Skip to content

Compliance Building

Doug Cornelius on compliance for private equity real estate

Menu
  • Home
  • About
    • About
    • About Doug
    • About This Website
    • Why I Blog
    • Speaking Engagements
    • Contact
    • Publications
  • Archives
    • Topic Archive
    • Book Reviews
    • Most Popular
  • Subscribe
  • Disclaimers
    • Disclaimers
    • Policies and Procedures
    • Use of Site Content
    • Comments
    • FTC Disclosure
Menu

Quishing Attacks

Posted on June 26, 2024 by Doug Cornelius
Print Friendly, PDF & Email

This is a new term to me.

Quishing:

a business email compromise (BEC) attack that uses QR codes in embedded PDF documents to redirect victims to phishing URLs.

 There is a Phishing-as-a-Service (PhaaS) platform called ONNX Store, which apparently has a user-friendly interface to enable the orchestration of phishing attacks. Good to know there are services making it easy to launch cyber attacks.

This new approach uses QR codes embedded in PDF documents to direct victims to the bad URL. I think we are all getting better at spotting bad links and avoiding them. QR codes input the URL without you getting a good look at it. At interesting vulnerability. Plus you are likely using a mobile device to scan the QR code and redirect to the website. Most mobile devices are personal don’t have the robust enterprise protections of the office device.

This new Quishing Attack takes you to a face Microsoft 365 login page and has some hacks to get around two-factor authentication.

The Quishing attacks were first targeted at financial institutions. This must have included broker-dealers because FINRA published an alert.

Sources:

  • FINRA Cyber Alert – ONNX Store Purportedly Targeting Firms in Quishing Attacks
  • ONNX Store: Phishing-as-a-Service Platform Targeting Financial Institution
  • Quishing – US Postal Inspector Service
  • What Is Quishing?

Share this:

  • Print (Opens in new window) Print
  • Share on Facebook (Opens in new window) Facebook
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on X (Opens in new window) X
  • Email a link to a friend (Opens in new window) Email

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Search for Stuff

Recent Stories

  • The Performance of the SEC in 2025
  • More on the Downsizing of the SEC
  • SEC Enforcement Results for FY 2025
  • Proposed Fundamental Reforms to AML Programs
  • Is It a Truck or a Security?
  • The One with Low IQ from Pet IQ
  • The Downsizing of the SEC
  • When “Today” Is Not all of “Today”
  • Compliance Bricks and Mortar for March 27
  • The One Where Theory Meets Reality

Fight Cancer

Please support my Pan-Mass Challenge
Make a donation to fight cancer. donate.pmc.org/DC0176
pan-mass challenge badge

I am a lawyer, but I am not your lawyer. Since I’m a lawyer, this website may be considered attorney advertising under the ethical rules of certain jurisdictions. Please read my disclaimers page before taking any action. And then, don't take any action based on what I wrote.

Creative Commons logo with the text 'Some Rights Reserved' and three symbols representing attribution, non-commercial use, and share alike.

Compliance Building - by Doug Cornelius is licensed under a Creative Commons Attribution-Noncommercial 3.0 United States License.