ZDNET58%

Is that QR code a trap? How to spot quishing scams before it's too late 59%

By Charlie Osborne45%

7/13/2026, 11:01:43 AM

BS Summary: This article contains 26 faulty reasoning types, including Biased Writer Voice, Availability Heuristic, and Appeal to Authority, with Negativity Bias as the most egregious example at 37.1% saturation with 318 hits. Analysis detected 2,150 faulty-reasoning hits from 856 analyzed words, generating a BS Score of 55% and a BS Rank of 59% (9,156 of 21,887 articles). This article is worse (more manipulative) than 58.20% of the article peer group.

ZDNET's key takeaways 
The QR code in your email or attachment could be a scam. 
QR code phishing bypasses MFA, leading to data theft. 
How quishing attacks work, and what you can do to stay safe. 
Ever had a QR code land in your inbox and curiosity get the better of you? 
When we think of phishing and scams, many of the oldest tricks are those we still encounter daily -- emails claiming we have long-lost relatives who've left us an inheritance; 'Facebook' warning that our accounts will be frozen unless we reply promptly; fake lottery wins; and unwanted solicitations from so-called investors willing to transfer us millions of dollars. 
Also: Mobile phishing is a bigger threat than email nowHowever, times are changing. 
Recruitment scams are becoming sophisticated enough to convince job seekers to engage; AI is being used to humanize and improve phishing attempts and even automate entire attack chains; and now, an attack vector is emerging that weaponizes QR codes to bypass multi-factor authentication (MFA), steal our data, and hijack our accounts. 
Quishing: QR fraud on the rise 
Quishing, or QR code-based phishing, embeds malicious links in QR codes to bypass traditional phishing filters and slip through security nets. 
The lure is the same: create a sense of urgency, appeal to our greed, instill fear and panic, or promise rewards for scanning the QR code with our phones and clicking the embedded link to visit an online page or platform. 
Also: Microsoft goes all in on new AI-powered Windows security strategy 
A QR code phishing scheme can take many forms. 
A fake message from your bank, an email congratulating you on a lottery win, or an urgent message from your social media provider. 
Once you've scanned the code and clicked the link, you could end up in a domain designed to steal your data or compromise an account you own. 
According to Hoxhunt's 2026 Phishing Trends Report, basic QR-code phishing messages via email are on the decline, but they are re-emerging as an attack vector hidden in scam email attachments, such as in malicious PDFs. 
Overall, QR code phishing attacks increased by 25% year-over-year. 
It's not just digital spaces, either, as QR codes have also been spotted in physical spaces, embedded in posters or emblazoned on fake business cards, according to the report. 
How attackers dodge MFA defenses 
Hothunt's research is supported by a June notice from Google's Trust & Safety team warning that traditional email attack vectors are being replaced by adversary-in-the-middle (AITM) and quishing attacks. 
Quishing pairs with AITM by disguising malicious links in a format that's hard to read or detect by security filters. 
According to both Google and Microsoft, this is how it works: You receive a quishing email, and curiosity lures you into scanning the code. 
You are then sent to a cloned website that appears to be the domain of a trusted service, such as a bank, financial services provider, or even a work platform. 
Also: How to make a QR code for free 
You then submit your credentials, allowing the attacker to bypass existing multi-factor authentication (MFA) protections because you believe you are logging into a trusted website. 
They can then capture your password and session token, leading to data theft, account compromise, and more. 
What makes this tactic more dangerous than traditional phishing, especially for businesses, is that victims use their handsets to scan a QR code, bypassing network-based security and safety nets, such as phishing detection. 
The Microsoft Defender team has observed QR code-based cybercriminal campaigns growing from 10% to 30% of total phishing campaigns in recent months. 
How to avoid falling for QR-code phishing 
As QR codes hide destinations, links, and content in an image-like format, we can't see what is in them or verify their origins easily -- which is why blindly scanning and following a QR code is risky. 
QR codes, especially those you aren't expecting, should be treated with the same suspicion as emailed links or attachments. 
Just because the format is different, the phishing angle remains the same: to coerce or exploit a victim's curiosity and lure them into clicking and visiting a malicious online resource. 
The only difference here is the delivery mechanism -- instead of a straightforward link or file, a victim uses a camera to scan. 
Also: The best malware removal software: Expert tested and reviewed 
The best advice here is to stay cautious. 
If you receive an email containing a QR code that appears to be from your bank, visit your bank's official website in a separate tab or open your bank's mobile app. 
Even if a message seems legitimate, for safety and security, you should not click links, open attachments, or scan QR codes unless you are completely sure the source is legitimate and the message's contents are safe. 
Keep in mind, too, that QR code threats aren't limited to emails. 
See that QR code sticker slapped on a lamp post near your favorite store? 
Even physical QR code stickers can harbor a serious threat to your privacy and security. 
Article reasoning-pattern comparisonThis article: 9.3%Charlie Osborne: 1.9%ZDNET: 2.9%Confirmation Bias9.3%This article: 0.0%Charlie Osborne: 0.6%ZDNET: 1.7%Anchoring Bias0.0%This article: 20.7%Charlie Osborne: 5.9%ZDNET: 3.1%Availability Heuristic20.7%This article: 6.2%Charlie Osborne: 1.1%ZDNET: 1.0%Representativeness Heuristic6.2%This article: 0.0%Charlie Osborne: 0.2%ZDNET: 0.5%Hindsight Bias0.0%This article: 2.0%Charlie Osborne: 1.1%ZDNET: 3.2%Overconfidence Bias2.0%This article: 10.2%Charlie Osborne: 3.9%ZDNET: 4.2%Framing Effect10.2%This article: 0.0%Charlie Osborne: 3.8%ZDNET: 1.4%Loss Aversion0.0%This article: 3.7%Charlie Osborne: 1.5%ZDNET: 0.7%Status Quo Bias3.7%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.2%Sunk Cost Effect0.0%This article: 0.8%Charlie Osborne: 1.9%ZDNET: 5.2%Optimism Bias0.8%This article: 13.9%Charlie Osborne: 3.3%ZDNET: 1.3%Pessimism Bias13.9%This article: 37.1%Charlie Osborne: 8.4%ZDNET: 4.5%Negativity Bias37.1%This article: 0.0%Charlie Osborne: 0.3%ZDNET: 1.6%Self-Serving Bias0.0%This article: 2.9%Charlie Osborne: 0.7%ZDNET: 0.3%Fundamental Attribution Error2.9%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Actor-Observer Bias0.0%This article: 0.0%Charlie Osborne: 0.3%ZDNET: 0.5%In-Group Bias0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.2%Out-Group Homogeneity Bias0.0%This article: 2.5%Charlie Osborne: 2.0%ZDNET: 3.9%Halo Effect2.5%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.2%Horn Effect0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Dunning-Kruger Effect0.0%This article: 13.3%Charlie Osborne: 2.4%ZDNET: 1.5%Recency Bias13.3%This article: 0.0%Charlie Osborne: 0.4%ZDNET: 0.4%Primacy Effect0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Blind-Spot Bias0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Ad Hominem0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Straw Man0.0%This article: 17.4%Charlie Osborne: 4.4%ZDNET: 4.7%Appeal to Authority17.4%This article: 3.9%Charlie Osborne: 0.9%ZDNET: 1.5%False Dilemma3.9%This article: 6.0%Charlie Osborne: 1.8%ZDNET: 0.6%Slippery Slope6.0%This article: 4.3%Charlie Osborne: 0.3%ZDNET: 0.2%Circular Reasoning4.3%This article: 6.8%Charlie Osborne: 3.5%ZDNET: 6.5%Hasty Generalization6.8%This article: 0.0%Charlie Osborne: 0.6%ZDNET: 0.5%Red Herring0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.5%Bandwagon0.0%This article: 9.6%Charlie Osborne: 4.1%ZDNET: 2.0%Appeal to Emotion9.6%This article: 0.0%Charlie Osborne: 0.1%ZDNET: 0.7%Begging the Question0.0%This article: 0.0%Charlie Osborne: 1.0%ZDNET: 1.5%Post Hoc (False Cause)0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Tu Quoque0.0%This article: 4.2%Charlie Osborne: 0.6%ZDNET: 0.2%Burden of Proof4.2%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Appeal to Nature0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.3%Composition/Division0.0%This article: 13.0%Charlie Osborne: 1.7%ZDNET: 4.9%Anecdotal13.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%No True Scotsman0.0%This article: 5.0%Charlie Osborne: 2.1%ZDNET: 2.5%Ambiguity (Equivocation)5.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Gambler’s Fallacy0.0%This article: 2.2%Charlie Osborne: 0.2%ZDNET: 0.2%Middle Ground2.2%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Personal Incredulity0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.2%Special Pleading0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Genetic Fallacy0.0%This article: 13.8%Charlie Osborne: 2.4%ZDNET: 0.9%Unattributed Quote13.8%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.5%Quote-first Misdirection0.0%This article: 25.7%Charlie Osborne: 3.0%ZDNET: 6.8%Biased Writer Voice25.7%This article: 13.4%Charlie Osborne: 11.1%ZDNET: 3.9%Indoctrination13.4%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Politically Right Leaning Bias0.0%This article: 3.3%Charlie Osborne: 1.9%ZDNET: 7.5%Attempt to Sell a Product or S…3.3%

