Despite Feeling Prepared for Image-Based Attacks, Most Organizations Have Been Compromised by Them

Stu Sjouwerman | Mar 14, 2024

QR Code PhishingWith QR-code phishing attacks on the rise, new data sheds light on just how unprepared organizations actually are in stopping and detecting these device-shifting attacks.

One of the challenges with attacks is that we rely on security solutions to look for indicators of malicious intent. Content within an email, where a link points to, and the insides of an attachment can indicate potential foul play.

But when it’s a malicious QR-code being sent to someone, there are two aspects of this kind of attack that throw off an organization’s ability to detect malice intent. First, email scanners don’t (currently) have the ability to follow a QR-code and see where it goes, and second, a QR-code changes devices mid-attack, making it impossible for security solutions to stay in control of the situation.

So, do organizations really have an ability to stop such attacks?  According to a new Osterman Research report, Fortifying the Organization Against Image-Based and QR Code Attacks, the answer is a resounding no.

According to the report, 70% of organizations believe they’re ready to detect and stop QR-code attacks, and yet only 5.5% were able to detect and block every image-based and QR-code phishing attack from reaching the inbox over the past 12 months. 

So nearly three-quarters are “ready” and 94.5% weren’t. The math doesn’t add up.

To combat this, the report points out that 80% of organizations are training users to spot such attacks to help minimize the likelihood they’ll engage with the QR-code. Here at KnowBe4, we know that not all security awareness training is created equal.

It’s one thing to implement “training” as a quarterly breakroom session for 30 minutes. It’s an entirely different thing to implement continual new-school security awareness training that includes phishing testing to ensure users are improving their sense of vigilance and reducing the potential risk they pose to the organization with the opening of each email.

QR-code phishing will only exist for as long as victims keep engaging with the codes. Teach your users not to the organization’s security will thank you.

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.