Midyear Technology Checkup for Small BusinessesThe Midyear Technology Checkup Your Business Keeps Postponing
Does Your Business Have Too Many Software Apps?Your Business Has Too Many Apps. Nobody Wants to Admit It.
2024's Most Shocking Data Breaches and How to Protect Your Business

That QR Code Might Be the Most Dangerous Thing in the Room

QR codes are everywhere now.

Restaurants use them for menus. Parking garages use them for payments. Conferences put them on badges and brochures. Businesses use them for invoices, sign-ins, surveys, document sharing, and even employee authentication.

Most of us have been trained to scan first and think later.

That is exactly what attackers are counting on.

QR code phishing, sometimes called quishing, has become one of the fastest-growing phishing methods. Microsoft reported that QR code phishing more than doubled during the first quarter of 2026, making it the fastest-growing email attack vector during that period.

The problem is simple.

A QR code hides the destination.

You cannot look at the squares and know where they lead. You scan, a page opens, and if it looks familiar enough, you keep going.

That tiny moment of trust is what scammers are trying to exploit.

Why QR Code Scams Work So Well

Traditional phishing emails usually contain a link.

Employees have learned to hover over links, check the domain, and look for suspicious addresses.

QR codes remove that visual clue.

The employee sees a graphic instead of a URL.

That changes the behavior.

They pull out a phone, scan the code, and continue the process on a mobile device. At that point, the scam may also be moving outside some of the security protections that monitor activity on the employee’s business computer.

The FTC has warned that malicious QR codes can send people to fake websites designed to steal login credentials, financial information, or other sensitive data. Some malicious destinations may also attempt to deliver malware.

The QR code itself is not dangerous.

The destination can be.

The Parking Meter Problem

Imagine you park downtown for a client meeting.

There is a QR code on the meter that says:

SCAN TO PAY

You scan it.

The page looks like the city’s parking website. You enter your payment information, submit the transaction, and head to the meeting.

The payment never went to the city.

Someone placed a fraudulent QR sticker over the legitimate code.

Nothing about the interaction felt unusual.

That is what makes physical QR scams effective.

They can appear on:

  • Parking meters
  • Restaurant tables
  • Event posters
  • Flyers
  • Business cards
  • Building entrances
  • Package inserts
  • Public charging stations
  • Conference materials

A scammer does not have to hack the parking meter.

Sometimes they just need a printer and a sticker.

The Guide to Better IT Service, Security, and Compliance

Get a clear, practical framework for evaluating IT providers. Learn the warning signs, security essentials, and key questions to ask before choosing a Managed IT partner.

The QR Code in Your Email Is Different, but the Trick Is the Same

QR phishing is also showing up inside business emails.

An employee might receive a message saying:

  • Your Microsoft 365 password is expiring
  • Your voicemail is ready
  • A secure document is waiting
  • Your account needs verification
  • A payment requires approval
  • Your benefits enrollment needs attention

Instead of a clickable button, the email contains a QR code.

The employee scans it with a phone.

The code opens a sign-in page that looks like Microsoft, Google, DocuSign, or another familiar service.

They enter their credentials.

Now the attacker has them.

Microsoft’s 2026 email threat research found QR code phishing growing rapidly because attackers are adapting their techniques as traditional phishing defenses improve.

Your Phone Makes the Scam Harder to Inspect

Phones are convenient.

They are also not ideal for investigating suspicious websites.

On a desktop computer, you can easily inspect the full URL, compare browser tabs, or ask someone nearby to take a look.

On a phone, the address bar may be shortened or partially hidden. The screen is smaller. You may be standing in a parking lot, walking through an airport, or between meetings.

You are not conducting a security review.

You are trying to get something done.

That is the environment scammers want.

Convenience creates speed.

Speed reduces scrutiny.

The Fake Login Page Can Look Completely Normal

One of the biggest misconceptions about phishing is that the fake website will look fake.

Modern phishing pages can closely imitate legitimate login screens.

A fraudulent Microsoft login page may contain:

  • The Microsoft logo
  • Familiar colors
  • The normal username field
  • A password prompt
  • Company branding
  • A convincing error message
  • A realistic multifactor authentication workflow

The page does not need to be perfect.

It only needs to look believable for the few seconds the employee interacts with it.

That is why CISA recommends avoiding links or contact information contained in suspicious messages and instead navigating to a trusted site through a known method.

The same principle applies to QR codes.

QR Codes Can Also Exploit Familiarity

Think about how often your employees scan QR codes without hesitation.

At lunch.

At trade shows.

In airports.

On equipment.

During software setup.

For multifactor authentication.

To connect to Wi-Fi.

To download an app.

QR codes have become normal enough that the act of scanning one rarely feels risky.

