QR codes are part of normal business now.
You scan them to see a menu, pay for parking, connect to Wi-Fi, or open a shared document.
You know that. I know that. Attackers know that, and they have started hiding malicious links inside QR codes to get past the security tools that would normally catch a bad link in an email.
The technique has a name, quishing, and it works because when it comes down to it, a QR code is just an image.
Your email filter reads text, so a link encoded into a QR code can pass straight through. When you scan it, you usually do so on your phone, which sits outside most of the protection your work computer has.
This post covers what a QR code scam is, why it gets past your security, what the common ones look like, and the habits that protect your business.
A QR code scam is a phishing attack that uses a QR code in place of a written link.
Instead of a clickable URL your email security can inspect, the attacker encodes the web address into a square image.
You scan it with your phone camera, your phone opens the link, and you land on a page built to steal your login or your payment details.
The page on the other end is the same kind of fake you would see in any phishing attack, a login screen made to look like Microsoft 365 or a payment form that copies your bank. The QR code is only the delivery method that gets you there.
Two things make these scams effective.
First, the malicious link is hidden inside an image.
Most email security tools scan the text of a message for known bad links. A QR code is a picture, so the link inside it is not text the filter can read.
The UK's National Cyber Security Centre points out that not all phishing-detection tools scan images, which is the reason criminals started using QR codes to disguise their links in the first place.
Second, scanning a code moves you onto your phone.
Your work computer probably has web filtering, endpoint protection, and DNS controls that block known bad sites.
Your personal phone usually has none of that. So the moment you scan, you step outside the protection your business pays for, often without realizing it happened.
The volume is climbing fast. In its report on email threats for the first quarter of 2026, Microsoft said it detected around 8.3 billion email-based phishing threats in those three months.
QR code phishing rose 146% across the quarter, from 7.6 million attacks in January to 18.7 million in March.
By the end of the quarter it had reached its highest monthly volume in at least a year.
Microsoft also found that most of these attacks arrived as PDF attachments, growing from 65% of QR code attacks in January to 70% in March.
The QR code sits inside a PDF, the PDF is attached to an email, and the whole thing looks like an ordinary document until someone scans it.
These are the QR code scams that come up most often.
Protecting yourself against Quishing comes down to a few habits:
If you or someone on your team scanned a QR code and entered details on the page that opened:
Acting quickly limits what an attacker can do with the details they captured.
Article used with permission from The Technology Press.