How to Spot a QR Code Scam Before It Costs You

TL;DR: QR code scams, also called quishing, hide a bad link inside an image so your email filter can’t read it. Scanning moves the person onto a personal phone that sits outside your company’s protection. Microsoft tracked a 146% jump in QR code phishing in early 2026. Protecting your business takes email security that inspects attachments, phishing-resistant MFA, and a team trained to pause before they scan.

You probably scanned a QR code this week without thinking twice. A parking lot downtown, a menu at a restaurant, a code inside a vendor invoice. QR code scams work because scanning has become that automatic.

Attackers noticed. They started hiding malicious links inside QR codes for one simple reason: a code is just a picture. Your email security reads text, so a link buried in an image walks right past the filter you pay for every month. Then you scan with your phone, which means you just stepped off your work computer and onto a device with almost none of the protection your business set up.

We see this pattern constantly with businesses across Louisville. The email looks routine. The code looks harmless. The login page on the other end is a copy of Microsoft 365, and the password your employee types goes straight to a stranger.

Here’s what these scams look like, why they work, and what stops them.

What Is a QR Code Scam?

A QR code scam is a phishing attack that swaps a written link for a square image. The attacker encodes a fake login page or payment form into the code. You scan it with your phone, the page opens, and whatever you type goes straight to the attacker.

The technique has a name: quishing, a mashup of “QR” and “phishing.”

The code isn’t really the attack. It’s the wrapper. The page on the other side is the same fake you’d see in any phishing email, usually a Microsoft 365 sign-in screen or a payment form dressed up like your bank.

Why QR Code Scams Slip Past Your Email Security

Two things make this work, and neither is a flaw in your judgment.

First, the link hides inside a picture. Most email filters scan message text for known bad web addresses, and a QR code gives them no text to read. The UK’s National Cyber Security Centre has pointed out that plenty of phishing detection tools don’t inspect images at all, which is exactly why criminals moved to codes.

Second, scanning moves the person to a different device. Your work computer probably has web filtering, endpoint protection, and DNS controls that block known bad sites. A personal phone has none of that.

Strong email and spam protection still matters. It just can’t be your only layer, because this attack is built to finish somewhere your email security can’t reach.

How Common Are QR Code Scams Right Now?

They’re the fastest-growing email attack Microsoft tracks. In Microsoft’s Q1 2026 email threat report, QR code phishing climbed from 7.6 million attacks in January to 18.7 million in March, a 146% increase in a single quarter. Most arrived inside PDF attachments.

That PDF detail is worth a pause. The share of QR attacks delivered by PDF grew from 65% in January to 70% by March. The code sits inside a document, the document is attached to an email, and the whole thing looks like an ordinary invoice until somebody scans it.

The FBI’s 2025 Internet Crime Report logged more than one million complaints and $20.8 billion in losses, with business email compromise alone accounting for $3.04 billion. Most of those cases start with one stolen password.

The QR Code Scams We See Most Often

These are the patterns showing up in real inboxes.

  • The MFA re-enrollment notice. An email that looks like it came from Microsoft or your IT provider says you need to scan a code to keep your account active. The code leads to a fake sign-in page.
  • The shared document. A colleague or client “shared a file.” Scan to view. The page asks you to log in first.
  • The vendor invoice. A PDF invoice includes a code to pay faster. The payment routes to the attacker instead of your supplier.
  • The missed delivery. A text about a package asks you to scan and reschedule. The Federal Trade Commission has warned about this one directly. Elizabethtown police flagged a Kentucky version last year involving unsolicited Amazon packages with codes inside.
  • The sticker over the real code. Attackers print their own codes and place them over legitimate ones on meters, terminals, and posters. Toronto police reported a driver who expected a $7 parking charge and got hit for nearly $2,000.

That last one hits close to home. Plenty of Louisville lots switched to scan-to-pay signage in recent years, and most drivers have no idea what the real code should look like.

How Can You Protect Your Business From QR Code Scams?

