Quishing: Why QR Code Scam Emails Are Slipping Past Perth Business Inboxes

QR code phishing (quishing) jumped 146% in the first quarter of 2026, and attackers are now hiding QR codes inside PDF attachments to dodge email filters. Here's how it works and how Perth businesses can stop it. From Computer Mechanics, Perth IT specialists since 1997.

BrettBrett · Workshop Manager & Senior Hardware Expert
12 August 2026
5 min read
Cybersecurity
Phishing
Email Security
Perth Business

Quishing is phishing done with a QR code instead of a clickable link, and it's currently one of the fastest-growing scam tactics hitting business inboxes. Microsoft's own threat intelligence team recorded a 146% jump in QR code phishing attacks over the first quarter of 2026 alone, and attackers are increasingly hiding the QR code inside a PDF attachment rather than the email body, specifically to slip past filters that only scan the message text. If a "scan to view your invoice" or "scan to reset your MFA" email has landed in your team's inbox lately, this is why.

What Is Quishing?

Instead of a normal phishing link you can hover over or check before clicking, the scam email contains an image of a QR code. The email might claim to be a delivery notice, a parking fine, a payslip, an MFA re-registration request, or a scanned document waiting for you. Scan the code with your phone, and it takes you to a fake login page built to steal your Microsoft 365 password, or straight to a malware download.

It works because it exploits a gap in how people (and some security tools) think about links. We've all been trained, rightly, to be suspicious of a link in an email. Fewer people apply the same caution to a QR code, because scanning one feels more like using a tool than clicking on something.

Why QR Codes Slip Past Email Filters

A handful of things make quishing genuinely harder to catch than an ordinary phishing link:

  • No visible URL to inspect. You can't hover over a QR code to preview where it goes the way you can with a text link.

  • It's usually scanned on a phone. Most people pull out their personal or work mobile to scan a QR code, which can be outside the reach of the security software and web filtering protecting your office computers.

  • It hides well inside a PDF. Microsoft reported that by March 2026, around 70% of quishing emails were delivering the QR code inside a PDF or image attachment rather than the email body. A security filter that only scans the text of an email can miss a QR code buried in the attached file entirely.

The good news is that email security has caught up considerably. Microsoft Defender for Office 365 added the ability to detect QR codes during mail flow, extract the URL they point to, and run it through the same reputation and sandboxing checks as an ordinary link, including QR codes hidden inside attachments. If your business is on Microsoft 365 with the right security tier switched on, a good number of these emails are already being caught before they reach anyone's inbox. The catch is that plenty of businesses are on a licence that includes this protection but haven't had it properly configured, something we cover in what changed in Microsoft 365 security in 2026.

Why Small Businesses Are a Realistic Target, Not Just Big Ones

It's tempting to assume scammers go after large enterprises first. In practice, smaller businesses are an attractive target precisely because they're less likely to have advanced email security fully switched on, and a single successful login-credential theft can go a long way, into your accounting system, your client email history, or a supplier's invoice thread for a follow-up business email compromise scam.

The riskiest version of quishing isn't a straightforward password-stealing page. Some kits are built to intercept a live login session, including the multi-factor authentication step, by presenting a fake Microsoft login and MFA prompt and passing what the victim enters straight through to the real site in real time. That's why "just having MFA" isn't a complete answer on its own, the login page itself has to be genuine, which is exactly what a scan-and-type QR scam is designed to fake.

What a Quishing Attempt Typically Looks Like

Watch for these common lures turning up in a Perth business inbox:

  • An "MFA re-registration required" or "your Microsoft account needs verification" email with a QR code instead of a normal sign-in button.

  • A fake delivery notice, parking or toll fine with a "scan to pay" code.

  • An invoice, payslip or "secure document" that can only be viewed by scanning a code rather than clicking a link.

  • A PDF attachment that's mostly blank except for a QR code and a short instruction to scan it.

