While email-based hackers and cybercriminals have many tools at their disposal in order to deceive users and harvest their credentials via phishing attacks, a new report from Microsoft stated that malicious QR codes were growing in popularity.
In a report titled ‘Email threat landscape: Q1 2026 trends and insights,’ by Microsoft Threat Intelligence and the Microsoft Defender Security Research Team, researchers outlined that between January and March, they detected around 8.3 billion email-based phishing threats.
The report noted that by the end of the quarter, the fastest-growing form of attack was QR code phishing, which more than doubled during the time.

“The most significant shift in Q1 2026 was the rapid escalation of QR code phishing, with attack volumes increasing from 7.6 million in January to 18.7 million in March, a 146% increase over the quarter,” stated Microsoft, adding that after a decline in January, there was a significant surge in both February and March.
QR code-based phishing works by inserting malicious URLs within the scannable designs, and sending them through the body of an email or via an attachment.
“By the end of the quarter, QR code phishing had reached its highest monthly volume in at least a year,” said the report.
Link-based email threats made up 78%, while malicious payloads made up 19% of attacks in January, though these figures changed throughout the quarter.
Other cyberattack strategies included CAPTCHA-gated phishing, where fake versions of tests meant to detect organic human behaviour were used as a decoy to hide the “transition to malicious content,” per the report.

“By forcing users to engage with the CAPTCHA before accessing the payload, threat actors reduce the likelihood of automated scanning tools identifying the threat and increase the chances of successful credential harvesting or malware delivery,” said the report.
CAPTCHA-gated phishing was enabled through HTML attachments, SVG files, PDF files, DOC/DOCX files, and email-embedded URLs, though hacker preferences for these formats fluctuated over the months.
In order to deceive users and lull them into a false sense of security, many such malicious emails made use of fake confidentiality disclaimers, similar to those found at the tail end of corporate emails.
In March, the U.S. FBI published an advisory that warned about ongoing phishing campaigns by cyber actors associated with the Russian Intelligence Services (RIS).





























