The Hoxhunt Challenge revealed some worrying trends in phishing (using QR codes) and the ability of employees to spot the threat before it's too late (with simulated attacks). The results show that the human factor is crucial to the success or failure of a phishing attack.

The recent study, conducted across 38 organizations, across nine industries and 125 countries, revealed that 22% of phishing attacksin the first few weeks of this month used QR codes to deliver malicious payloads.
The Challenge categorized employee responses into three groups: success, failure, and click/scan. Only 36% of email successfully detected and reported the simulated attack. The rest did not, meaning most organizations are vulnerable to phishing threats. The retail industry had the highest failure rate, with only 2 in 10 employees responding correctly. In contrast, employees in legal and business services were better at detecting and reporting suspicious QR codes.
See also: Education: Increased attacks through phishing and exploitation of vulnerabilities
“QR codes are everywhere in our daily lives. We all love convenience, and QR codes are incredibly useful and convenient,” commented Timothy Morris, principal security consultant at Tanium. “Users should be extremely suspicious of QR codes that arrive via email.”
According to the Hoxhunt Challenge, an employee’s job title and role within a company played a role in their response to phishing QR codes. Communications staff were 1.6 times more likely to be involved in a attack . Conversely, employees with legal responsibilities were the most cautious.
Additionally, how involved one is in their work also plays a role. Engaged employees (those who feel passionate about their work) had a 40% failure rate, while those who are not as invested in their work and the organization they work for had a 90% failure rate.
See also: Gmail: Strengthens defenses against phishing and malware from 2024

Finally, employees who had received some information and trainingwere more effective at detecting phishing attacks.
All of the above shows that ongoing cybersecurity trainingis critical to protecting an organization. Failure to provide such training increases vulnerability to cyberthreats and puts the organization's data at risk.
“If your organization uses QR codes for authentication, it’s important to be aware of the types of attacks attackers are using and implement mitigation strategies,” says Georgia Weidman, security architect at Zimperium.
See also: AI-generated phishing emails are increasingly difficult to detect
Protection against phishing
The above shows that there is a great need to take some protective measures. Let's look at some of them:
- Use of email spam filters
- Protect devices with antivirus software and regular software updates
- Using a unique password for each of your online accounts.
- Multi-factor authentication application
- Backup
Ways to protect yourself specifically for businesses
- Informing staff about new threats and training with test phishing attacks.
- Monitoring and protection of endpoints.
- Restrict access to critical systems ( only those who absolutely need to have access to critical systems should have access)
- Network segmentation
Source: www.infosecurity-magazine.com
