Skip to main content

QR Code Phishing: Why Your Email Filter Never Sees It

Media QR Code Phishing Why Your Email Filter Never Sees It

 

QR codes are now a familiar part of everyday business. They appear on invoices, event tickets, restaurant menus, delivery notices and authentication screens.

That familiarity has made them useful to cybercriminals.

In a QR code phishing attack—often called quishing—the attacker replaces a normal clickable link with a QR code image. The recipient scans it with a phone and is taken to a fake login page, malicious website or fraudulent authentication process.

The title “why your email filter never sees it” is deliberately provocative: modern security platforms can detect many malicious QR codes, but basic and older email filters may struggle because the dangerous destination is hidden inside an image rather than written as a conventional URL. Microsoft has described QR phishing as a distinctive detection challenge because the malicious link is visually encoded rather than presented as ordinary readable text. 

What Is QR Code Phishing?

QR code phishing uses a QR image to direct the victim towards malicious content.

A typical attack works like this:

  1. The attacker sends an email containing a QR code.
  2. The message creates urgency or curiosity.
  3. The victim scans the code using a mobile phone.
  4. The phone opens a website controlled by the attacker.
  5. The website requests credentials, payment details or authentication approval.
  6. The attacker steals the submitted information or session.

Common lures include:

  • “Your Microsoft 365 password expires today.”
  • “Scan to review the secure document.”
  • “Your MFA registration is incomplete.”
  • “A voicemail is waiting.”
  • “Confirm your payroll information.”
  • “Scan to release the quarantined message.”
  • “Your account will be suspended.”
  • “View the attached invoice.”

Microsoft has observed QR phishing emails impersonating routine business processes such as password resets, two-factor authentication checks, document signing and HR communications. 

Why QR Codes Can Evade Basic Email Filtering

Traditional email-security systems are very good at examining:

  • Clickable links
  • Attachment types
  • Sender reputation
  • Known malicious domains
  • Message text
  • Embedded scripts
  • File signatures

A QR code changes the format of the threat.

Instead of including:

https://fake-microsoft-login.example

the email contains a grid of black and white squares.

A basic filtering system may identify the item only as an image. Unless the platform can locate the QR code, decode its contents and analyse the resulting destination, it may not see the hidden URL before the message reaches the inbox.

Attackers may make detection harder by:

  • Placing the code inside a PDF
  • Embedding it within a larger image
  • Changing its colours
  • Adding company branding
  • Splitting or distorting parts of the image
  • Using multiple redirect services
  • Personalising the destination for each recipient
  • Activating the malicious page only on mobile devices

Microsoft reported that QR code phishing rose sharply because the technique enabled attackers to conceal destinations inside images and redirect victims to credential-harvesting pages. 

Modern Email Filters Can Detect Some QR Attacks

It is important not to overstate the problem.

Advanced email-security platforms can use image analysis, computer vision, URL extraction, reputation checks and behavioural detection to identify suspicious QR codes.

Microsoft Defender for Office 365, for example, added specialised detection intended to locate QR codes within messages, decode their URLs and evaluate the surrounding email context. Microsoft said its systems had blocked more than 18 million unique phishing emails containing QR images before announcing those protections in late 2023. 

However, no filter catches every attack.

Newly created domains, compromised legitimate websites, delayed redirects and heavily modified QR images can still create detection challenges. QR code phishing was described by Microsoft as the fastest-growing email attack vector during the first quarter of 2026, more than doubling during that period. 

The correct assumption is not that your filter sees nothing. It is that the filter cannot be your only defence.

Why QR Phishing Often Moves the Attack to a Personal Phone

The victim normally scans the email using a smartphone.

That creates a useful separation for the attacker:

  • The email arrives on the protected company computer.
  • The malicious site opens on the phone.
  • The phone may be personal or unmanaged.
  • The mobile browser may not use company web filtering.
  • Endpoint security may not inspect the session.
  • The full destination can be difficult to read on a small screen.

The user is also moving from one device to another. They may not notice that the website opened on their personal phone is unrelated to the company system displayed on their laptop.

This device switch can weaken the connection between the original email-security alert and the later web activity.

The Fake Microsoft 365 Login

Many QR phishing attacks lead to pages designed to imitate Microsoft 365.

The page may request:

  • Email address
  • Password
  • Authenticator code
  • MFA approval
  • Device code
  • Recovery information

A sophisticated adversary-in-the-middle page may relay the victim’s information to the real Microsoft service and capture the authenticated session cookie after MFA succeeds.

That means the attacker may obtain access even though the user completed genuine multi-factor authentication. Proofpoint has documented QR-delivered phishing campaigns using platforms capable of stealing credentials, two-factor authentication data and session cookies. 

QR Codes Can Also Abuse Device Authentication

Not every QR phishing attack leads to a conventional fake password page.

Attackers may use a QR code to initiate:

  • Device code authentication
  • Messaging-app device linking
  • OAuth consent
  • Account pairing
  • Malicious application authorisation

In these attacks, the victim may interact with a genuine website but unknowingly approve a session or device controlled by the attacker.

Google Threat Intelligence has documented malicious device-linking QR codes that impersonated legitimate Signal resources, while CISA has warned about QR-based device linking used to compromise messaging accounts. 

