QR Code Scams Are Rising: What Your Business Needs to Know About “Quishing”
- jbonyuet
- 4 days ago
- 10 min read

QR codes have become part of everyday business.
Employees scan them to open shared documents, connect to Wi-Fi, make payments, access event information, and complete account setup. Because QR codes are familiar and convenient, most people scan them without giving them much thought.
Cybercriminals are counting on that.
A QR code scam, sometimes called quishing, hides a malicious website inside a QR code. Instead of clicking a suspicious link in an email, the recipient scans an image with a phone and is taken to a fake login page, payment form, or malware download.
These attacks are becoming much more common. Microsoft reported that QR code phishing volume increased 146% during the first quarter of 2026, rising from 7.6 million attacks in January to 18.7 million in March. Most were delivered through PDF attachments, which can look like ordinary invoices, account notices, or shared documents.
Here is what business owners and employees need to know.
What Is a QR Code Scam?
A QR code scam is a phishing attack that uses a QR code instead of a written web link.
The attacker places a malicious web address inside the code. When someone scans it, their phone opens a website designed to steal information or install harmful software.
The destination may look like:
A Microsoft 365 login page
A bank or payment portal
A shared document
A delivery-tracking page
A password-reset screen
A company benefits or payroll portal
The website may look convincing, but any information entered goes directly to the attacker.
The QR code itself is only the delivery method. The goal is the same as traditional phishing: steal passwords, payment details, or other sensitive information.
Why QR Code Scams Get Past Security
QR code scams are effective for two main reasons.
1. The malicious link is hidden inside an image
Most email security tools inspect the text of an email for suspicious links and known malicious websites.
A QR code stores the link inside an image. Some security tools can analyze these images, but not all of them do. The UK National Cyber Security Centre has warned that QR codes may slip past phishing detection because some tools do not inspect images for embedded links.
This allows a malicious message to look relatively harmless until someone scans the code.
2. Scanning often moves the employee onto a personal phone
Most people scan QR codes using their phones.
That matters because a personal phone may not have the same protections as a managed business computer. Your company computer may use web filtering, endpoint protection, DNS security, and other controls. A personal phone may have none of them.
The employee can move outside the company’s security environment without realizing it.
A Simple Example of How Quishing Works
Imagine an employee receives an email that appears to come from Microsoft.
The message says:
Your multi-factor authentication registration expires today. Scan the QR code below to keep your account active.
The email includes a Microsoft logo, familiar colors, and a PDF attachment.
The employee opens the PDF, scans the code, and sees what looks like a normal Microsoft login page on their phone.
They enter their email address, password, and verification code.
The page is fake.
The attacker now has the information needed to access the employee’s account. From there, they may read email, impersonate the employee, request payments, access shared files, or send more convincing phishing messages to coworkers and customers.
Nothing about the initial message has to look obviously malicious. That is what makes these attacks dangerous.
How Common Are QR Code Scams?
QR code phishing grew sharply during the first quarter of 2026.
According to Microsoft:
QR code phishing volume rose from 7.6 million attacks in January to 18.7 million in March.
That represented a 146% increase during the quarter.
QR code phishing reached its highest monthly volume in at least a year.
PDF attachments were the most common delivery method.
PDFs accounted for 65% of QR code attacks in January and 70% in March.
Attackers use PDFs because businesses receive them every day. Invoices, contracts, reports, payment requests, and account notices commonly arrive in that format.
A PDF containing a QR code may not immediately look suspicious, especially when the message appears to come from a known vendor or service.
What QR Code Scams Usually Look Like
These are some of the most common versions businesses may encounter.
Fake account-security notices
An email claims that an employee must scan a QR code to:
Reset a password
Re-register multi-factor authentication
Prevent an account from being suspended
Review unusual activity
Confirm identity
The code leads to a fake login page.
Shared-document notifications
A message says that a coworker, client, or vendor shared a confidential document.
Instead of including a normal link, it asks the recipient to scan a QR code to view the file. The destination then asks for Microsoft 365 or Google Workspace credentials.
