TechNewsReel
Live

Cybercriminals Use Fake Breach Alerts and QR Codes to Bypass Security

Attackers are leveraging 'quishing' to trick anxious users into scanning malicious codes that steal sensitive data.

TechNewsReel Newsroom · September 11, 2026

Cybercriminals are deploying fraudulent data breach notifications to trick individuals into scanning malicious QR codes. This tactic, known as 'quishing,' leverages widespread anxiety surrounding identity theft to lure victims to phishing sites designed to steal sensitive information or install malware.

These fraudulent alerts claim a user's personal data has been compromised in a security breach. Once the victim scans the provided QR code, they are redirected to a malicious website. These campaigns have expanded beyond digital messages; the FBI and the U.S. Postal Inspection Service (USPIS) have warned that some fake breach alerts are being delivered via unsolicited physical packages containing QR codes.

The Rise of Quishing

The surge in these attacks coincides with a period of frequent, high-profile corporate data breaches, leaving the general public more susceptible to alerts regarding compromised data. Attackers choose QR codes because they provide a technical advantage over traditional phishing links.

Scammers use QR codes to make it more difficult for researchers and automated security software to analyze malicious links. Traditional email filters and security tools are generally more effective at detecting and blocking standard malicious URLs than they are at scanning the contents of a QR code, providing attackers with a stealthier vector for delivery.

Why the Tactic Works

This scam is particularly dangerous because it exploits a legitimate fear—the threat of identity theft—and pairs it with a technology that many users trust. Because QR codes are ubiquitous in restaurants and retail, many people scan them without verifying the destination URL or the identity of the sender.

By bypassing the initial security layer of the device or email provider, the attacker moves the interaction to a mobile browser where the user may be less likely to notice a fraudulent domain. This can lead to total account takeover, financial loss, or the installation of spyware on the victim's device.

What to Watch

Security experts advise users to be skeptical of any unsolicited notification regarding a data breach, especially those requesting a QR code scan to 'verify' an account or 'secure' data. Legitimate organizations typically provide official communication channels and do not rely on physical packages or QR codes to notify users of security incidents. Users are encouraged to navigate directly to a company's official website rather than following links or codes provided in unexpected messages.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.