Why QR Codes Are the New Favourite Trick
QR codes became part of everyday life during the pandemic: menus, parking, payments, event check-ins. We’ve all learned to point a phone at one without a second thought. Criminals noticed.
“Quishing” (QR code phishing) hides a malicious link inside a QR code instead of in clickable text. It works for two reasons. First, a QR code in an email is just an image, so many email filters that scan links never see the destination. Second, the victim scans it with their personal phone, which usually sits outside company security tools entirely.
What It Looks Like in Practice
The most common versions we see reported:
- “Your Microsoft 365 password expires today”: an official-looking email with a QR code to “keep your current password”. The page it opens is a convincing fake login that captures your credentials and, often, your MFA code as well.
- Fake invoices and payment requests: a PDF with a QR code for “quick payment” that leads to a card-harvesting page.
- Parking meters and car parks: stickers placed over genuine QR codes, sending drivers to a fake payment site. Councils and car park operators across Europe have issued warnings about this.
- Parcel delivery notices: a card or email asking you to scan to reschedule a delivery and pay a small fee.
The common thread is urgency plus a reason to scan now rather than think.
Why It Matters for Your Business
One captured Microsoft 365 login is often all an attacker needs. From a single mailbox they can read invoices and conversations, set up mail rules to hide their activity, and send convincing fraud emails to your customers and suppliers from a genuine address. By the time anyone notices, a payment may already have been redirected.
How to Protect Your Team
Train the habit, not just the rule. Tell staff plainly: a QR code in an email asking you to log in, pay or verify something is a red flag. Microsoft will never ask you to scan a QR code to keep your password.
Check before you tap. Most phone cameras show a preview of the web address before opening it. Teach people to read it. A login page that isn’t on a microsoft.com or microsoftonline.com address is not Microsoft.
Use phishing-resistant sign-in where you can. Standard MFA codes can be captured by fake login pages. Passkeys, Microsoft Authenticator with number matching, and conditional access policies make stolen credentials far less useful.
Tighten email filtering. Modern filtering can decode QR codes in images and attachments. If yours doesn’t, it’s worth reviewing.
Make reporting easy. Staff should be able to forward a suspicious email in one click and get a quick answer, without feeling foolish for asking.
A Quick Test for Your Office
Ask your team this week: “If you got an email saying your password expires today, with a QR code to fix it, what would you do?” The answers will tell you a lot about where you stand.
If you’d like help setting up QR code scanning in your email filter or moving your team to phishing-resistant sign-in, we can review your Microsoft 365 security settings with you in about an hour.