
Quishing is phishing done with a QR code instead of a clickable link, and it's currently one of the fastest-growing scam tactics hitting business inboxes. Microsoft's own threat intelligence team recorded a 146% jump in QR code phishing attacks over the first quarter of 2026 alone, and attackers are increasingly hiding the QR code inside a PDF attachment rather than the email body, specifically to slip past filters that only scan the message text. If a "scan to view your invoice" or "scan to reset your MFA" email has landed in your team's inbox lately, this is why.
What Is Quishing?
Instead of a normal phishing link you can hover over or check before clicking, the scam email contains an image of a QR code. The email might claim to be a delivery notice, a parking fine, a payslip, an MFA re-registration request, or a scanned document waiting for you. Scan the code with your phone, and it takes you to a fake login page built to steal your Microsoft 365 password, or straight to a malware download.
It works because it exploits a gap in how people (and some security tools) think about links. We've all been trained, rightly, to be suspicious of a link in an email. Fewer people apply the same caution to a QR code, because scanning one feels more like using a tool than clicking on something.
Why QR Codes Slip Past Email Filters
A handful of things make quishing genuinely harder to catch than an ordinary phishing link:
No visible URL to inspect. You can't hover over a QR code to preview where it goes the way you can with a text link.
It's usually scanned on a phone. Most people pull out their personal or work mobile to scan a QR code, which can be outside the reach of the security software and web filtering protecting your office computers.
It hides well inside a PDF. Microsoft reported that by March 2026, around 70% of quishing emails were delivering the QR code inside a PDF or image attachment rather than the email body. A security filter that only scans the text of an email can miss a QR code buried in the attached file entirely.
The good news is that email security has caught up considerably. Microsoft Defender for Office 365 added the ability to detect QR codes during mail flow, extract the URL they point to, and run it through the same reputation and sandboxing checks as an ordinary link, including QR codes hidden inside attachments. If your business is on Microsoft 365 with the right security tier switched on, a good number of these emails are already being caught before they reach anyone's inbox. The catch is that plenty of businesses are on a licence that includes this protection but haven't had it properly configured, something we cover in what changed in Microsoft 365 security in 2026.
Why Small Businesses Are a Realistic Target, Not Just Big Ones
It's tempting to assume scammers go after large enterprises first. In practice, smaller businesses are an attractive target precisely because they're less likely to have advanced email security fully switched on, and a single successful login-credential theft can go a long way, into your accounting system, your client email history, or a supplier's invoice thread for a follow-up business email compromise scam.
The riskiest version of quishing isn't a straightforward password-stealing page. Some kits are built to intercept a live login session, including the multi-factor authentication step, by presenting a fake Microsoft login and MFA prompt and passing what the victim enters straight through to the real site in real time. That's why "just having MFA" isn't a complete answer on its own, the login page itself has to be genuine, which is exactly what a scan-and-type QR scam is designed to fake.
What a Quishing Attempt Typically Looks Like
Watch for these common lures turning up in a Perth business inbox:
An "MFA re-registration required" or "your Microsoft account needs verification" email with a QR code instead of a normal sign-in button.
A fake delivery notice, parking or toll fine with a "scan to pay" code.
An invoice, payslip or "secure document" that can only be viewed by scanning a code rather than clicking a link.
A PDF attachment that's mostly blank except for a QR code and a short instruction to scan it.
The same red flags that apply to any other phishing email still apply here: urgency, an unexpected sender, and a request to log in or pay. Our guide on how to identify phishing emails covers those signs in more detail, quishing is really the same scam wearing a different disguise.
How to Protect Your Business
On the IT side:
Confirm your email protection actually scans QR codes and attachment content, not just message text and standard links, this is a setting, not something every business automatically has switched on.
Keep MFA switched on everywhere, but pair it with sign-in methods (like passkeys or number-matching approval) that are harder for a fake login page to intercept than a plain six-digit code.
Review sign-in logs periodically for logins from unusual locations shortly after a suspicious email was received.
For your team:
Treat a QR code in an unexpected email exactly like an unexpected link, don't scan it.
If a QR code claims to be from Microsoft, your bank, or a supplier, go to the site directly by typing the address in yourself, rather than scanning.
Report anything that looks like this to whoever manages your IT, even if nobody clicked through. Knowing an attempt landed helps flag the same sender to everyone else.
The Bottom Line
Quishing isn't a fundamentally new scam, it's an old one (credential phishing) wearing a format that's harder to filter and easier for a busy employee to trust. The fix isn't complicated: make sure your email security is actually configured to inspect QR codes and attachments, keep MFA in place with phishing-resistant methods where you can, and remind staff that "scan to verify" deserves the same suspicion as "click to verify."
If you're not sure whether your Microsoft 365 security settings are catching this kind of thing, we can check for you. Get in touch or call (08) 9325 1196 and we'll take a look.



