feedzop-word-mark-logo
searchLogin
Feedzop
homeFor YouIndiaIndia
You
bookmarksYour BookmarkshashtagYour Topics
Trending
Terms of UsePrivacy PolicyAboutJobsPartner With Us

© 2026 Advergame Technologies Pvt. Ltd. ("ATPL"). Gamezop ® & Quizzop ® are registered trademarks of ATPL.

Gamezop is a plug-and-play gaming platform that any app or website can integrate to bring casual gaming for its users. Gamezop also operates Quizzop, a quizzing platform, that digital products can add as a trivia section.

Over 5,000 products from more than 70 countries have integrated Gamezop and Quizzop. These include Amazon, Samsung Internet, Snap, Tata Play, AccuWeather, Paytm, Gulf News, and Branch.

Games and trivia increase user engagement significantly within all kinds of apps and websites, besides opening a new stream of advertising revenue. Gamezop and Quizzop take 30 minutes to integrate and can be used for free: both by the products integrating them and end users

Increase ad revenue and engagement on your app / website with games, quizzes, astrology, and cricket content. Visit: business.gamezop.com

Property Code: 5571

Home / Technology / FBI: QR Codes Are New Cyber Threat Vector

FBI: QR Codes Are New Cyber Threat Vector

10 Jan

•

Summary

  • North Koreans exploit QR codes for phishing US government entities.
  • Attacks target Microsoft 365, Okta, and VPN credentials.
  • Unmanaged mobile devices bypass standard security defenses.
FBI: QR Codes Are New Cyber Threat Vector

The FBI has issued a critical warning regarding a new wave of sophisticated phishing attacks originating from North Korea. These "quishing" campaigns specifically target US government institutions, think tanks, and academic organizations, aiming to steal sensitive Microsoft 365, Okta, and VPN credentials. The threat actor, known as Kimsuky, uses email lures containing QR codes embedded in images, which are harder for traditional security systems to detect and block.

These attacks exploit a common vulnerability: the use of personal mobile devices for scanning QR codes. Since these unmanaged devices often fall outside corporate endpoint detection and network inspection boundaries, they become prime targets. After scanning, victims are directed through multiple redirects that gather identifying information before landing on fake credential-harvesting pages designed to mimic legitimate login portals.

The FBI emphasizes that these "quishing" attacks are highly effective and resilient against multi-factor authentication, often resulting in session token theft. This allows attackers to gain persistent access and even launch secondary attacks from compromised accounts. To combat this threat, the FBI recommends a multi-layered defense strategy, including enhanced employee training, clear reporting protocols for suspicious QR codes, and robust mobile device management solutions.

trending

Harmanpreet Kaur stars in WPL

trending

Mumbai Indians vs Delhi Capitals

trending

Du Plessis, James Vince shine

trending

Nigeria beats Algeria in AFCON

trending

Spurs lose to Aston Villa

trending

Newcastle faces Bournemouth in FA

trending

Leverkusen favored against Stuttgart

trending

Barcelona focuses on Real Madrid

trending

DMart Q3 profit jumps

Disclaimer: This story has been auto-aggregated and auto-summarised by a computer program. This story has not been edited or created by the Feedzop team.
The FBI is warning about sophisticated "quishing" attacks where threat actors embed malicious QR codes in emails to steal user credentials for services like Microsoft 365 and Okta.
US government institutions, think tanks, and academic organizations are the primary targets of these advanced phishing campaigns.
The FBI advises a multi-layered defense including employee training, clear reporting protocols for suspicious QR codes, and mobile device management.

Read more news on

Technologyside-arrow

You may also like

UK Eyes Phone Nudity Blocks for Kids

16 Dec, 2025 • 137 reads

article image

Australia Bans Social Media for Under 16s

9 Dec, 2025 • 186 reads

article image

Roblox Blocked in Russia Over LGBTQ Content

4 Dec, 2025 • 159 reads

article image

New Android Malware Silences Phones, Drains Accounts

28 Nov, 2025 • 245 reads

article image

Apple Digital ID: Skip Airport Lines!

24 Nov, 2025 • 255 reads

article image