{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-qr-code-phishing-campaign-targets-a-major-us-energy-company-s-microsoft"},"incident":{"title":"QR code phishing campaign targets a major US energy company's Microsoft logins","date":"2023-08","date_precision":"month","victim_org":"Unnamed major US energy company (plus manufacturing, insurance, technology and financial targets)","sector":"Energy & Utilities","country":"United States","primary_vector":"QR Code Phishing","secondary_vectors":["Credential Phishing Portal","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Credential Theft","Attempt Blocked"],"loss_usd":null,"loss_note":"No loss figure; Cofense reported the campaign volume rather than confirmed compromises.","records_affected":null,"threat_actor":null,"summary":"Cofense reported a phishing campaign running from May to August 2023 that used QR codes embedded in PNG and PDF attachments to steal Microsoft credentials. More than 1,000 malicious emails were observed, of which roughly 29 percent were directed at a single large US energy company, with the remainder spread across manufacturing, insurance, technology and financial services. The campaign grew sharply from May onward.","how_it_worked":"Emails spoofed Microsoft security notifications and told recipients they had to update account security relating to two-factor or multifactor authentication. Rather than a clickable link, the message carried a QR code inside an image or PDF attachment, which defeated URL scanning in email gateways because the destination was encoded in pixels. Scanning the code moved the victim onto a personal mobile phone, typically outside corporate device management and web filtering, where a credential harvesting page imitating Microsoft sign-in captured the username and password. Attackers also used redirects through legitimate services such as Bing to further obscure the final destination.","lessons":"Email security needs to decode QR images rather than only parse hyperlinks, and enrolling users in phishing-resistant authentication means a credential captured on an unmanaged phone is not enough to sign in.","confidence":"Confirmed","sources":[{"title":"Major Energy Company Targeted in Large QR Code Campaign","url":"https://cofense.com/blog/major-energy-company-targeted-in-large-qr-code-campaign","publisher":"Cofense"},{"title":"QR Code Phishing Campaign Targets Top US Energy Company","url":"https://www.darkreading.com/cyberattacks-data-breaches/qr-code-phishing-campaign-targets-top-u-s-energy-company","publisher":"Dark Reading"},{"title":"Phishing campaign used QR codes to target large energy company","url":"https://therecord.media/phishing-campaign-used-qr-codes-to-target-energy-firm","publisher":"The Record"}],"entry_type":"campaign","slug":"2023-qr-code-phishing-campaign-targets-a-major-us-energy-company-s-microsoft","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-qr-code-phishing-campaign-targets-a-major-us-energy-company-s-microsoft"}}