feedzop-word-mark-logo
searchLogin
Feedzop
homeFor YouIndiaIndia
You
bookmarksYour BookmarkshashtagYour Topics
Trending
Terms of UsePrivacy PolicyAboutJobsPartner With Us

© 2026 Advergame Technologies Pvt. Ltd. ("ATPL"). Gamezop ® & Quizzop ® are registered trademarks of ATPL.

Gamezop is a plug-and-play gaming platform that any app or website can integrate to bring casual gaming for its users. Gamezop also operates Quizzop, a quizzing platform, that digital products can add as a trivia section.

Over 5,000 products from more than 70 countries have integrated Gamezop and Quizzop. These include Amazon, Samsung Internet, Snap, Tata Play, AccuWeather, Paytm, Gulf News, and Branch.

Games and trivia increase user engagement significantly within all kinds of apps and websites, besides opening a new stream of advertising revenue. Gamezop and Quizzop take 30 minutes to integrate and can be used for free: both by the products integrating them and end users

Increase ad revenue and engagement on your app / website with games, quizzes, astrology, and cricket content. Visit: business.gamezop.com

Property Code: 5571

Home / Technology / FBI: QR Codes Are New Cyber Threat Vector

FBI: QR Codes Are New Cyber Threat Vector

10 Jan

•

Summary

  • North Koreans exploit QR codes for phishing US government entities.
  • Attacks target Microsoft 365, Okta, and VPN credentials.
  • Unmanaged mobile devices bypass standard security defenses.
FBI: QR Codes Are New Cyber Threat Vector

The FBI has issued a critical warning regarding a new wave of sophisticated phishing attacks originating from North Korea. These "quishing" campaigns specifically target US government institutions, think tanks, and academic organizations, aiming to steal sensitive Microsoft 365, Okta, and VPN credentials. The threat actor, known as Kimsuky, uses email lures containing QR codes embedded in images, which are harder for traditional security systems to detect and block.

These attacks exploit a common vulnerability: the use of personal mobile devices for scanning QR codes. Since these unmanaged devices often fall outside corporate endpoint detection and network inspection boundaries, they become prime targets. After scanning, victims are directed through multiple redirects that gather identifying information before landing on fake credential-harvesting pages designed to mimic legitimate login portals.

The FBI emphasizes that these "quishing" attacks are highly effective and resilient against multi-factor authentication, often resulting in session token theft. This allows attackers to gain persistent access and even launch secondary attacks from compromised accounts. To combat this threat, the FBI recommends a multi-layered defense strategy, including enhanced employee training, clear reporting protocols for suspicious QR codes, and robust mobile device management solutions.

trending

Army vehicle plunges in Doda

trending

Nurses infected with Nipah virus

trending

IIFL shares plunge after tax

trending

SIDBI gets ₹5,000 cr boost

trending

FSSAI enforcement has limited impact

trending

AFCAT 1 admit card released

trending

India Post expands ATM network

trending

Delhi weather: Yellow alert issued

trending

Gold, silver prices fall

Disclaimer: This story has been auto-aggregated and auto-summarised by a computer program. This story has not been edited or created by the Feedzop team.
The FBI is warning about sophisticated "quishing" attacks where threat actors embed malicious QR codes in emails to steal user credentials for services like Microsoft 365 and Okta.
US government institutions, think tanks, and academic organizations are the primary targets of these advanced phishing campaigns.
The FBI advises a multi-layered defense including employee training, clear reporting protocols for suspicious QR codes, and mobile device management.

Read more news on

Technologyside-arrow

You may also like

Microsoft Tops 2025 Phishing List Again

20 Jan • 16 reads

article image

UK Eyes Phone Nudity Blocks for Kids

16 Dec, 2025 • 195 reads

article image

Roblox Blocked in Russia Over LGBTQ Content

4 Dec, 2025 • 227 reads

article image

New Android Malware Silences Phones, Drains Accounts

28 Nov, 2025 • 300 reads

article image

Apple Digital ID: Skip Airport Lines!

24 Nov, 2025 • 315 reads

article image