22 August 2026
QR Code Scams: What They Are and How to Protect Your Business
By Tanya Wetson-Catt
Photo by Pixabay on Pexels
QR codes are just part of doing business now. You scan one to see a menu, pay for parking, join the office Wi-Fi, or open a document a colleague has shared.
Scammers have noticed the same thing, and they've started hiding malicious links inside QR codes specifically because it gets them past the security tools that would normally catch a bad link sitting in an email.
The technique has a name, quishing, and here at Atema we've started seeing it come up more often in conversations with clients across Gloucestershire and the wider South West, usually as "is this email legitimate?" rather than as a full-blown incident. That's the right instinct. A QR code is just an image, so your email filter can't read the link hidden inside it the way it can read a normal web address. Scan it, and you're usually doing so on your phone, away from whatever protection your work computer has.
This post covers what a QR code scam actually is, why it slips past your existing defences, what the common versions look like, and the habits that keep your business safe.
What is a QR code scam?
A QR code scam is a phishing attack that swaps a written link for a QR code. Instead of a clickable web address your email security can inspect, the attacker encodes the destination into a square image.
You scan it with your phone's camera, your phone opens the link, and you land on a page built to steal your login details or your card information. The page itself is the same kind of fake you'd see in any phishing attempt, a login screen dressed up as Microsoft 365, or a payment form copying your bank. The QR code is only the delivery method that gets you there.
Why QR code scams get past your security
Two things make this technique effective.
First, the link is hidden inside a picture. Most email security tools scan the text of a message for known bad links, but a QR code is an image, not text, so the filter often has nothing to read. The NCSC's own guidance on QR codes points out that not every phishing-detection tool scans images, which is exactly why criminals started disguising links this way in the first place.
Second, scanning a code moves you onto your phone. Your work computer likely has web filtering, endpoint protection and DNS controls that block known bad sites. Your personal phone usually has none of that, so the moment you scan, you've stepped outside the protection your business pays for, often without noticing it happened. A managed, company-issued mobile closes that particular gap, since it's set up and looked after the same way as the rest of the business's kit, rather than left as a personal device doing double duty.
How common are QR code scams?
The volume is climbing quickly. In its report on the email threat landscape for the first quarter of 2026, Microsoft said it detected around 8.3 billion email-based phishing threats across those three months, and that QR code phishing specifically rose 146% over the quarter, from 7.6 million attacks in January to 18.7 million in March, its highest monthly volume in at least a year.
Microsoft also found that most of these attacks arrived as PDF attachments, growing from 65% of QR code attacks in January to 70% in March. The QR code sits inside the PDF, the PDF is attached to an otherwise unremarkable-looking email, and the whole thing reads as a normal document until someone scans it.
What QR code scams look like
These are the versions we'd flag if a client asked us about them:
- A "security" email. A message that looks like it's from Microsoft or your IT provider, asking you to scan a code to re-enrol your multi-factor authentication or keep your account active. The code leads to a fake login page.
- A shared document. An email claims a colleague or client has shared a file, and you need to scan a code to view it. The page asks you to sign in first, and that's where your credentials go.
- A fake invoice. A PDF invoice includes a QR code "to pay faster." The code routes the payment to the attacker instead of the intended supplier.
- A missed delivery notice. A text or email about a missed parcel asks you to scan a code to rebook or pay a small redelivery fee. The NCSC has specific guidance on scam missed-parcel messages impersonating Royal Mail and other couriers, since it's one of the most common versions UK recipients see.
- A sticker in the real world. Attackers print their own QR code stickers and place them over legitimate ones on parking meters, posters and payment terminals. You think you're paying for parking, and instead you're handing your card details to a stranger.
How to protect your business from QR code scams
Protecting yourself against quishing comes down to a handful of habits:
- Be suspicious of QR codes in emails. A code that arrives by email, especially one asking you to log in or pay, deserves the same caution as a strange link. The NCSC's advice is to be wary of QR codes inside emails specifically, even though codes in places like restaurants are usually fine.
- Check the web address before you act. When you scan a code, your phone shows the destination link before it opens anything. Read it. If the address isn't the official site you expected, close it.
- Go direct instead of scanning. If an email claims your Microsoft account needs attention, open your browser and type the address yourself, or use a saved bookmark. Don't rely on the code to take you to the right place.
- Use your phone's built-in scanner. The NCSC recommends scanning with the camera app that comes with your phone rather than a separate scanner app downloaded from an app store, since a personal device with a random scanning app installed carries more risk than one without.
- Watch for urgency. Messages that threaten account closure or a fee "within 24 hours" are trying to rush you past your own judgement. That pressure is itself a warning sign, the same one we'd point clients towards when checking whether an email is really from who it claims to be.
- Use phishing-resistant MFA. If a scam does capture a password, phishing-resistant multi-factor authentication, a passkey, a hardware key, or number-matching in an authenticator app, makes that password far harder to actually use.
- Check physical codes for tampering. Before scanning a code on a parking meter or payment terminal, look for a sticker placed over the original.
- Tell your team. Most people have never been warned about QR code scams specifically. A short message with a real example goes a long way.
What to do if someone already scanned one
If you or someone on your team scanned a QR code and entered details on the page that opened:
- Change the password for that account straight away, along with any other account that reused the same password.
- Confirm multi-factor authentication is switched on for the account.
- Tell whoever manages your IT, so they can check for unusual sign-ins.
- If card or banking details were entered, call the bank immediately and watch the account closely.
Acting quickly limits what an attacker can actually do with what they captured. If it's escalated beyond a single account, our step-by-step guide to what to do during a cyberattack covers the fuller response, including when and how to report it to Report Fraud, the UK's national fraud and cybercrime reporting service.
Quishing is a small, specific trick, but it's the same underlying problem as every other phishing attempt: something arrives that looks routine, and it's designed to get you moving before you've had a chance to think it through. This is exactly the kind of everyday threat our cyber security & compliance work is built to catch, both the technical filtering and the staff awareness side. If you'd like us to look at how prepared your business currently is, book a call with our team and we'll take it from there.
Frequently Asked Questions
Are QR codes safe to use?
Most QR codes are safe. A code on a restaurant table or an official payment terminal is usually fine. The risk comes from codes sent in unexpected emails or texts, and from stickers placed over real codes in public. Treat those with caution.
What is quishing?
Quishing is phishing that uses a QR code instead of a written link. The word combines "QR" and "phishing." The goal is the same as any phishing attack: get you onto a fake page that captures your login or payment information.
Can antivirus or email filters stop QR code scams?
Not always. Many email security tools scan the text of a message for bad links, and a QR code hides its link inside an image, so it can slip through. Some products now scan images for codes, but you shouldn't assume the scam will be caught before it reaches you.
Why is a QR code in an email more dangerous than a normal link?
A written link can be inspected by your email security and opened on a managed work computer. A QR code hides the link from those tools and pushes you to scan with your phone, which usually has far less protection than your work device.
What should I do if I scanned a scam QR code but didn't enter anything?
If you closed the page without typing anything, the risk is low. Close it, don't go back, and let your IT contact know so they can keep an eye out. If you did enter a password or payment details, follow the recovery steps above.
Written by
Tanya Wetson-CattTanya is a co-founder of Atema, running much of what keeps the business itself moving, marketing, finance and admin, while keeping a close eye on the practical, jargon-free advice that goes out to clients.
