The scam hiding in a little black-and-white square

QR codes are everywhere now. Restaurant menus, parking meters, packing slips, even the flyer taped to a light pole outside your office. We got trained during the pandemic to scan first and ask questions never. Scammers noticed.

There is a name for this now. It is called quishing, which is just phishing with a QR code instead of a link. And it is getting popular for one ugly reason: it works. The code looks harmless, your phone opens the page, and by the time you realize something is off, you have already typed your Microsoft 365 password into a fake login screen.

Why QR codes are the perfect disguise

A regular phishing email shows you the link. If you hover over it, you might catch that yourpayroll-portal dot ru is not your actual payroll company. A QR code hides all of that. You cannot hover over a square of pixels. You just point, tap, and go wherever it sends you.

It gets worse. When you scan a code, you usually do it on your phone. Your phone screen is small, the address bar is tiny, and you are probably standing in a parking lot or a lobby. That is exactly the situation where nobody stops to read the URL carefully. Attackers know your guard is down on mobile, which is why they aim there.

How the attack actually plays out

Here is a real pattern we see. An email lands in your inbox looking like it is from Microsoft or DocuSign. It says your account needs re-verification, and to make it easy, there is a QR code to scan with your phone. The email itself has no clickable link for a spam filter to flag, so it sails right through security tools that only scan text and URLs.

You scan it. You land on a page that is a pixel-perfect copy of the Microsoft login. You enter your email and password. Maybe you even approve the MFA prompt because you think you are logging in. Now the attacker has your credentials and a live session. They are reading your email, resetting other passwords, and hunting for the invoice they can reroute to their own bank account.

The physical version is sneakier. Someone prints a fake QR sticker and slaps it over the real one on a parking meter or a payment terminal. You scan to pay for parking and hand your card details straight to a criminal. We have seen this hit parking garages and public chargers across Florida.

What this means for your business

If your team scans codes as part of the workday, and most do, you have an opening a scammer can walk through. Think about how many QR codes touch your operation: vendor invoices, shipping labels, event check-ins, Wi-Fi guest access. Each one is a chance for a fake to slip in.

The damage is not just one person losing a password. One compromised 365 account can send emails to your whole client list, approve fraudulent payments, and sit quietly for weeks reading everything. A single bad scan can turn into a business email compromise, and those cost real money.

How to protect yourself and your team

You do not need fancy tools to shut most of this down. You need a few habits.

  • Slow down before you scan. Ask yourself why this code exists. An email asking you to scan a QR to log in is almost always fake. Real companies just send you to their website.
  • Check the preview URL. Most phone cameras show the web address before they open it. Read it. If the domain looks off, or it is a random string of characters, do not tap.
  • Do not scan codes from unexpected emails. If Microsoft or your bank supposedly needs you to verify something, close the email and go to the site directly by typing the address yourself.
  • Inspect physical codes. If a QR sticker looks like it was placed over another one, or the edges are peeling, walk away. Pay another way.
  • Turn on phishing-resistant MFA. App-based approval helps, but number matching and hardware keys are much harder for an attacker to trick you into approving.
  • Train your people. Your front desk and your accounting team are the ones scanning invoices and check-in codes all day. A ten-minute talk about quishing pays for itself the first time someone pauses instead of scanning.

The bigger picture

QR codes are not going away, and they are genuinely useful. The problem is that we trust them the same way we once trusted a phone call from a number we recognized. That trust is exactly what gets exploited. Treat a QR code like any other link, because that is all it is. A link you cannot see until it is too late.

At YourTech, we build phishing awareness into the way we protect South Florida businesses, from Delray Beach up to West Palm. We run simulated phishing tests, lock down 365 with strong MFA, and make sure your team knows what a trap looks like before they fall in one. Securing systems is half of it. Supporting the people using them is the other half.

Want to know if your team would scan the wrong code? We can find out safely, before a real attacker does. Reach out and let us take a look.