QR Code scams – how to protect yourself and your business

image of a QR code with the word scam embedded

What is a QR code scam?  

Simply put – a QR code scam is the same as a phishing attack – it just uses a QR code that you scan, instead of coaxing you into clicking a link.  

It’s the type of cyberattack where bad actors pretend to be a trusted site, person or company to steal private data like passwords, credit card numbers, or cash. You scan it with your phone camera, your phone opens the link, and you land on a page built to fool you to steal your login or payment details. 

The page you land on is the same kind of fake you would see in any phishing attack, a login screen made to look like Microsoft 365 or a payment form that copies your bank. The QR code is just the delivery method that gets you there. 

By hiding a malicious web link inside a QR code, it can get past the security tools that would normally spot a dangerous link written in something like an email. Instead of a URL your security can inspect, the attacker encodes the web address into the image.  

Why worry? 

Microsoft reported a 146% rise in QR code phishing during the first quarter of 2026.  

QR codes are part of normal business now. You scan them to see a menu, pay for parking, connect to Wi-Fi, or open a shared document. Attackers know that, so they’ve started hiding malicious links inside them.  

The technique has a name, “Quishing”. Your email security filter reads text not pictures, so a link encoded into a QR code can pass straight through.  

More on how the scams work  

Two things make these scams effective. First, the malicious link is hidden inside an image. Most email security tools scan the text of a message for known bad links. A QR code is a picture, so the link inside it is not text the filter can read.  

The UK’s National Cyber Security Centre (NCSC) points out that not all phishing-detection tools scan images, which is the reason criminals started using QR codes to disguise their links in the first place.  

Second, scanning a code moves you onto your phone. Your work computer probably has web filtering, endpoint protection, and DNS controls that block known bad sites, but your personal phone often has none of that. The moment you scan, you step outside the protection your organisation pays for without even realising it happened.  

How common are QR code scams?  

The volume is climbing fast. In its report on email threats for the first quarter of 2026, Microsoft said it detected around 8.3 billion email-based phishing threats in those three months. QR code phishing rose from 7.6 million attacks in January to 18.7 million in March. By the end of the quarter, it had reached its highest monthly volume in at least a year.  

Microsoft also found that most of these attacks arrived as PDF attachments, growing from 65% of QR code attacks in January to 70% in March. The QR code sits inside a PDF, the PDF is attached to an email, and the whole thing looks like an ordinary document until someone scans it.  

What QR code scams look like  

These are the QR code scams that come up most often:  

  • A ‘security’ email. You get a message that looks like it’s from Microsoft or your IT team, telling you to scan a code to re-enrol your multi-factor authentication or keep your account active. The code leads to a fake login page  
  • A shared document. An email says a colleague or client has shared a file, and you need to scan the code to view it. The page asks you to sign in first 
  • A fake invoice. A PDF invoice includes a QR code “to pay faster.” The code routes your payment to the attacker  
  • A delivery notice. A text or email about a missed package asks you to scan a code to reschedule  
  • A sticker in the real world. Attackers print QR code stickers and place them over legitimate ones on parking meters, posters, and payment terminals. You think you are paying for parking, and instead you’re handing your card details to a stranger.  

How to protect yourself and your organisation  

Protecting yourself against Quishing comes down to a few good habits:  

  • Don’t just be suspicious of QR codes in emails – actively avoid them! Or use a QR scanner that displays the link before it activates and then check it as you would for a suspicious link in an email.  

A code that arrives by email, especially one that asks you to log in or pay, deserves the same caution as any strange link. The NCSC’s advice is to be wary of scanning QR codes inside emails, even if you believe codes in places like restaurants are usually fine  

  • Check the web address before you act. When you scan a code, your phone shows the link before it opens. Read it. If the address is not the official site you expected, close it 
  • Go direct instead of scanning. If an email says your Microsoft account needs attention, open your browser and type the address yourself, or use a bookmark. Do this with any supplier – always use the official site. Don’t rely on the code to take you to the right place  
  • Watch for urgency. Messages that threaten account closure or a fine “within 24 hours” are trying to rush you past your own judgment. That pressure is itself a warning sign  
  • Use phishing-resistant MFA. If a scam does capture a password, phishing-resistant multi-factor authentication (a passkey, a hardware key, or number-matching in an authenticator app) makes that password much harder to use. We always set up MFA as standard on all our clients’ Microsoft accounts.  
  • Add content and DNS (Domain Name System) filters. These can be added to mobiles too, to extend the reach of your organisation’s protection. If you’re not sure, ask us to recommend a tool. Ideally, you’re looking for one that combines edge security, an always-on zero trust VPN, DNS filtering and content filtering, as well as managed extended detection and repair for endpoints, including phones and tablets. The good news is that most are surprisingly affordable.  
  • Check physical codes for tampering. Before scanning a code on a parking meter or payment terminal, look for a sticker placed over the original  
  • Tell your team. Most people have never been warned about QR code scams. Send your staff a short message with a real example so they know what to watch for – and sign up for security awareness training with simulated phishing attacks!  

What to do if someone already scanned one  

If you or someone on your team scanned a QR code and entered details on the page that opened:  

  • Change the password for that account right away and make sure you’re signed out of any other sessions 
  • Change the password on any other account that used the same password  
  • Make sure you’re signed out of any other sessions for that account.  
  • Confirm multi-factor authentication is turned on for the account.  
  • Tell whoever manages your IT, so they can check for unusual sign-ins as well as check for added apps that might allow fraudsters to log back in, create forwarding rules, tamper with your login settings, or enable other methods of log in that bypass MFA. 
  • If card or banking details were entered, call the bank and watch the account closely.  

Acting quickly limits what an attacker can do with the details they captured.  

Frequently asked questions 

Are QR codes safe to use? 

Most QR codes are safe. A code on a restaurant table or an official payment terminal is usually fine. The risk comes from codes sent in unexpected emails or texts, and from stickers placed over real codes in public. Treat those with caution.  

Remember – most QR codes have the actual web address printed underneath. It only takes a second to type it in and you can check it before you start. 

Can antivirus or email filters stop QR code scams?  

Not always. Many email security tools scan the text of a message for bad links, and a QR code hides its link inside an image, so it can slip through.  

Some products now scan images for codes, but you shouldn’t assume the scam will be caught before it reaches you.  

Adding DNS and content filtering to your mobile devices as well as laptops – especially if you use them for work provides some protection. 

Why is a QR code in an email more dangerous than a normal link?  

A written link can be inspected by your email security and opened on a managed work device. A QR code hides the link from those tools and pushes you to scan with your phone, which usually has far less protection than your work device.  

What should I do if I scanned a scam QR code but didn’t enter anything?  

If you closed the page without typing anything, the risk is low. Close it, don’t go back, and let your IT contact know so they can keep an eye out. If you did enter a password or payment details, follow the recovery steps above.  

If you’d like some support 

If you’d like some support, just get in touch or schedule a consultation to review your current controls and staff training. We can help you identify where your most crucial gaps are and show you what you can do to minimise the risks.  

Ensure you ramp up your organisation’s security posture to limit the impact when errors occur, as well as training your staff, to keep mistakes from occurring in the first place! 

We’re here to help 

You can reach us on 01223 903 800, [email protected], or book a time for a call online with our top techs at: https://calendly.com/hello-gsl/mtg-25min

 

Basis for article used with permission from The Technology Press.