Why a QR Code Beats the Email Security

Picture of Ikram Massabini

Ikram Massabini

August 18, 2026

Passkeys_ A Login With Nothing for an Attacker to Steal

Your email filtering is reasonably good at what it does. It reads the text of a message, compares links against reputation data, and holds back the ones that look wrong. That capability is the reason attackers stopped writing links in text.

A QR code is a picture. The web address inside it is not text your filter can parse, so a message carrying one arrives looking like an ordinary email with an image in it. The technique has a name, quishing, and the volume behind it is no longer marginal. Microsoft reported QR code phishing climbing 146 percent through the first quarter of 2026, from 7.6 million attacks in January to 18.7 million in March, its highest monthly volume in at least a year.

A second mechanism is at work too, and it is the more interesting one.

The device switch is the real attack

Your work machines probably sit behind web filtering, endpoint protection, and DNS controls that would block a known malicious site before the page loaded. That stack is doing its job.

Your employee’s phone has none of it. The moment someone lifts their phone to scan a code that arrived in their work inbox, they have stepped outside every protective layer the business pays for, usually without any sense that a boundary was crossed. The fake Microsoft 365 login page that would have been blocked on the laptop renders perfectly on the phone.

That combination, a link your filters cannot read delivered onto a device your controls do not cover, is what makes this worth a staff conversation.

The forms it usually takes

Most of these attacks reuse a small number of pretexts.

The security notice is the most common: a message styled as coming from Microsoft or your own IT team, saying you need to scan a code to re-enroll multi-factor authentication or prevent your account from being deactivated. The code opens a credential harvesting page.

Shared document notifications work similarly, with a sign-in step before the file supposedly appears. Fake invoices include a code offered as a faster way to pay, routing the payment to the attacker. Missed delivery notices, which the FTC has warned about specifically, ask you to scan to reschedule. Attackers also print stickers and apply them over legitimate codes on parking meters and payment terminals, so the victim believes they are paying for parking and is handing card details to a stranger.

One detail from Microsoft’s data is worth planning around: most of these attacks arrived as PDF attachments, rising from 65 percent in January to 70 percent in March. The code sits inside a document, the document is attached to an email, and nothing looks unusual until someone scans it.

The habits that hold up

Protection here is mostly behavioral, which means it is cheap and depends on people knowing about it.

Treat a QR code that arrives by email the way you would treat an unexpected link, especially one asking you to log in or pay. The UK’s NCSC makes this distinction: codes in a restaurant or on a product are generally fine, while codes inside emails warrant real suspicion.

Read the address before you act. Your phone displays the destination after a scan and before it opens. That preview is the whole defense, and most people scroll past it.

When a message claims your account needs attention, go directly. Open a browser, use a bookmark, and sign in the way you always do. A legitimate notice will still be waiting.

Notice urgency for what it is. Threats of account closure or a fine within 24 hours exist to push someone past their own judgment.

Deploy phishing-resistant multi-factor authentication, so a captured credential is much harder to use. And tell your team, because most employees have never heard of this, which is precisely why it works. A short message with one real example does more than a policy document.

If someone already scanned one

Move quickly, because the value of stolen credentials decays as you close doors. Change the password for that account and anything else using the same one. Confirm multi-factor authentication is active. Tell whoever manages your IT so they can review sign-in activity. Anything involving a card number or account details goes to the bank the same day.

Someone who scanned a code and closed the page without typing anything is in reasonable shape. Let IT know and carry on.

Getting your team prepared

MVP Network Consulting works with businesses across Buffalo and Western New York on exactly this gap, where the technical controls are fine and the delivery method routes around them. We can review what your email security catches today, strengthen your MFA, and brief your staff in a way they will remember. Reach out when you want that handled.