QR Code Phishing: The Attack Built to Skip Your Email Filter

A QR code is an image, and image-based links sail past text-scanning email filters. Here is exactly how quishing works, the pretexts to expect, and what to change.

In January 2026, Microsoft's threat intelligence team counted 7.6 million phishing attacks that used a QR code. By March, that number was 18.7 million.

That is a 146% increase in three months, which made it the fastest-growing attack vector in a quarter where Microsoft analyzed roughly 8.3 billion email-based phishing threats in total. Not the biggest category. The fastest growing, by a wide margin.

When a tactic triples in a quarter, it is almost never because attackers got more creative. It is because they found something that works better than what they were doing before. So the interesting question is not "what is QR phishing." It is "what exactly does a QR code defeat that a regular link does not."

The answer is specific, mechanical, and once you see it, the defense becomes obvious. Let me walk you through it.

The mechanic: a link that is not text

A QR code is a two-dimensional barcode. Those black and white squares encode data, usually a web address, in a form a camera can read. That is all it is: a URL wearing a costume.

Here is the important part. When a QR code arrives in an email, it arrives as an image file. A picture. A JPEG or PNG, or sometimes a picture inside a PDF attachment.

Now think about how email security filters have historically worked. They read the message, extract the links as text, and check those addresses against reputation databases and known-bad lists. This works well, which is why attackers stopped putting obviously bad URLs in emails years ago.

But a filter that scans text cannot read a URL that only exists as pixels. Microsoft describes the tactic exactly this way: attackers embed malicious URLs within image-based QR codes specifically to "exploit the limitations of text-based scanning engines." There is no link in the message for the filter to evaluate, because the link is a drawing.

That is the whole trick. It is not clever social engineering. It is a format mismatch.

The second half: where you scan it

The costume has a second benefit for the attacker, and this one is arguably worse.

You are reading the email on your work laptop. The laptop has your company's security software on it, sits behind your firewall, and runs whatever web filtering you pay for. But you cannot scan a QR code with a laptop. So you pick up your phone.

Microsoft is explicit that the goal is to redirect "victims to phishing sites on unmanaged mobile devices." The scan moves the victim from the protected device to the unprotected one, over cellular, outside every control you have.

Then the phone works against you further. Mobile browsers truncate long URLs, so microsoft-verify.secure-login-portal.co displays as microsoft-verify.... There is no way to hover over a link to preview its destination on a touchscreen. And people scan codes while walking, standing in line, or between two other tasks.

The 2026 Verizon Data Breach Investigations Report found that mobile social engineering success is up 40%, and that the human element appears in 62% of breaches. Social engineering overall accounts for 17% of all breaches. For context on how durable that human factor is, the same report found the human element holding steady near two-thirds of breaches year over year. People are not more gullible on phones. They are less equipped, and the interface hides the evidence they would need.

The pretexts you will actually see

Attackers need a reason for a code to be there. In practice, small businesses see a fairly short list.

Multi-factor re-enrollment. This is the most effective one I have seen, because it is self-justifying. The email claims your organization is updating its authenticator setup and you need to scan the code to re-register your device. Scanning a QR code is *genuinely* how you enroll an authenticator app, so the request matches the reader's real experience. This one catches security-conscious people specifically.

A document waiting for signature. Branded like DocuSign or Adobe, with a code instead of a button.

Payroll or HR. "Scan to review your updated direct deposit information" or "scan to confirm your benefits election," timed near a pay period.

A voicemail or fax notification. Ancient pretext, still working, now with a code.

An unpaid invoice or a parking citation. Urgency plus a payment page.

And then the physical-world version, which people forget is the same attack. A sticker placed over the legitimate QR code on a parking meter, a restaurant table tent, or a payment terminal. The FTC has warned about this pattern directly, including a scam where an unexpected package arrives with a note asking you to scan a code to find out who sent it. The FBI's Internet Crime Complaint Center issued its own public advisory on unsolicited packages containing QR codes used to start fraud schemes. Nobody inspects a sticker for authenticity. That is the point.

The layer after the scan

One more piece worth knowing, because it explains why the phishing page often looks so convincing.

Microsoft reported that CAPTCHA-gated phishing more than doubled in March, up 125% to 11.9 million attacks, the highest volume in a year. A CAPTCHA is one of those "prove you are human" challenges. Attackers now put one in front of their fake login page.

Why? Because automated security scanners that follow links to inspect the destination cannot solve a CAPTCHA. The scanner sees a harmless challenge page and moves on. A human clicks the checkbox and proceeds to the fake login. The CAPTCHA is not there to stop bots from attacking. It is there to stop defenders from looking.