856 words analyzed.

Speakers

2speakers6.7%attributed speech799writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 6 words • 100.0% coverageWriter's voice • 9 words • 100.0% coverageWriter's voice • 3 words • 0.0% coverageWriter's voice • 12 words • 100.0% coverageWriter's voice • 9 words • 100.0% coverageWriter's voice • 12 words • 100.0% coverageWriter's voice • 16 words • 100.0% coverageWriter's voice • 58 words • 0.0% coverageWriter's voice • 13 words • 100.0% coverageWriter's voice • 51 words • 100.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 41 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageWriter's voice • 27 words • 0.0% coverageHoxhunt • 35 words • 100.0% coverageWriter's voice • 9 words • 100.0% coverageWriter's voice • 29 words • 100.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 29 words • 100.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 30 words • 0.0% coverageWriter's voice • 9 words • 100.0% coverageWriter's voice • 25 words • 100.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 33 words • 100.0% coverageMicrosoft Defender team • 22 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 37 words • 100.0% coverageWriter's voice • 19 words • 100.0% coverageWriter's voice • 30 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageWriter's voice • 10 words • 100.0% coverageWriter's voice • 8 words • 100.0% coverageWriter's voice • 31 words • 100.0% coverageWriter's voice • 36 words • 100.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 14 words • 100.0% coverageWriter's voice • 15 words • 0.0% coverage
Selected voice

Hoxhunt

100%flagged-word coverage
35 attributed words61% of attributed speech100% writer coverage
0%50.0%100.0%Unattributed Quote+89.6 ptsWriter: 10.4%Hoxhunt: 100.0%100.0%Biased Writer Voice-27.5 ptsWriter: 27.5%Hoxhunt: 0.0%0.0%Indoctrination-14.4 ptsWriter: 14.4%Hoxhunt: 0.0%0.0%Attempt to Sell a Product -3.5 ptsWriter: 3.5%Hoxhunt: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.