Someone at your company will scan a QR code today. There is one on the lunch menu, one on the parking sign, one on the shipping label, and one on the flyer taped to the breakroom fridge. Nobody thinks twice, because pointing a phone at a little black and white square has become as routine as clicking a link was twenty years ago.

Attackers noticed. Here is the uncomfortable part: you cannot read a QR code with your eyes, so you cannot check where it goes before you commit to it. That gap has a name now. It is called quishing, and it is phishing delivered as a picture instead of a link. It is growing quickly, and most of the security tools you already pay for were never built to look inside a picture.

A QR Code Is Just a Link You Cannot Read

Strip away the mystique and a QR code is a web address wearing a costume. The pattern of squares encodes text, and almost always that text is a URL. Your camera decodes it and hands it to your browser. That is the whole technology.

What makes it useful for attackers is not cleverness. It is that the normal human safety check is missing. On a laptop, you can hover over a link and see the destination in the corner of the screen. You can spot that “microsoft-verify-login.co” is not Microsoft. With a QR code, there is nothing to hover over. You scan, and by the time you see an address, you are already on the page and being asked for your password.

Why Your Email Filter Misses It

Email security works largely by reading text. It scans the message, pulls out the links, checks them against reputation lists, and decides. That approach is very good at catching a bad URL sitting in a paragraph.

A QR code defeats that process by not being text. The malicious address lives inside an image file. Microsoft, reporting on the first quarter of 2026, described attackers embedding malicious URLs inside image based QR codes specifically to exploit the limitations of text based scanning engines. In the same period Microsoft said it detected roughly 8.3 billion email based phishing threats, and that QR code attacks rose 146 percent across the quarter, climbing from 7.6 million in January to 18.7 million in March.

Attackers scale what works. QR codes work because the filter sees a picture, the picture looks like a picture, and the message goes through. Some filters have improved and now decode images before delivery. Do not assume yours does. Ask your IT provider directly. It is the same broader pattern we covered in our look at why phishing keeps getting through.

Your Phone Is Weaker Ground Than Your Laptop

There is a second reason quishing works, and it has nothing to do with filters. A QR code moves the victim from a managed device to an unmanaged one. Microsoft made this point in the same report, noting that attackers redirect victims to phishing sites on unmanaged mobile devices. Your company laptop may have web filtering, endpoint protection, and access rules. Your employee’s personal phone, on cellular data in the parking lot, usually has none of that.

Phones are also worse for humans, not just for tools. Here is what changes on a small screen:

  • The address bar is short. Mobile browsers truncate long URLs, so a convincing prefix is often all anyone sees before the text runs out.
  • Login pages look identical. A mobile sign in page is a logo and two boxes. There is much less visual context to feel wrong.
  • You are usually walking. People scan codes standing at a printer, in a lobby, or at a parking meter. Distraction is built into the moment.
  • Reporting is harder. Forwarding a suspicious message to IT is easy on a laptop and awkward on a phone, so incidents go unreported.

The Stickers, Posters, and Invoices Nobody Checks

Email is only half of it. The physical version of this attack costs about four dollars at an office supply store, and it does not touch your network at all until it works. The Federal Trade Commission has warned consumers about this directly, saying that scanning a scam code “could take you to a phishing website that steals your personal information, like credit card numbers or usernames and passwords” and that “it could also download malware onto your phone and give hackers access to your device.”

The places we see it show up around small and mid sized businesses in Denton County and beyond:

  • A sticker placed over a real code. Parking meters, EV chargers, and payment kiosks are the classic targets. The original code is still underneath.
  • Invoices and statements. A code labeled “scan to pay” that routes a real payment to a fake portal. The invoice may otherwise be perfectly accurate.
  • Breakroom and lobby posters. “Scan to enroll in the new benefits portal” or “Scan for the updated parking policy.” Printed, taped up, and rarely questioned.
  • Unexpected packages. A delivery nobody ordered, containing a code that promises to identify the sender.

How to Brief Your Team in Ten Minutes

You do not need a training platform for this. You need one short conversation, repeated at the next staff meeting. Keep it to these points.

  1. Treat a code like a stranger’s link. Same rules. If you did not go looking for it, be suspicious of it.
  2. Look at the preview before you tap. Most phone cameras show the address as a banner before opening it. Read the domain, not the words around it.
  3. Never sign in from a scan. This is the single rule that stops most of the damage. If a code leads to a login page for a system you use at work, close it and open that system the way you normally do.
  4. Feel for the sticker. In the physical world, run a thumbnail over the edge of the code. A label applied over printed material has a lip you can feel.
  5. Verify payment codes by phone. Any code that moves money gets a call to a number you already had, not a number printed next to the code.
  6. Report without embarrassment. Say out loud that nobody gets in trouble for reporting a scan. You want the report in minutes, not the confession in weeks.

If someone did enter credentials, the FTC’s advice matches ours: change the password immediately and turn on two factor authentication. Then tell your IT provider, because the password is only part of the cleanup. Sessions, tokens, and mailbox rules all need a look.

The Bottom Line

Quishing is not a new kind of attack. It is the same credential theft that has run for two decades, repackaged into the one format your filters read poorly and your people trust automatically.

The durable fix is not “stop scanning codes,” because your team will scan them anyway and most of them are fine. The durable fix is making a stolen password worth less. Strong multi factor authentication, and ideally the phishing resistant kind, means a harvested password on a fake page does not open the door. If you want the plain English comparison of the options, we broke them down in YubiKey vs Passkey vs MFA. Pair that with the ten minute briefing above and you have covered both halves of the problem: the click and the consequence.

If you are not sure whether your email filtering decodes QR codes, or whether your MFA would stop a credential harvest, we can tell you in a short conversation. Harrison Ward Technology supports small and mid sized businesses across Denton County with practical security work, not scare tactics. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).