The same red flags that apply to any other phishing email still apply here: urgency, an unexpected sender, and a request to log in or pay. Our guide on how to identify phishing emails covers those signs in more detail, quishing is really the same scam wearing a different disguise.

How to Protect Your Business

On the IT side:

  • Confirm your email protection actually scans QR codes and attachment content, not just message text and standard links, this is a setting, not something every business automatically has switched on.

  • Keep MFA switched on everywhere, but pair it with sign-in methods (like passkeys or number-matching approval) that are harder for a fake login page to intercept than a plain six-digit code.

  • Review sign-in logs periodically for logins from unusual locations shortly after a suspicious email was received.

For your team:

  • Treat a QR code in an unexpected email exactly like an unexpected link, don't scan it.

  • If a QR code claims to be from Microsoft, your bank, or a supplier, go to the site directly by typing the address in yourself, rather than scanning.

  • Report anything that looks like this to whoever manages your IT, even if nobody clicked through. Knowing an attempt landed helps flag the same sender to everyone else.

The Bottom Line

Quishing isn't a fundamentally new scam, it's an old one (credential phishing) wearing a format that's harder to filter and easier for a busy employee to trust. The fix isn't complicated: make sure your email security is actually configured to inspect QR codes and attachments, keep MFA in place with phishing-resistant methods where you can, and remind staff that "scan to verify" deserves the same suspicion as "click to verify."

If you're not sure whether your Microsoft 365 security settings are catching this kind of thing, we can check for you. Get in touch or call (08) 9325 1196 and we'll take a look.

Brett
Written by
Brett
Workshop Manager & Senior Hardware Expert · 15+ years in IT

Brett is the Workshop Manager and a senior hardware expert at Computer Mechanics, a 15-year veteran known for rapid issue diagnosis and deep, hands-on knowledge across hardware, systems and day-to-day support. His commitment to quality has earned long-standing customer trust.

Meet the IT Support Perth team →
Brett
12 August 2026
5 min read
Cybersecurity
Phishing
Email Security
Perth Business

Stay Updated with IT Insights

Get the latest cybersecurity tips and technology insights delivered to your inbox

Related Articles

Microsoft's August 2026 Patch Tuesday Fixed a Flaw Already Under Attack: What to Do

Microsoft's August 2026 security update patched a Windows flaw that was already being exploited to seize full control of machines, plus a critical SharePoint hole. Here's what Perth businesses need to check this week. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Does Microsoft 365 Back Up Your Data? Why the Answer Trips Up Perth Businesses

Microsoft 365 protects the platform, not your data. A plain-English look at the shared responsibility model, the retention limits that catch businesses out, and what a real backup needs to cover. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Microsoft 365 Keeps Going Down: How Perth Businesses Can Keep Working Through the Next Outage

Microsoft 365 has had several major outages in 2026, including a wide North American incident in July. Here's how Perth businesses can keep operating when Teams, Outlook or SharePoint go down. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Need Expert IT Support?

Get personalized advice from our Perth IT experts. Free consultation available.

Related Content

Continue Reading

Explore more insights and expert advice on IT support, cybersecurity, and digital transformation

ATO & myGov Impersonation Scams Are Surging: What Perth Businesses Must Know
Scams
Cybersecurity

ATO & myGov Impersonation Scams Are Surging: What Perth Businesses Must Know

ATO impersonation scam reports jumped 12% in June 2026. Here's how the scam targets Perth business owners and five steps to protect your business. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
8/6/2026
Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.
CyberSecurity
ITSupportPerth

Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.

Most small business owners believe end-to-end encryption means their messages are completely private. A recent FBI case proves that assumption is dangerously incomplete.

5 min read
4/15/2026
What’s new in SMB1001:2026?
SMB1001
SMB10012026

What’s new in SMB1001:2026?

SMB1001:2026 updates for Perth SMBs: Mandatory DMARC from Silver tier, 5 maturity levels, Essential Eight alignment. Get certified, cut insurance costs, win tenders—start your roadmap today!

5 min read
2/25/2026
Call us