Back to Insights
Security6 min read

KSeF Phishing and QR Quishing: How to Recognise Fake Invoice Notifications

Phishing impersonating KSeF appeared four days after launch. CERT Polska issued alert 48/2026. Fake notifications deliver malware. QR quishing targets invoice visualisations. Here are the red flags.

KSeF Phishing and QR Quishing: How to Recognise Fake Invoice Notifications

CERT Polska recorded 260,783 cybersecurity incidents in 2025, a 152% year-on-year increase. Four days after KSeF's mandatory launch on 1 February 2026, the first phishing wave impersonating KSeF appeared. CERT Polska issued alert 48/2026 on 17 April 2026, covering fake "new invoice in KSeF" email notifications that deliver malware.

The Phishing Patterns

Pattern 1: Fake KSeF notification email

The email appears to come from KSeF or the Ministry of Finance. It claims a new invoice is waiting in your KSeF inbox. It contains a link to a fake login page that harvests credentials, or an attachment that installs malware.

Red flags:

  • The sender domain is not ksef.podatki.gov.pl or podatki.gov.pl
  • The link URL does not start with https://ksef.podatki.gov.pl/ or https://aplikacja-podatnika.mf.gov.pl/
  • The email asks you to log in via a link (KSeF does not send login links by email)
  • The email contains an attachment (KSeF does not send invoices as email attachments)
  • The email uses urgency language ("act now", "invoice expires")

Pattern 2: QR quishing on invoice visualisations

The fraudster takes a legitimate KSeF invoice PDF visualisation and replaces the QR code with a malicious one. When the recipient scans the QR code with their phone, it opens a phishing site or downloads malware.

Red flags:

  • The QR code URL does not match ksef.podatki.gov.pl
  • Scanning the QR code opens a page asking for login credentials
  • The QR code looks different from previous invoices from the same supplier (different size, position, or style)
  • The PDF was received by email, not through KSeF

Pattern 3: Fake "new bank details" using KSeF authority

The fraudster sends an email claiming to be from a known supplier, referencing a recent KSeF invoice number (which they may have obtained from a compromised email account). The email claims the supplier has changed their bank account and future payments should go to the new account.

Red flags:

  • The bank account change notification comes by email only, without a corresponding KSeF invoice
  • The new bank account is not on the biała lista for the supplier's NIP
  • The email address differs from previous correspondence (even slightly: one character changed)

How to Verify

  1. Check KSeF directly. Log in to Aplikacja Podatnika or your invoicing software. If there is a new invoice, it will be there. Do not click email links to check.
  2. Verify the sender domain. Official KSeF communications come from podatki.gov.pl or mf.gov.pl. Any other domain is not official.
  3. Do not scan QR codes from emailed PDFs. If you need to verify a KSeF invoice, look it up by KSeF number in Aplikacja Podatnika. The official QR code is verified through the KSeF portal.
  4. Call the supplier. For any bank-detail change, call using a number from your existing records. Not from the email.

What to Do If You Are Targeted

  1. Do not click links or open attachments.
  2. Report to CERT Polska at incydent@cert.pl or through moje.cert.pl.
  3. Delete the email. Do not forward it internally.
  4. If you already clicked: disconnect from the network, run a malware scan, change any credentials you entered on the fake page.
  5. If you already paid a fraudster's account: contact your bank immediately. A reversal may be possible if reported within hours. File a police report.

This material is information of a general nature and does not constitute legal or tax advice. For a specific situation, verify the current rules or consult a qualified adviser.