Fake invoices and payment requests
A PDF invoice contains a QR code labeled:
Pay now
View invoice
Confirm payment
Update billing information
The code may lead to a fake payment page or redirect the payment to an attacker.
Delivery and package notices
An email or text claims that a package could not be delivered and asks the recipient to scan a QR code to reschedule or pay a small fee.
The Federal Trade Commission has warned that malicious QR codes can lead to phishing sites that steal usernames, passwords, credit card numbers, and other personal information.
QR code stickers in public places
Not every attack arrives by email.
Criminals may place fake QR code stickers over legitimate codes on:
Parking meters
Payment terminals
Restaurant signs
Event posters
Public Wi-Fi instructions
Building-access notices
The victim believes they are using the official code but is redirected to the attacker’s website.
Why These Attacks Matter to Businesses
A stolen login can create a much larger problem than one compromised account.
Depending on the employee’s access, an attacker may be able to:
Read confidential email
Access shared business files
Reset passwords for other services
Impersonate employees or executives
Send fake payment instructions
Contact customers or vendors
Steal financial or personal information
Launch additional phishing attacks
Introduce malware or ransomware
A compromised email account is often used to make the next attack more convincing.
For example, an attacker may review real conversations with a vendor and then send a believable request to change banking information. Because the message comes from a legitimate account and fits an existing conversation, it can be difficult to recognize as fraud.
How to Protect Your Business From QR Code Scams
You do not need to ban QR codes entirely. Most are legitimate.
The goal is to teach employees to slow down when a code asks them to log in, make a payment, or provide sensitive information.
Be cautious with QR codes sent by email or text
Treat an unexpected QR code the same way you would treat an unexpected link.
Be especially careful when the message asks you to:
Sign in
Reset a password
Confirm an account
Make a payment
Enter banking details
Provide personal information
Act immediately
The NCSC specifically advises caution when QR codes arrive inside emails.
Check the destination before opening it
Most phones display the destination website before loading it.
Read the address carefully.
Look for:
Misspellings
Extra words
Unfamiliar domains
Swapped letters
Strange endings
Shortened links
A page can copy Microsoft’s colors and logo. The web address is often the better clue.
Go directly to the official website
When a message says an account needs attention, do not use the QR code.
Instead:
Open your browser.
Type the official website address yourself.
Use a saved bookmark or trusted application.
Check the account from there.
For example, when a Microsoft account supposedly needs attention, open Microsoft 365 directly instead of scanning the code in the message.
Verify payment requests another way
Never rely only on an emailed QR code for a payment or banking change.
Call the vendor using a phone number already stored in your records. Do not use the phone number listed in the suspicious message.
A quick verification call can prevent a costly fraudulent transfer.
Watch for urgency
Attackers often create pressure by saying:
Your account will close today
Payment is overdue
A package cannot be delivered
Your password has expired
Suspicious activity was detected
You must respond within 24 hours
Urgency is designed to stop people from thinking carefully.
A threatening deadline should make you more cautious, not less.
Use strong multi-factor authentication
Multi-factor authentication adds another barrier when a password is stolen.
Whenever possible, use phishing-resistant methods such as:
Passkeys
Hardware security keys
Number matching in an authenticator application
MFA does not make phishing impossible, but stronger authentication can reduce the damage caused by a stolen password.
Keep phones and computers updated
Software updates often include important security fixes.
Employees should regularly update:
Phone operating systems
Browsers
Security applications
Business applications
Company-managed computers
The FTC also recommends keeping phones and computers updated to receive current security patches.
Inspect physical QR codes
Before scanning a code on a parking meter, terminal, sign, or poster, look closely.
Watch for:
A sticker placed over another code
Uneven edges
Different coloring
Peeling material
Signs of tampering
When possible, use the organization’s official app or website instead.
Train employees using real examples
Many employees have received general phishing training but have never been warned about QR code scams.
Include quishing in security-awareness training and show employees what these attacks look like.
Training should clearly explain:
Why emailed QR codes deserve caution
How to inspect destination addresses
How to verify account and payment requests
Who to contact when something looks suspicious
How to report a possible mistake quickly
Create a no-blame reporting culture. Employees are more likely to report a suspicious scan quickly when they know they will not be punished for speaking up.
