WordPress Under Attack, QR Phishing Explodes, 153M Licenses Leaked

by The Creator | Sep 3, 2026

Phishing attack response requires immediate action on multiple fronts. QR code phishing (quishing) has reached record levels, with hackers bypassing email security by embedding malicious links in QR codes that employees scan on personal phones, making detection harder than traditional email threats.

Today's cyber news brings critical updates for small business owners. A critical vulnerability in the Elementor Pro WordPress plugin is being actively exploited, allowing hackers to take complete control of websites. Immediate updates are essential.

QR code phishing attacks have reached record levels, with hackers using sophisticated techniques to bypass email security by embedding malicious links in QR codes. These 'quishing' attacks trick users into scanning codes with their phones, moving the threat from monitored work computers to personal devices.

In major breach news, 153 million driver's license scans have surfaced on the dark web, prompting an FBI investigation. This affects people across the US and Canada, highlighting serious identity theft risks. Thomson Reuters also disclosed a breach affecting court management software, exposing sensitive records.

Hackers are weaponizing ScreenConnect remote support software to spread malware across Windows systems in worm-like fashion.

Key actions: Update WordPress plugins immediately, train employees about QR code risks, review identity verification vendor security, and audit remote access tools.

How should SMBs handle phishing attack response now?

QR code phishing bypasses traditional email filters because the threat moves to personal devices outside your security perimeter. CISA and FBI alerts confirm quishing attacks are now weaponized at scale. Immediate actions: (1) Communicate to all staff that scanning unknown QR codes creates breach risk, especially from external messages. (2) Audit your email security vendor to confirm QR detection capabilities. (3) Review remote access tools like ScreenConnect for unauthorized use. (4) Test phishing response with a controlled drill to measure employee reaction time. Unlike traditional phishing, quishing targets human judgment rather than email systems, so training replaces technical solutions.

Key takeaways

  • QR code phishing bypasses email filters by moving the attack to personal phones, where users may not question malicious links.
  • WordPress sites running Elementor Pro face active exploits. Update plugins immediately to prevent site takeover and data access.
  • Train staff to treat unknown QR codes as phishing bait, even if they appear in legitimate-looking messages or documents.
  • Audit vendor security for remote access tools, identity verification services, and court management software that handle sensitive records.

Frequently asked questions

What makes QR code phishing harder to stop than email phishing?

QR codes move the threat from monitored work computers to personal phones where email filters don't apply. Employees are more likely to trust scanning a code than clicking an email link because the threat appears less obvious. Your security tools have no visibility into personal device behavior.

Do I need to replace my email security if QR phishing bypasses it?

No, but you need additional controls. Email security still blocks most threats. Add staff training on QR risks, enable multi-factor authentication to limit damage if credentials are stolen, and audit which vendors have access to sensitive data in case their security fails.

How should I respond if an employee scanned a malicious QR code?

Reset their passwords immediately, check their email for forwarding rules or suspicious activity, monitor their account for lateral movement, and notify your IT vendor or MSP. If the breach affects client data, notify those clients and relevant regulators per state requirements.

What should I look for in a phishing attack response plan?

Include clear escalation steps (who to call first), evidence preservation procedures, notification timelines for clients and regulators, and password reset protocols. Test the plan annually with a real scenario so staff knows their role when actual threats occur.

Sources

Keep reading