Warning Signs of a QR Phishing Email

Treat the message as suspicious when:

  • You were not expecting a QR code.
  • The email creates an urgent deadline.
  • It asks you to verify a password or MFA setting.
  • The sender claims that scanning is the only way to continue.
  • The message contains little text beyond the QR image.
  • The sender address does not match the organisation.
  • The QR code appears inside an unexpected PDF.
  • The email asks you to scan using a personal phone.
  • The promised document or message was not expected.
  • The destination requests credentials immediately.

A QR code does not become trustworthy because it displays a Microsoft, bank or courier logo beside it.

What Employees Should Do Before Scanning

Before scanning a business QR code:

  1. Confirm that the message was expected.
  2. Check the sender’s full address.
  3. Verify the request through a known communication channel.
  4. Ask why a normal company link cannot be provided.
  5. Preview the destination before opening it where the phone allows.
  6. Check the full domain carefully.
  7. Never enter credentials merely because a QR code requested them.
  8. Report suspicious messages to IT or security.

CISA advises users to be cautious with unsolicited messages, inspect requests for urgency and report suspected phishing rather than interacting with it. 

Why Looking at the Domain Still Matters

After scanning, the phone may show a preview of the destination.

Check the actual registered domain, not just words appearing elsewhere in the address.

For example:

login.microsoftonline.com

is different from:

microsoft-login.security-check.example

The second address contains the word “Microsoft,” but the controlling domain is example.

Be especially cautious when the destination:

  • Uses a URL shortener
  • Contains spelling substitutions
  • Includes long random strings
  • Opens several redirects
  • Requests Microsoft credentials on an unrelated domain
  • Shows an unexpected file download
  • Requests installation of an app or profile

Controls Businesses Should Implement

Use Advanced QR Code Detection

Confirm whether your email-security service can:

  • Detect QR codes in message bodies
  • Inspect QR codes in PDF attachments
  • Decode embedded URLs
  • Follow redirects safely
  • Analyse newly registered domains
  • Re-scan destinations after delivery
  • Remove malicious messages already delivered

Do not assume these features are enabled automatically for every licence.

Protect Mobile Devices

Company mobile devices should use:

  • Mobile device management
  • Supported operating systems
  • Security updates
  • Safe-browsing protection
  • Approved applications
  • Endpoint or mobile threat defence where appropriate

Sensitive company access should be restricted from unmanaged devices when practical.

Use Phishing-Resistant MFA

Passkeys and FIDO2 security keys are harder to use on fake domains because authentication is cryptographically bound to the legitimate service.

They provide stronger protection than passwords combined with SMS codes, one-time codes or ordinary push approvals.

Phishing-resistant authentication does not make users invulnerable, but it can prevent many credential-harvesting pages from turning a mistake into an account compromise.

Configure Conditional Access

Microsoft Entra Conditional Access can help by requiring:

  • Phishing-resistant authentication
  • Compliant devices
  • Approved applications
  • Stronger controls for administrators
  • Risk-based access decisions
  • Restricted access from unmanaged devices

It can also block authentication flows, such as device code flow, where the organisation does not require them.

Train Users With Realistic Examples

Security awareness training should include QR phishing examples, not only traditional blue-link emails.

Users should practise identifying:

  • QR codes inside PDFs
  • Fake MFA-registration messages
  • Payroll and HR lures
  • Secure-document scams
  • Mobile credential-harvesting pages
  • Suspicious device-linking requests

Microsoft provides QR phishing simulations through its attack simulation and training capabilities for supported Defender for Office 365 customers. 

What to Do After Scanning a Suspicious QR Code

Scanning alone does not always mean the account has been compromised.

The risk increases if the user:

  • Entered a password
  • Approved MFA
  • Entered a device code
  • Granted application permissions
  • Downloaded a file
  • Installed an application or profile
  • Submitted payment information

When this happens:

  1. Stop interacting with the page.
  2. Contact IT or security immediately.
  3. Preserve the original email.
  4. Provide the approximate scan time.
  5. Identify which device was used.
  6. Revoke active sessions where account compromise is possible.
  7. Reset credentials through a trusted process.
  8. Review MFA methods and application consent.
  9. Inspect the mobile device.
  10. Check email, files and sign-in logs for suspicious activity.

Do not merely delete the message and assume the problem has ended.

Final Thoughts

QR code phishing succeeds by hiding a dangerous link inside a familiar image and moving the user from a protected email environment to a phone that may have fewer security controls.

Basic email filters may not decode or analyse the QR destination. Advanced platforms can detect many of these messages, but attackers continue changing image formats, domains and redirect methods to evade inspection.

The strongest defence combines:

  • Modern email protection
  • Mobile-device security
  • Conditional Access
  • Phishing-resistant MFA
  • User training
  • Rapid incident response

The simplest rule for employees is this:

Never scan an unexpected QR code to sign in, reset a password or approve an account request.

A genuine business process should be independently verifiable through a known website, application or contact.

Worried About QR Code Phishing?

Hamilton Group can help your business strengthen its Microsoft 365 email and identity security.

Our experts can help you:

  • Review Microsoft Defender for Office 365
  • Improve phishing and QR-code detection
  • Configure Safe Links and attachment protection
  • Deploy phishing-resistant MFA
  • Strengthen Microsoft Entra Conditional Access
  • Secure company mobile devices
  • Run realistic phishing simulations
  • Investigate suspicious Microsoft 365 sign-ins
  • Build account-compromise response procedures

Visit hgmssp.com, call Hamilton Group on 0330 043 0069, or book a meeting with one of our experts to improve your protection against modern phishing attacks.