Fast reporting gives your IT team more time to contain the incident.
What to Do If Someone Scans a Suspicious QR Code
The correct response depends on what happened after the scan.
If the person scanned the code but entered nothing
The risk is generally lower.
They should:
Close the website.
Avoid downloading anything.
Do not return to the page.
Report the message to the company’s IT contact.
Delete the original email or text after it has been reported.
Your IT team may want to block the website and look for similar messages sent to other employees.
If the person entered a password
Act immediately.
Change the password using the official website.
Sign out of other active sessions where possible.
Confirm that multi-factor authentication is enabled.
Contact your IT provider or security team.
Review the account for unfamiliar login activity.
Check for suspicious inbox rules or email forwarding.
Change any other account that used the same password.
Attackers sometimes create hidden email rules that forward messages or delete security alerts, so changing the password alone may not be enough.
If payment or banking information was entered
Contact the bank or card provider immediately.
Also:
Freeze or replace the affected card
Monitor the account for unauthorized transactions
Notify the company’s financial leadership
Preserve the original message and website details
Report the fraud to the appropriate authorities
The FTC advises people who enter credentials into a phishing page to change their passwords immediately and enable two-factor authentication.
If a file or application was downloaded
Disconnect the device from company systems and contact IT immediately.
Do not continue using the device until it has been checked. A downloaded file may contain malware even when nothing appears to happen.
Frequently Asked Questions
Are QR codes safe to use?
Most QR codes are legitimate.
A code on a restaurant menu or an official company sign may be perfectly safe. The risk increases when the code arrives unexpectedly, asks for sensitive information, creates urgency, or appears to have been placed over another code.
Always check the destination before opening it.
What is quishing?
Quishing is a form of phishing that uses a QR code instead of a written link.
The word combines “QR” and “phishing.” The attacker’s goal is usually to lead the victim to a fake website that steals passwords, payment information, or other sensitive data.
Can email security stop QR code scams?
Sometimes, but not always.
Some modern email-security platforms can identify QR codes and inspect their destinations. Other tools may treat the code only as an image and fail to recognize the hidden link.
Businesses should use appropriate security tools, but employee awareness remains important because no filter catches every attack.
Why is a QR code in an email more dangerous than a normal link?
A normal link can often be inspected by the company’s email security before the employee clicks it.
A QR code hides the destination inside an image and encourages the employee to open it on a phone. That phone may sit outside the company’s normal web filtering and endpoint protections.
Can scanning a QR code install malware?
It can.
A malicious QR code may lead to a website that attempts to download harmful software or convinces the user to install an application. The FTC has warned that scam QR codes may lead to phishing sites or malware downloads.
Avoid downloading applications or files after scanning an unexpected code.
What should I do if I scanned a suspicious code but did not enter anything?
Close the page and report the message to your IT contact.
The risk is lower when you did not enter information, download a file, approve an MFA request, or grant permissions. Reporting it still matters because other employees may have received the same attack.
Should businesses stop using QR codes?
Not necessarily.
QR codes remain useful for legitimate business purposes. Companies should use them carefully, protect any pages they lead to, and train employees not to trust every code automatically.
The better approach is informed use, not a complete ban.
A QR Code Should Not Be Automatically Trusted
QR codes feel familiar, but they can hide the same threats as any suspicious link.
The difference is that the destination is harder to see, the message may bypass some email protections, and the employee often opens it on a less-protected personal device.
The best defense combines three things:
Security tools that can inspect modern phishing techniques
Strong account protections such as multi-factor authentication
Employees who know when to stop and verify a request
A two-second pause before scanning can prevent a much larger incident.
Is Your Business Prepared?
QR code phishing is one example of how attackers continue adapting their methods to bypass traditional security.
Your business does not need an overly complicated response. It needs clear employee training, properly configured email and account security, and a reliable process for reporting suspicious activity.
Vital IT helps businesses identify security gaps, strengthen Microsoft 365 environments, and put practical protections in place without adding unnecessary complexity.
Not sure whether your current setup is enough?
Contact Vital IT for a practical security review.
Article adapted and used with permission from The Technology Press.




Comments