after scanning.

​The goal is not to make users blindly trust QR codes. It is to give people enough information to make an informed decision about whether the scanning experience makes sense.

A More Secure Future For QR Codes

The rapid growth of quishing can create an understandable reaction: If attackers are abusing QR codes, perhaps businesses should stop using them.

​That would miss the bigger lesson. QR codes are no more inherently malicious than URLs, email or NFC technology. They are data carriers. The security of the experience depends on what they point to, who controls that destination and whether users can establish that it is legitimate.

​The appropriate response is to build trust around their use. Businesses and organizations should respond by treating QR codes as part of their digital security surface. They may only occupy a small space on a sign or screen, but their impact can extend across the entire user and business experience.

​Convenience made QR codes ubiquitous. Trust will help keep them useful.​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Benjamin Claeys
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related News

Data Reconciliation, Trust And Context

September 24, 2026

Your AI Agent Has Agency, Treat It Like A Privileged Human

September 24, 2026

The Next Mandate For CIOs And CAIOs

September 24, 2026

Why To Keep Hiring Engineers Even When Your Code Is AI-Assisted

September 24, 2026

​Security Is The Quiet Investment That Makes Healthcare Innovation Credible

September 24, 2026

The EV Industry May Be Solving The Wrong Problem

September 24, 2026
Add A Comment
Leave A Reply Cancel Reply

Don't Miss

How Businesses Can Manage The Risks Of Quishing

Tech September 25, 2026

Benjamin Claeys is CEO of QR TIGER, MENU TIGER and GiftLips. He also hosts Stay…

Inside Kalshi CEO Tarek Mansour’s testy relationship with Indian casinos — and how it could pose an existential threat: ‘Lying little twerp’

September 25, 2026

New York sues Polymarket, accuses company of running illegal gambling operation

September 24, 2026

Starbucks to close another 250 stores after CEO axed hundreds of white-collar jobs

September 24, 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks

OpenAI reveals more rogue AI incidents — attempted hacks of government, education websites

September 24, 2026

Publix sued over Florida woman’s death blamed on E. coli-tainted blueberries

September 24, 2026

Iconic California steakhouse chain closes another store, only 2 remain

September 24, 2026

Data Reconciliation, Trust And Context

September 24, 2026
The Financial News 247
Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact us
© 2026 The Financial 247. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.