




Quishing (QR-code phishing) is rising: QR code phishing attacks increased 25% year-over-year, even as basic QR phishing emails decline. Google and Microsoft warn quishing can bypass multi-factor authentication by sending victims to cloned sites after they scan QR codes, enabling attackers to capture credentials and session tokens. Microsoft Defender data shows QR-code campaigns growing from 10% to 30% of total phishing campaigns, underscoring an escalating cybersecurity risk.
This is more a budget reallocation signal than an earnings shock. QR-based social engineering tends to move security spend away from perimeter filtering and toward identity, mobile device management, browser/session protection, and employee training, which is a better fit for subscription security vendors than for point solutions tied to email-only detection.
The second-order winners are the platforms that can bundle MFA, conditional access, and endpoint telemetry into existing enterprise contracts. MSFT is better positioned than GOOGL because it can monetize security anxiety inside an installed base through Entra/Defender attach, while GOOGL is more exposed to trust and support-cost drag across consumer and cloud workflows. For OZK and peers, the immediate risk is not losses but nuisance fraud, call-center load, and slower digital adoption, which can quietly raise operating expense without showing up as a headline event.
Contrarian view: the market may overestimate how quickly this turns into incremental revenue. QR scams are a delivery mechanism, not a new category, so unless enterprises tighten controls or regulators force mobile/session-security upgrades, the spend lift could lag the media cycle by 1-2 quarters. The signal to fade is any plateau in attack frequency or a management tone that frames this as a training issue rather than a product upgrade cycle.
AI-powered research, real-time alerts, and portfolio analytics for institutional investors.
Request TrialOverall Sentiment
mildly negative
Sentiment Score
-0.35
Ticker Sentiment