1 in 9 phishing emails now uses QR codes; ConsentFix abuses Microsoft OAuth flow

TechNadu · x · 2026-09-30

ESET telemetry from H1 2026 shows 1 in 9 detected phishing emails used a QR code to steer victims past traditional mail filters.

More concerning is ConsentFix: it abuses a legitimate Microsoft sign-in flow to trick users into granting consent, obtaining OAuth codes that are exchanged for access and refresh tokens — full account access. Classic phishing red flags are getting easier to bypass.

Related event: ESET: QR Code Phishing Surges, Misusing Microsoft Login Flows(2 posts)→

Original post →

More from Safety

Safety channel →