KSeF Phishing and QR Quishing: How to Recognise Fake Invoice Notifications
Phishing impersonating KSeF appeared four days after launch. CERT Polska issued alert 48/2026. Fake notifications deliver malware. QR quishing targets invoice visualisations. Here are the red flags.
KSeF Phishing and QR Quishing: How to Recognise Fake Invoice Notifications
CERT Polska recorded 260,783 cybersecurity incidents in 2025, a 152% year-on-year increase. Four days after KSeF's mandatory launch on 1 February 2026, the first phishing wave impersonating KSeF appeared. CERT Polska issued alert 48/2026 on 17 April 2026, covering fake "new invoice in KSeF" email notifications that deliver malware.
The Phishing Patterns
Pattern 1: Fake KSeF notification email
The email appears to come from KSeF or the Ministry of Finance. It claims a new invoice is waiting in your KSeF inbox. It contains a link to a fake login page that harvests credentials, or an attachment that installs malware.
Red flags:
- The sender domain is not
ksef.podatki.gov.plorpodatki.gov.pl - The link URL does not start with
https://ksef.podatki.gov.pl/orhttps://aplikacja-podatnika.mf.gov.pl/ - The email asks you to log in via a link (KSeF does not send login links by email)
- The email contains an attachment (KSeF does not send invoices as email attachments)
- The email uses urgency language ("act now", "invoice expires")
Pattern 2: QR quishing on invoice visualisations
The fraudster takes a legitimate KSeF invoice PDF visualisation and replaces the QR code with a malicious one. When the recipient scans the QR code with their phone, it opens a phishing site or downloads malware.
Red flags:
- The QR code URL does not match
ksef.podatki.gov.pl - Scanning the QR code opens a page asking for login credentials
- The QR code looks different from previous invoices from the same supplier (different size, position, or style)
- The PDF was received by email, not through KSeF
Pattern 3: Fake "new bank details" using KSeF authority
The fraudster sends an email claiming to be from a known supplier, referencing a recent KSeF invoice number (which they may have obtained from a compromised email account). The email claims the supplier has changed their bank account and future payments should go to the new account.
Red flags:
- The bank account change notification comes by email only, without a corresponding KSeF invoice
- The new bank account is not on the biała lista for the supplier's NIP
- The email address differs from previous correspondence (even slightly: one character changed)
How to Verify
- Check KSeF directly. Log in to Aplikacja Podatnika or your invoicing software. If there is a new invoice, it will be there. Do not click email links to check.
- Verify the sender domain. Official KSeF communications come from
podatki.gov.plormf.gov.pl. Any other domain is not official. - Do not scan QR codes from emailed PDFs. If you need to verify a KSeF invoice, look it up by KSeF number in Aplikacja Podatnika. The official QR code is verified through the KSeF portal.
- Call the supplier. For any bank-detail change, call using a number from your existing records. Not from the email.
What to Do If You Are Targeted
- Do not click links or open attachments.
- Report to CERT Polska at
incydent@cert.plor throughmoje.cert.pl. - Delete the email. Do not forward it internally.
- If you already clicked: disconnect from the network, run a malware scan, change any credentials you entered on the fake page.
- If you already paid a fraudster's account: contact your bank immediately. A reversal may be possible if reported within hours. File a police report.
This material is information of a general nature and does not constitute legal or tax advice. For a specific situation, verify the current rules or consult a qualified adviser.