QR Code Security | The Cloud Network
QR Code Security Alert

Beware of unexpected QR codes from unknown senders

QR codes are a convenient tool — but they are also increasingly used by attackers to bypass email security filters and direct victims to malicious websites. You cannot see where a QR code leads until you have already scanned it.

If you received an unexpected QR code in an email or message: Do not scan it. If you have already scanned it and entered any information, contact your IT team immediately.

What is "quishing"?

Quishing is QR code phishing — an attack that uses a QR code in place of a traditional link to send victims to a fraudulent website. It has become significantly more common because it sidesteps most email security tools.

Why attackers use QR codes instead of links

Standard email security tools scan message text and embedded links for known threats. A QR code is just an image — security tools cannot read what is encoded inside it. This means a malicious URL hidden in a QR code passes straight through filters that would have blocked the same link written as text.

Once scanned, the QR code opens a URL on your mobile device, which is often less protected than your work computer and may not have the same security software installed.

QR code attacks increased by over 400% in a single quarter in 2023. Major targets include Microsoft 365 credential theft, fake parcel delivery notifications, and fraudulent invoice payment pages.

Four reasons QR code attacks are so effective

Understanding why these attacks succeed makes it easier to defend against them.

01

Bypasses email link scanning

Security tools read text and URLs. A QR code is an image — the hidden URL inside it is invisible to automated filters.

02

Moves the attack to your phone

Mobile devices typically have fewer security controls than work computers. Scanning shifts the risk to a less-protected device.

03

People trust QR codes

QR codes are associated with restaurants, payments, and event check-ins. Many people scan without thinking, unlike suspicious links.

04

The URL is hidden until scanned

You cannot hover over a QR code to preview the destination the way you can with a hyperlink. The risk is concealed by design.

How attackers deliver malicious QR codes

Quishing attacks arrive through several different channels. These are the most common scenarios you are likely to encounter.

Email with a QR code instead of a link

A message claims your Microsoft 365 account, parcel, or bank account needs attention and asks you to scan a QR code to resolve it. The code leads to a convincing fake login page designed to steal your credentials.

Text message or WhatsApp with a QR code image

A QR code is sent via SMS or a messaging app, often posing as a delivery company, HMRC, or a bank. Because it arrives on your phone, you are already one tap away from scanning it.

PDF attachment containing a QR code

An email with a PDF attached — often posing as an invoice, courier notice, or HR document — where the actual link is presented as a QR code inside the PDF rather than as a clickable URL. Security tools scan the email but often do not inspect PDF contents deeply.

Physical QR codes in public or on printed materials

Stickers placed over legitimate QR codes in car parks, restaurants, or reception areas. Fake posters or printed documents left in public spaces. Scanning these can lead to credential theft or malware downloads — and the physical code appears entirely trustworthy.

What a QR code phishing email looks like

These emails are designed to look official and routine. The QR code replaces the suspicious link — making it harder to spot the threat at a glance.

Email example
From: Microsoft Account Team <noreply@microsoft-accounts-verify.com>
Subject: Your Microsoft account requires verification — action needed

Dear User,

We have detected unusual sign-in activity on your Microsoft account. To protect your account, we have temporarily limited access.

To restore full access, please scan the QR code below using your mobile device's camera and follow the on-screen instructions.

If you did not attempt to sign in, you can ignore this message.

— Microsoft Account Security

Red flags in this email
Sender domain is "microsoft-accounts-verify.com" — not a Microsoft domain
Uses a QR code to hide the malicious URL from email security filters
"Expires in 15 minutes" creates artificial urgency to stop you checking
Generic greeting — real Microsoft alerts include your name and account email
Directs you to use your mobile — bypassing your computer's security tools

What to do if you receive an unexpected QR code

Whether it arrives by email, text, PDF, or printed material — these steps apply any time a QR code appears unexpectedly.

1

Do not scan it

If you were not expecting a QR code from this sender, do not scan it. Unlike a link, you cannot preview where it leads without scanning — which is exactly what makes it dangerous.

2

Check the sender and the context

Does the email address match who it claims to be from? Were you expecting this message? Legitimate services — Microsoft, your bank, HMRC — will not ask you to scan a QR code out of the blue to verify your account.

3

If you must check, preview the URL before visiting it

Most phone camera apps show a preview of the URL before opening it. Read the URL carefully — does it match the legitimate domain of who the email claims to be from? If in doubt, do not proceed.

4

If you have already scanned it and entered details — act immediately

Change your password for any account you may have signed into via the QR code, enable MFA if not already active, and contact your IT team straight away. Speed is critical — attackers can use stolen credentials within minutes.

5

Report it to your IT team

Forward suspicious emails to your IT support team. If you are a managed customer of The Cloud Network, call us immediately on 0345 450 9666 and we will assess and help secure your account.

Physical QR codes in public spaces are also a risk. If a QR code sticker looks like it has been placed over another sticker, or does not look like it belongs on the surface it is on, do not scan it — report it to the venue instead.

Dos and don'ts for QR codes

✓ Do this
  • Preview the URL your camera shows before tapping to open it
  • Ask yourself whether you were expecting a QR code from this source
  • Keep your phone's operating system and apps up to date
  • Report suspicious QR codes in emails to your IT team immediately
  • Use MFA on all accounts so a stolen password alone is not enough
✗ Never do this
  • Scan a QR code from an unexpected or unsolicited email
  • Enter login credentials on a page reached by scanning an unknown QR code
  • Assume a QR code is safe because it arrives in an otherwise professional-looking email
  • Ignore urgency warnings in the message — they are designed to stop you thinking
  • Scan physical QR codes that look tampered with or out of place
The simplest defence is a pause. A QR code that is genuinely important will still be there in five minutes after you have checked the sender, verified the context, and confirmed it is legitimate. No real service will penalise you for taking that time.

Need help or have a concern?

Our team is available to advise on any security concerns, investigate suspicious activity, or help you improve your organisation's security posture.

Please use our contact details below to get in touch