Claude is having a major outage. Status board · Discuss Claude

The QR code is just a link you cannot read

You know not to click a strange link in an email. Your mail filter knows it too, and so does your security awareness training. Now picture the same link, drawn as a black and white square, printed on a sticker. No filter reads it. No hover shows you where it goes. You lift your phone and the phone does the clicking for you.

That is quishing: phishing with a QR code. It works because it moves the attack from a place that is defended, your inbox, to a place that is not, your phone camera.

Why a square is a good disguise

A QR code is nothing magical. It is a web address, or some other text, written in a pattern a camera can read. The address behind it can be anything, and a person looking at the square has no way to tell a real one from a fake one.

  • Email filters struggle with it. A message whose only content is a picture of a square has no link for a scanner to follow. Attackers also split the picture into pieces or hide it in an attachment so it is harder to spot.
  • It jumps devices. The email arrives on the work laptop, which is protected. The QR code asks you to scan with your personal phone, which is usually not. The attacker has just walked around your security stack.
  • It looks official. Restaurants, car parks, shops and delivery firms really do use QR codes, so scanning one feels normal. A sticker placed over a real parking meter code is a common trick; the page it opens asks for your card details “to pay”.
  • The page that loads is a normal sign-in. The usual target is a copy of the Microsoft 365 or Google sign-in, ready to take the password and, increasingly, to relay the MFA code as well.

The rule: a QR code is a link from someone you have not verified. Treat it exactly the way you treat a link in an unexpected email, because that is what it is.

Five seconds before you open the page

  1. Read the address your phone shows. Most phone cameras display the web address before opening it. Read it. A misspelled brand, a long string of random words or an address that has nothing to do with the sender is your answer.
  2. Look at the sticker. A code stuck on top of another one, a glossy square on a worn sign, or a code that peels at the corner has been added by someone. Real businesses rarely hide their payment code under a sticker.
  3. Do not sign in from a code that arrived in a message. If an email or text says “scan to keep your account active” or “re-enrol your MFA”, close it. Open the app or type the site address yourself.
  4. Pay by another route when you can. At a meter or a car park, use the operator’s own app or the number on the machine. If a payment page asks for card details on a page you reached by QR code, stop and use another way.
  5. Never enter a password or an MFA code on a page you reached from a QR code. If you already did, change the password now and tell your IT team. See The Patch Panel if you want a second pair of eyes first.

For the people who run the tenant

  • Teach it with a real example. Add a QR code to your next phishing exercise. Most people have never been tested on one and it shows the gap quickly.
  • Check what your email protection does with images. Some products can read a QR code inside an image or PDF and score the address behind it. Find out whether yours does, and whether it is switched on.
  • Protect the second device. If staff scan with personal phones, the sign-in page they reach is outside your Conditional Access. Move the people who matter to phishing-resistant MFA (passkeys, FIDO2 keys), which a fake page cannot relay.
  • Watch where you place your own codes. A QR code on posters, badges or print material should point to an address on your own domain, and should be checked now and then to make sure nothing has been stuck over it.
  • Give people one place to report. A shared “report phishing” button or mailbox, with a thank-you that comes back quickly, turns a nervous scan into a warning for everyone else.

The habit fits on a sticky note: read the address, ignore codes that come to you, and never sign in from a square. A QR code is a convenience, not a credential.

Seen a suspicious sticker or a strange scan-to-pay page? Tell the rest of us in The Patch Panel. A photo of the sticker is worth a thousand warnings.

About KEH-TECH