What happened
Cofense reported a phishing campaign running from May to August 2023 that used QR codes embedded in PNG and PDF attachments to steal Microsoft credentials. More than 1,000 malicious emails were observed, of which roughly 29 percent were directed at a single large US energy company, with the remainder spread across manufacturing, insurance, technology and financial services. The campaign grew sharply from May onward.
How the deception worked
Emails spoofed Microsoft security notifications and told recipients they had to update account security relating to two-factor or multifactor authentication. Rather than a clickable link, the message carried a QR code inside an image or PDF attachment, which defeated URL scanning in email gateways because the destination was encoded in pixels. Scanning the code moved the victim onto a personal mobile phone, typically outside corporate device management and web filtering, where a credential harvesting page imitating Microsoft sign-in captured the username and password. Attackers also used redirects through legitimate services such as Bing to further obscure the final destination.
AI involvement · No AI reported
No AI element reported.
The control that would have caught it· our reading, not a claim from the sources
Email security needs to decode QR images rather than only parse hyperlinks, and enrolling users in phishing-resistant authentication means a credential captured on an unmanaged phone is not enough to sign in.
Sources (3)
- Major Energy Company Targeted in Large QR Code CampaignCofense·cofense.comOpen ↗
- QR Code Phishing Campaign Targets Top US Energy CompanyDark Reading·darkreading.comOpen ↗
- Phishing campaign used QR codes to target large energy companyThe Record·therecord.mediaOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.