QR codes are part of normal business now — you scan them to see a menu, pay for parking, join Wi-Fi, or open a shared document. Attackers know that, and they’ve started hiding harmful links inside QR codes to slip past the security tools that would normally catch a harmful link in an email. The technique even has a name: quishing. And it’s climbing fast — Microsoft reported a 146% rise in QR code phishing across the first quarter of 2026.
It works because a QR code is just an image. Your email filter reads text, so a link encoded into a QR code can pass straight through. And when you scan it, you usually do so on your phone — which sits outside most of the protection your work computer has. Here’s what a QR code scam is, why it gets past your security, what the common ones look like, and the habits that protect your business.
It’s a phishing attack that uses a QR code in place of a written link. Instead of a clickable URL your email security can inspect, the attacker encodes the web address into a square image. You scan it with your phone camera, the phone opens the link, and you land on a page built to capture your sign-in or payment details — the same kind of fake you’d see in any phishing attack, a sign-in screen mimicking Microsoft 365 or a payment form copying your bank. The QR code is only the delivery method.

Two things make them effective. First, the link is hidden inside an image. Most email security scans the text of a message for known harmful links; a QR code is a picture, so the link inside isn’t text the filter can read. The UK’s National Cyber Security Centre notes that not all phishing-detection tools scan images — which is exactly why criminals started using QR codes. Second, scanning moves you onto your phone. Your work computer probably has web filtering, endpoint protection, and DNS controls that block known risky sites. Your personal phone usually has none of that. The moment you scan, you step outside the protection your business pays for — often without realizing it.
Climbing fast. In its Q1 2026 email-threat report, Microsoft said it detected around 8.3 billion email-based phishing threats in three months, with QR code phishing rising 146% across the quarter — from 7.6 million attacks in January to 18.7 million in March, its highest monthly volume in at least a year. Most arrived as PDF attachments (growing from 65% to 70% of QR attacks): the code sits inside a PDF, the PDF is attached to an email, and the whole thing looks like an ordinary document until someone scans it.
Protecting against quishing comes down to a few habits: be suspicious of QR codes in emails, especially ones asking you to log in or pay; check the web address your phone previews before it opens, and close it if it isn’t the official site; go direct instead of scanning — if an email says your Microsoft account needs attention, type the address yourself or use a bookmark; watch for urgency, since “within 24 hours” pressure is itself a warning sign; use phishing-resistant MFA (a passkey, hardware key, or number-matching authenticator) so a captured password is much harder to use; check physical codes for a sticker placed over the original; and tell your team — most people have never been warned, so send staff a short message with a real example.
If details were entered on the page that opened: change that account’s password right away (and any account sharing it), confirm MFA is on, tell whoever manages your IT so they can check for unusual sign-ins, and if card or banking details were entered, call the bank and watch the account closely. Acting quickly limits what an attacker can do.
Most are. A code on a restaurant table or official payment terminal is usually fine. The risk is codes sent in unexpected emails or texts, and stickers placed over real codes in public.
Phishing that uses a QR code instead of a written link. The goal is the same as any phishing attack — get you onto a counterfeit page that captures your login or payment info.
Not always. Many tools scan text for bad links, and a QR code hides its link in an image. Some products now scan images for codes, but don’t assume the scam will be caught before it reaches you.
A written link can be inspected by your email security and opened on a managed work computer. A QR code hides the link and pushes you to scan with your phone, which usually has far less protection.
If you closed the page without typing, the risk is low. Close it, don’t go back, and tell your IT contact. If you did enter a password or payment details, follow the recovery steps above.
Staff awareness is the part most businesses skip. Our cybersecurity services for Toronto businesses include phishing and quishing training, and we provide IT support across the GTA if you’d like someone to run the session in person.
Prepared by the EB Solution team — managed IT and cybersecurity for businesses across the Greater Toronto Area. Want a short staff briefing on QR scams tailored to your team? We’ll help you run one.