Article Summary: QR code scams, sometimes called quishing, hides a malicious web link inside a QR code. Because the link is buried in an image instead of written as text, it slips past the email filters that normally catch bad links, and scanning the code usually moves the victim onto a personal phone that sits outside the company’s security. Microsoft reported a 146% rise in QR code phishing during the first quarter of 2026.
QR codes are part of normal business now.
You scan them to see a menu, pay for parking, connect to Wi-Fi, or open a shared document.
Attackers know that, and they have started hiding malicious links inside QR codes to get past the security tools that would normally catch a bad link in an email.
The technique has a name, quishing, and it works because a QR code is just an image.
Your email filter reads text, so a link encoded into a QR code can pass straight through. When you scan it, you usually do so on your phone, which sits outside most of the protection your work computer has.
This post covers what a QR code scam is, why it gets past your security, what the common ones look like, and the habits that protect your business.