Attackers benefit from that familiarity.

They do not have to convince the employee that scanning QR codes is safe.

We already did that ourselves.

Five Rules for Safer QR Code Use

You do not need to ban QR codes.

You just need to stop treating every QR code as automatically trustworthy.

1. Preview the destination before opening it

Most modern phones display the web address before opening a scanned QR code.

Read it.

Look for misspellings, strange domains, extra words, or an address that does not match the organization you expected.

If the destination looks questionable, do not continue.

2. Do not use a QR code to access a site you already know

If the QR code supposedly takes you to Microsoft, your bank, a parking provider, or another service you already use, open the official app or type the known address yourself.

The extra few seconds remove the QR code from the trust equation.

3. Be suspicious of QR codes asking for credentials

A QR code that leads directly to a login page deserves additional scrutiny.

Ask yourself:

Did I expect this?

Did I initiate this?

Why am I being asked to sign in?

If the answer is unclear, stop.

4. Inspect physical QR codes for tampering

Before scanning a code on a parking meter, poster, kiosk, or sign, look closely.

Does it appear to be a sticker placed over another code?

Does the printing style look different from the rest of the sign?

Does anything appear peeled, layered, or recently added?

If so, use another payment method or locate the organization’s official website.

5. Treat unexpected QR codes like unexpected links

An unexpected QR code in an email or text should receive the same skepticism as an unexpected hyperlink.

Do not assume it is safer simply because there is no visible URL.

What Businesses Should Teach Employees

Security awareness training needs to catch up with how people actually work.

Telling employees to avoid suspicious links is no longer enough.

They should also understand:

  • QR codes can hide malicious links
  • A familiar logo does not prove a website is legitimate
  • QR codes received unexpectedly should be treated cautiously
  • Login requests should be verified independently
  • Payment QR codes deserve extra scrutiny
  • Suspicious activity should be reported quickly

The goal is not to make employees afraid to scan anything.

It is to make scanning intentional instead of automatic.

A Simple Business QR Code Policy

You do not need a 12-page policy.

Start with four rules:

  1. Never scan an unexpected QR code to log into a business account.
  2. Never approve a payment solely through a QR code received by email or text.
  3. Use official apps or known websites whenever possible.
  4. Report suspicious QR codes or login pages to IT.

Simple rules are easier to remember when someone is moving quickly.

What If Someone Already Scanned One?

Scanning a QR code alone does not automatically mean an account is compromised.

What happened afterward matters.

If an employee entered credentials, approved MFA, downloaded something, or submitted financial information, report the incident immediately.

The response may include:

  • Changing the affected password
  • Revoking active sessions
  • Reviewing account login activity
  • Checking for unknown MFA methods
  • Inspecting the device
  • Reviewing email rules and forwarding settings
  • Alerting financial institutions if payment information was entered

Fast reporting matters.

Employees should never hide a suspicious click because they are embarrassed.

The sooner IT knows, the more options there are.

A Quick QR Code Reality Check

Ask your team:

  • Would employees hesitate before scanning an unexpected QR code?
  • Do they know how to preview the destination?
  • Would they enter their Microsoft 365 password after scanning one?
  • Do they know how to report a suspicious QR code?
  • Are QR codes used internally for authentication or device setup?
  • Does your security training specifically cover QR phishing?

If you are not sure how employees would answer, it is worth addressing.

The Takeaway

QR codes became popular because they remove friction.

Point your camera. Tap. Done.

Unfortunately, removing friction also removes some of the moments when people normally stop and evaluate what they are clicking.

Attackers understand that.

Microsoft’s threat data shows QR phishing growing rapidly in 2026, but the solution is not complicated.

Slow down.

Preview the destination.

Use official apps and websites when possible.

And never assume that a square full of black dots is more trustworthy than a regular link.

Sometimes the most dangerous thing in the room is not the computer.

It is the little QR code sitting next to it.

Make Everyday Technology Safer

Capital Network Solutions helps businesses strengthen cybersecurity without making everyday work unnecessarily complicated.

If you are unsure whether your employees, email systems, and security controls are prepared for newer phishing techniques like malicious QR codes, a short discovery call can help identify practical ways to reduce exposure.

No scare tactics. No unnecessary complexity. Just a straightforward conversation about protecting your business from threats designed to look completely normal.

Let's Talk IT! (916) 866-9969

Capital Network Solutions, Inc. Logo

Need IT Guidance?

Talk with a CNS Advisor

Get practical help with technology, security and compliance questions from the CNS team.

  • Managed IT & Help Desk

  • Cybersecurity & Risk Reviews

  • Microsoft 365 & Cloud

  • Compliance Guidance

or call (916) 866-9969

  • 30+ years serving California businesses