In the same period, malicious attachment payloads dropped from 19% of attacks in January to 13% in February and March, as attackers shifted toward hosted credential phishing infrastructure. Trade coverage of the report noted the same directional shift: malicious attachments are declining while QR codes surge, and both QR and CAPTCHA-gated phishing more than doubled in the quarter. The whole ecosystem is moving away from "send the bad thing" and toward "send a clean-looking pointer to the bad thing."

If someone already scanned one

This will happen eventually, so decide now what you do in the first hour, because the response window is short and the steps are not intuitive.

Assume the password is gone. Reset it, but understand that a password reset alone is frequently insufficient, because the attacker may already hold a session token, which is the credential your device gets after logging in so it does not have to ask again. Tokens survive password changes. In your admin console, use the "sign out everywhere" or "revoke sessions" function on that account explicitly.

Then check three things attackers reliably do within minutes of getting into a mailbox. Look for new inbox rules that quietly move or delete messages, which is how they hide their activity from the real owner. Look for mail forwarding newly enabled to an outside address. And check whether any multi-factor method was added, since registering their own authenticator is how they keep access after your reset.

Finally, look at what that account could reach beyond email. If it was a shared credential, every system using it is now in scope. CISA's advisory on routinely exploited weak controls is a useful cross-check here, since the follow-on damage usually travels through the same gaps it lists.

None of that requires an incident response retainer. It requires knowing the four places to look before you need to look at them.

Why your existing training does not cover this

Most phishing awareness training teaches three habits: check the sender address, hover over links before clicking, and look for spelling errors.

Habit one still helps, though a phone shows you a display name and hides the address. Habit two is impossible on a QR code. There is nothing to hover over, and no preview, and by the time the URL is visible you have already loaded the page. Habit three barely applies, because these emails are frequently well-written now and the pretext is often plausible.

So your team can be diligent, follow their training exactly, and still lose, because the training assumed a link they could inspect. That is worth saying out loud to your staff. Not "be more careful," but "here is a specific case your training does not cover, and here is the replacement rule."

Your action plan

1. Teach one rule, not a checklist. Do not scan a QR code that arrived in an email or a text message. Not "scan carefully." Do not scan. Legitimate business processes essentially never require you to scan a code out of your inbox, and the exceptions (like enrolling an authenticator) should be initiated by you, in the app, not by a message arriving unprompted.

2. Replace it with the navigate-yourself habit. If a message says a document needs signing, or your mailbox is full, or your password expires today, go to the service directly. Type the address, or use your bookmark, or open the app. This single habit neutralizes QR phishing, link phishing, and most credential theft at once, because it removes the attacker's ability to choose your destination.

3. Check whether your email filter reads images. Ask your provider or IT support one question: does our filtering inspect QR codes inside images and attachments? Many modern products do this now, and it may be a feature you already have that is switched off. Microsoft 365 and Google Workspace have both added detection here, but capability varies by license tier and configuration.

4. Protect the phone, since that is where the scan lands. App protection policies on the work account (requiring a PIN or biometric for work apps, blocking data transfer to personal apps, and allowing a selective wipe of company data) mean that a credential harvested on an unmanaged phone reaches much less. If your team uses personal phones for company email, and they do, this is the control that matters most.

5. Use phishing-resistant authentication. We covered passkeys in depth in the post on MFA fatigue attacks, so I will not repeat it here, except to say this is the durable fix rather than a mitigation. A passkey cannot be handed to a fake login page, because there is no code for a person to type into the wrong site. A stolen password plus a stolen one-time code still gets an attacker in. A passkey does not transfer.

6. Add QR codes to your simulation and training rotation. If you run phishing tests, most of them are probably link-based. Test this specific pattern, especially the multi-factor re-enrollment pretext, and use the results as a teaching moment rather than a scorecard.

7. Tell your team the physical version exists. Anyone who pays for parking, orders from a table code, or handles a customer payment terminal should know that a sticker can be placed over a real code. The tell is usually a sticker sitting on top of printed material, or a code that leads somewhere other than the business's own domain.

8. Make reporting frictionless and blameless. Put a "Report Phishing" button in the mail client and tell people explicitly that reporting a false alarm is always the right call. The worst outcome is not someone scanning a code. It is someone scanning a code, realizing it was wrong, and saying nothing for a week because they are embarrassed. Speed of reporting determines whether this is a password reset or an incident. CISA's small and medium business resource hub has free material you can hand to staff without writing your own.

Deciding which of these to do first depends on what your current setup already covers, which is the ordinary work of small business cybersecurity: finding the controls you are already paying for and turning them on.

The takeaway

QR code phishing grew 146% in a single quarter for one unglamorous reason: a picture of a link is invisible to filters that read text, and the scan moves your employee onto a phone you do not control. You cannot inspect your way out of it, because there is nothing to inspect. What you can do is give your team a rule that does not depend on inspection at all, which is to navigate to services yourself rather than letting a message decide where you land.