The habit that used to work
You have learned not to click a link you were not expecting. Hover over it, see where it really goes, and if it looks wrong, delete the message. That habit has protected your business more than once.
The scam has moved to a place that habit cannot reach. It arrives as a QR code.
A QR code is a link in a picture
That is the whole trick. When a bad link sits in an email as text, your mail filter reads it, and so do you. A QR code is an image. There is no text for the filter to inspect, and nothing for you to hover over. Your phone reads the square as a web address and opens the page. That page is usually a fake sign-in screen dressed up to look like Microsoft 365 or your bank. A phone screen is the last place you will study the real web address.
The code also moves the click off your work computer and onto a personal phone. The protections you pay for on the laptop do not follow that phone.
This is not a small problem anymore
Microsoft's threat researchers called QR code phishing the fastest-growing email attack of the first quarter of 2026, more than doubling between January and March (Microsoft, Q1 2026 email threat landscape). ESET, a security vendor, found malicious QR codes inside 11 percent of all phishing email in the first half of 2026. This is not a fringe trick anymore.
Where it shows up in a business like yours
A few shapes cover almost all of it.
The fake invoice. A message about a bill, a payment update, or a remittance, with a code to confirm your details. Finance and office staff are the targets.
The fake IT notice. Your Microsoft password expires today, scan to keep your account active. The code opens a page that copies your sign-in screen.
The document. A PDF that looks like a shared file, with the code printed inside it. The code rides along even when a filter would have caught a link.
The sticker in the real world. The FTC warned in September 2026 that scammers were covering the real QR codes on parking meters with their own. You scan to pay, and the money goes somewhere else. Same trick, stuck to something you already trust.
The one rule
Never scan a code to log in. Not from an email, not from a text, not from a paper sign taped to a wall.
Your bank and Microsoft will not ask you to scan a square to sign in or confirm a password. If a message tells you to, stop. Open the app yourself, or type the web address you already know. If it claims to be from someone you work with, call them at a number you already have. Do not call the number in the message.
What to put in place
You do not need a new product. You need a few things set correctly.
Your email security should look inside images and attachments, not just links. Many tools can decode a QR code and check where it leads, but the setting has to be on. Ask whoever manages your email whether it is running, and ask them to show you.
Keep multi-factor authentication on the accounts that matter, and use a stronger, phishing-resistant sign-in where you can. If a scanned code hands someone your password, a second strong factor is what keeps it from being enough.
Confirm big payments out loud. Any change to bank details, a new vendor, or a large transfer deserves one phone call to a number you already trust. That beats any filter.
The question worth asking first
Do not start by buying something. Start by asking what would happen if one person scanned a bad code on a busy Tuesday. Who would notice, and how fast?
That is a question worth an hour with someone who will tell you the truth, even when the answer is that you are fine.