QR Codes – Sidestepping cyberdefenses

Last updated: 14 August 2026
Scan with Caution
For years, our defences against phishing have focused on the familiar. We scan URLs, filter spam from our inboxes, and train ourselves to spot suspicious links by eye. But attackers keep changing tactics. They keep finding new ways to exploit our trust in everyday technology. Their latest trick? QR code phishing, sometimes called quishing. It targets a device most phishing tools ignore: the phone in your pocket.
The Unseen Threat: QR Code Phishing
A recent incident brought to light a particularly sophisticated phishing threat, cloaked behind the seemingly innocuous facade of a QR code. This malicious campaign began with an email-delivered document purporting to be an unpaid invoice, a lure chosen precisely because invoices carry a sense of urgency and routine that discourages close scrutiny. To access supposedly redacted information, the document prompted users to scan a QR code.

Unlike URLs, QR codes are often given a free pass by traditional phishing protection systems, which are not designed to scan a code’s embedded content for threats. This oversight, combined with the absence of a visible URL, means users may never question the legitimacy of the code. There is nothing to hover over, nothing to read, and nothing that looks obviously wrong, which makes the scam far more difficult to detect at first glance.
Unfolding the Scam
Those who scanned the QR code were redirected to a Cloudflare verification page, a common tactic used by threat actors to thwart both dynamic and static analysis by security systems. This step requires human interaction, and that single requirement does a great deal of work for the attacker. Automated crawlers and sandboxes cannot easily click through it, so the phishing site remains under the radar of automated defences for longer than it otherwise would.

Upon navigating the Cloudflare hurdle, users encountered a fake Microsoft login page asking them to enter their credentials. This is a classic phishing move designed to steal sensitive information. Because the page mimicked a service the victim already trusted and used daily, many would enter their username and password without a second thought, handing the attacker exactly what they were after.

The Takeaway
This incident is a stark reminder of the continuous need for vigilance, and of the importance of extending security protections to all endpoints. Attackers are increasingly exploiting the often lacklustre protection on mobile devices, spotting a gap they can exploit. Desktops and laptops tend to sit behind layered corporate defences, whereas phones frequently do not, and that imbalance is precisely what this campaign was built to exploit. QR codes, offering convenience and efficiency, have become a double-edged sword, providing cybercriminals with new opportunities to launch their attacks.
Corrata’s security solution immediately identified the threat posed by the newly registered domain. Our Zero Day Protection swiftly blocked the suspicious domain and alerted the administrators. Upon further analysis, the domain was reclassified as a phishing site.
The Evolution of QR Code Phishing
The lure in this campaign was a straightforward QR image sitting in a PDF. Attackers have since moved on to constructions built specifically to defeat the scanners that eventually learned to read them. Barracuda documented split QR codes in 2025, where the payload is fragmented across several images or pages so that no single element decodes to anything meaningful, and nested codes concealed inside other visual layers.
More awkward still are Unicode block-character constructions, which render a scannable pattern out of text characters rather than an image, so there is no picture for an image-based decoder to find in the first place.
Others simply change the container: one campaign in early 2026 hid encoded phishing URLs inside BMP attachments, which passed SPF, DKIM and DMARC and reached inboxes with the payload structurally invisible to every text-based control in the delivery path.
The pattern holds across all of them. Whatever the gateway has learned to parse, the next iteration puts the URL somewhere it is not looking, and the phone camera decodes it regardless.
How to Protect Yourself from QR Code Phishing
Defending against quishing does not require exotic tools so much as a shift in habits and a widening of coverage to the mobile device. A few practical measures go a long way.
Treat unexpected QR codes with the same suspicion you would give an unexpected link. If a code arrives in an email, particularly one attached to an invoice, a delivery notice, or a payment request, pause before scanning. Ask whether you were expecting it and whether the sender is who they claim to be.
Preview the destination before you commit. Most modern phone cameras display the underlying URL when they detect a code. Read it carefully, watch for misspelled brand names or odd domains, and do not proceed if anything looks off.
Never enter credentials on a page reached through a scanned code. Legitimate services rarely, if ever, ask you to log in this way. If you genuinely need to access an account, close the page and navigate to the site directly through your browser or app instead.
Enable multi-factor authentication wherever it is offered. Even if an attacker captures your password on a convincing fake login page, a second factor gives you a crucial extra layer of defence that can stop the intrusion in its tracks.
Extend security to mobile. The core lesson of this campaign is that the phone is now a front line. Endpoint protection that inspects the content behind a QR code, rather than merely the visible parts of a message, closes the gap that these attacks depend on.
Stay ahead of Cybercriminals
Corrata’s Mobile Security solution continues to monitor and defend against the ever-changing tactics of cybercriminals. By understanding the methods that attackers use, and by implementing advanced security measures across every device rather than only the traditional ones, we can stay one step ahead.
Frequently asked questions
What is QR code phishing?
QR code phishing, also called quishing, hides a malicious link inside a QR code instead of writing it out as a URL. The victim scans the code, usually with a phone, and is taken to a page built to steal credentials. In the campaign described above, the code arrived in an email attachment presented as an unpaid invoice, with the scan framed as the way to view redacted information.
Why do QR codes get past email security?
Email filters and URL scanners are built to inspect text-based links. A QR code is an image, so unless the security tool decodes the content embedded in it, there is nothing for the filter to check. The message passes through carrying what looks like an ordinary graphic. That gap is the reason attackers use codes in place of links.
Why do attackers want the victim to scan on a phone?
Scanning moves the victim off the managed laptop and onto a device that often has weaker protection. Mobile browsers also show little or none of the address bar, so the destination domain is hard to check. The victim has no visible URL to question before entering their password.
What should someone do if they have already scanned a suspicious QR code?
If no details were entered, close the page and report the message to IT or the security team. If credentials were entered, change the password straight away, sign out of active sessions and tell the security team the same day, because attackers move quickly once a password is captured. Report it even if you are unsure, so the domain can be blocked for everyone else.
How can organisations defend against QR code phishing?
Protection has to sit on the device that does the scanning, not only on the mail gateway. Inspecting mobile traffic allows newly registered and uncategorised domains to be blocked at the point the victim taps through, and administrators to be alerted. In the incident above, Corrata blocked the domain on the basis that it was newly registered, before it was reclassified as a phishing site.