Treat any QR code that arrives by email or text the way you’d treat a link from a stranger. Go directly to the website instead of scanning, read the address before you enter anything, turn on phishing-resistant MFA, and make sure your team knows this attack exists.

Here’s the split between what your people do and what your business puts in place.

Habits for your team

  • Don’t scan codes that arrive by email or text, especially ones asking you to log in or pay.
  • Read the web address your phone previews before the page opens. If it isn’t the official site, close it.
  • Type the address yourself, or use a bookmark, when a message says your account needs attention.
  • Slow down when a message threatens account closure or a fine within 24 hours. That pressure is the tell.
  • Check physical codes for a sticker over the original. Peeling edges and mismatched branding are warning signs.

Controls for your business

  • Email security that inspects attachments and images, not just message text.
  • Phishing-resistant MFA such as passkeys, hardware keys, or number matching in an authenticator app. If a password does get captured, it becomes much harder to use.
  • Protection that follows the user onto mobile devices, so a phone isn’t a blind spot.
  • Layered cybersecurity protection that assumes something will get through and catches it at the next step.

What Should You Do If Someone Already Scanned One?

Move fast. Change the password on that account and on any other account using the same password. Confirm MFA is turned on. Tell whoever manages your IT so they can review sign-in activity. If card or bank details were entered, call the bank right away.

The part most owners underestimate is culture. Employees hide mistakes when they expect to get chewed out, and a hidden mistake is what turns one compromised account into a company-wide problem.

You also need someone watching. Managed IT services in Louisville should include reviewing sign-in logs, spotting logins from odd locations, and shutting down a compromised session before it spreads.

Why QR Codes Belong in Your Next Training Cycle

Most employees have never been warned about this attack. They’ve heard “don’t click strange links” a hundred times. Nobody told them a picture counts as a link.

That gap is cheap to close. Ongoing security awareness training with real QR examples turns your staff from the softest target into the layer that catches what the filters miss. If your current provider hasn’t mentioned quishing to you this year, our guide on how to choose an IT provider covers what to ask.

The Habit That Protects You Most

Three things to take away. The QR code is only a wrapper, so judge the message and not the square. Your phone is the weak point, because it sits outside almost everything your business pays to protect. And going direct beats scanning every time. None of that requires new technology, just a team that pauses and security layers that assume someone eventually won’t.

If you aren’t sure whether your email security would catch a QR code buried in a PDF, that’s worth answering before an attacker answers it for you. Schedule an intro call and we’ll walk through where your gaps are.

Frequently Asked Questions

Are QR codes safe to use?

Most are. A code printed on a restaurant menu or built into an official payment terminal is usually fine. The risk comes from codes that arrive in unexpected emails and texts, and from stickers placed over real codes in public. Treat those two situations with caution.

What is quishing?

Quishing is phishing that uses a QR code instead of a written link. The word combines “QR” and “phishing.” The goal is the same as any phishing attack: get you onto a fake page that captures your login or payment details.

Can antivirus or email filters stop QR code scams?

Not reliably. Many email security tools scan message text for bad links, and a QR code hides its link inside an image. Some products now inspect images and attachments for codes, but you shouldn’t assume the scam gets caught before it reaches an inbox.

Why is a QR code in an email more dangerous than a regular link?

A written link can be inspected by your email security and opened on a managed work computer. A QR code hides the address from those tools and pushes the person to scan with a phone, which usually has far less protection than a company device.

What should I do if I scanned a scam QR code but didn’t enter anything?

If you closed the page without typing anything, your risk is low. Close it, don’t return to it, and tell your IT contact so they can watch for unusual activity. If you did enter a password or payment details, change that password immediately and call your bank if card information was involved.

Not Sure Where Your Gaps Are?

Most businesses learn their email security missed something the hard way. A short conversation is a better way to find out. Reach out to our team and we’ll review how your current setup handles QR codes, attachments, and the phishing attempts that get past standard filters.