The Evolution of Phishing: KHIPU Networks Announce QR Code Phishing Services

Written by KHIPU

  • News

KHIPU Networks, a leading provider of cyber security and network infrastructure solutions, today announced the expansion of its phishing assessment services with the addition of simulated ‘quishing’ assessments. This enhancement to their already successful phishing simulation services empowers organisations to comprehensively evaluate their susceptibility to both email phishing and QR code phishing attacks, ultimately strengthening their overall cybersecurity posture.

Phishing: An ever-present threat

Phishing attacks remain a prevalent threat for organisations of all types and sizes, with cybercriminals employing increasingly sophisticated techniques to steal sensitive information and credentials. The ability to recognise often-nuanced phishing scam variations is crucial to the development of effective strategies for both phishing detection and prevention. For businesses, arming staff members with enough knowledge of common phishing email characteristics and using this to implement robust security measures is essential.

Simulated Phishing Assessments: A proactive approach

KHIPU Networks’ phishing assessments have long been a valuable tool for organisations to simultaneously identify vulnerabilities in their email security and increase their staff and user awareness. A recent assessment showed that KHIPU’s simulated phishing teams had carried out over 500 bespoke Phishing-as-a-Service (PhaaS) campaigns, totalling in excess of 1.5 million emails. 

KHIPU uses simulated phishing attacks to assess how end-users react to phishing emails so that the right level of awareness training can be provided to educate them on cyber security and breach prevention (both personal and work related). These assessments simulate real-world phishing attempts, allowing organisations to measure employee response rates and identify areas for improvement in essential security training, also offered by KHIPU.

The Rise of ‘Quishing’ (QR Code Phishing) and the need for a multi-layered defence

QR code phishing, often referred to as “quishing,” is a form of socially engineered cyber-attack through which where cybercriminals use QR codes to deceive users into revealing sensitive information or to perform malicious actions.

Attackers may create QR codes that, when scanned by a smartphone or other device, redirect users to fraudulent websites or applications designed to steal login credentials, personal information, or financial data. This technique exploits the trust users place in QR codes, as they are commonly used for convenient access to websites, promotions, or other resources. To mitigate the risk of QR code phishing, users should verify the legitimacy of QR codes before scanning them, ensure they are from trusted sources, and be cautious of unexpected or unsolicited QR codes.

QR Code Phishing Simulation Services

With the growing prevalence of QR code phishing scams and attacks, KHIPU Networks recognised the need for a more comprehensive approach. Simulated ‘quishing’ assessments complement existing phishing assessments by mimicking malicious QR code phishing attacks.

What the services includes:

After each simulating ‘quishing’ campaign, which is conducted and managed by our dedicated cyber security team, a comprehensive prevention report is generated, outlining all findings which are discussed with you as part the assessment:

  • Infrastructure vulnerabilities across email setups (e.g. have DMARC, SPF, DKIM been correct implemented), gateway and firewall configuration and capability assessments.
  • Users who opened and were compromised – clicking URL’s and sharing information, opening attachments, scanning QR codes.
  • Endpoint inventories and risks including operating systems, versions, browsers, plug-ins and vulnerabilities / patching needed.
  • Wider portfolio of awareness campaigns showing who undertook them including videos watched and scores from quizzes.
  • Best practise recommendations for on-going prevention and protection against cyber-attack across all areas.
  • Reports will be reviewed by our team of cyber security experts and discussed with you as part of our strategic alignment, helping you understand all findings and look at ways to improve your cyber security posture.

Benefits of KHIPU Networks’ enhanced QR code and email phishing Assessments:

  • Comprehensive Evaluation: Identify vulnerabilities in both email and phone-based social engineering attempts.
  • Improved User Awareness: Train employees to recognise and resist phishing and ‘quishing’ attacks.
  • Reduced Risk of Compromise: Minimise the likelihood of successful social engineering attacks.
  • Enhanced Security Posture: Strengthen overall cybersecurity defences.

“Organisations can no longer afford to focus solely on email-based phishing attacks,” said Matt Ashman, CCO at KHIPU Networks. “By incorporating simulated phishing and ‘quishing’ simulation assessments, we provide our customers with a wider view of their security vulnerabilities allows us empower and educate them to create a more robust defence.”