BR100 Increased By (0.36%)
BR30 Decreased By (-0.13%)
KSE100 Increased By (0.22%)
KSE30 Increased By (0.37%)
AGHA 6.68 Increased By ▲ 0.01 (0.15%)
BECO 4.37 No Change ▼ 0.00 (0%)
BML 57.32 Increased By ▲ 0.88 (1.56%)
BOP 30.35 Increased By ▲ 0.01 (0.03%)
CNERGY 13.12 Increased By ▲ 0.03 (0.23%)
CSIL 5.41 Increased By ▲ 0.05 (0.93%)
FCCL 52.79 Increased By ▲ 0.41 (0.78%)
FFL 14.72 Decreased By ▼ -0.02 (-0.14%)
FNEL 1.12 No Change ▼ 0.00 (0%)
KEL 6.09 No Change ▼ 0.00 (0%)
KOSM 5.73 Increased By ▲ 0.77 (15.52%)
LOTCHEM 26.46 Decreased By ▼ -0.89 (-3.25%)
MLCF 93.16 Increased By ▲ 0.41 (0.44%)
NBP 164.66 Decreased By ▼ -0.32 (-0.19%)
NCPL 55.66 Increased By ▲ 0.02 (0.04%)
NPL 61.16 Decreased By ▼ -0.10 (-0.16%)
OGDC 316.73 Decreased By ▼ -1.03 (-0.32%)
PACE 9.87 Decreased By ▼ -0.06 (-0.6%)
PAEL 35.63 Increased By ▲ 0.13 (0.37%)
PIBTL 14.68 Increased By ▲ 0.11 (0.75%)
PPL 226.91 Decreased By ▼ -0.88 (-0.39%)
PRL 93.02 Increased By ▲ 0.45 (0.49%)
PTC 60.26 Decreased By ▼ -0.37 (-0.61%)
SSGC 23.81 Increased By ▲ 0.01 (0.04%)
TBL 8.75 Increased By ▲ 0.07 (0.81%)
TELE 7.80 Increased By ▲ 0.02 (0.26%)
TPL 22.35 Increased By ▲ 0.12 (0.54%)
TPLP 12.97 Increased By ▲ 0.30 (2.37%)
TREET 22.16 Decreased By ▼ -0.38 (-1.69%)
TRG 56.56 Decreased By ▼ -1.24 (-2.15%)

ISLAMABAD: A global cyber security company Monday cautioned Pakistani companies that malicious “QR codes” have evolved into one of the most effective phishing tools, resulting in data breaches, financial frauds and account takeovers/credential theft.

According to a new report of the cyber security company issued on Monday, Kaspersky reported a spike in phishing emails containing malicious QR codes. Detections for these jumped from 46,969 in August to 249,723 in November – a more than fivefold growth – as cyber criminals increasingly exploit QR codes.

Attackers use QR codes in emails more frequently because they provide a simple and cost-effective way to conceal malicious URLs, evading detection by many protective solutions.These QR codes are often embedded directly in email bodies or, even more commonly, within PDF attachments – an evolution that both masks phishing links and encourages users to scan them on mobile phones, which may have weaker security than work PCs.

Malicious QR codes commonly appear in mass phishing campaigns as well as targeted ones. Links embedded within them may lead to phishing forms impersonating login pages for services like Microsoft accounts or internal corporate portals, designed to steal usernames, passwords, and other credentials. Fake HR notifications urging employees to review or sign documents, such as vacation schedules, or even view lists of terminated staff, ultimately directing to credential-stealing sites. Fraudulent invoices or purchase confirmations in PDF attachments, often combined with vishing (voice phishing) tactics that prompt victims to call provided phone numbers to ‘cancel’ or clarify the transaction, enabling further social engineering attacks.

These tactics exploit trust in routine business communications, leading to credential theft, account takeovers, data breaches, and financial fraud, the report added.

Copyright Business Recorder, 2026

Comments

Comments are closed for this article.