← All articles
Guard

QR code phishing (quishing) in Microsoft 365: why filters miss it

24 June 2026 · 3 min read

Quishing is phishing that delivers its malicious link as a QR code instead of as clickable text. The email looks routine, often with a single image and a short instruction: "scan to verify your account", "scan to view the secure document", "scan to keep your password". The victim lifts their phone, scans the code, and lands on a credential-harvesting page that the email filter never had a chance to see.

It works because it sidesteps the two things that usually protect a Microsoft 365 inbox: link scanning and the corporate device. Understanding both is the key to stopping it.

Why QR codes slip past email filters

Most email security reads text. It inspects the visible body, the headers and any URLs written into the message, checks them against reputation data, and rewrites or blocks the bad ones. A QR code defeats that model in two ways:

  • The link is inside an image. There is no URL in the text for a text-based scanner to read. The destination is encoded in a picture, which many filters do not decode.
  • The click moves to a phone. When the victim scans with a personal phone, the dangerous link opens outside your Microsoft 365 protections entirely: no Safe Links, no managed browser, often no endpoint controls. The riskiest moment happens on the least protected device.

That combination is why quishing rose so sharply once attackers realised text-link filtering had gotten good. They simply moved the payload to where the filter is not looking.

The lures that work

Quishing leans on the same psychology as classic phishing: authority, urgency and a routine-looking action. The patterns that show up most:

  • MFA or password "re-enrollment" that claims your security setup is expiring today.
  • Shared document or DocuSign notifications with a QR code instead of a button.
  • Payroll, benefits or HR messages timed around the end of the month.
  • Delivery and invoice notices aimed at finance and operations staff.
If a message wants you to scan a code with your phone to sign in or approve something, treat it as
guilty until proven innocent, no matter how ordinary the sender looks.

How to defend against it

No single control catches everything, and any honest vendor will tell you so. A layered approach works:

  1. Decode and judge the code, not just the text. Defences that actually read the QR image, extract the destination and weigh its reputation can flag the message that a text-only filter waves through.
  2. Warn the person in the message. A plain-language banner that says "this email contains a QR code leading to an unrecognised site" turns an invisible risk into a decision the recipient can make. This matters most for the non-technical staff quishing targets.
  3. Make reporting one click. When someone is unsure, the safe path is a report button that routes to whoever can act, not a forwarded email that gets lost.
  4. Reinforce the rule. Sign-ins and approvals happen by navigating to the app yourself, never by scanning a code from an email.

This is the gap Olyteck Guard is built for: it scores inbound mail for spoofing, impersonation, malicious links and QR codes, adds an in-message banner with a public "why it was flagged" page, and gives people a one-click way to report. The detection lives where the attack lands, which is the inbox, and the verdict is written in language a finance manager can act on.

A practical baseline

  • Use email security that decodes and evaluates QR codes, not only text links
  • Add visible banners for image-only and QR-bearing messages
  • Give staff a one-click report button and a clear escalation path
  • Train on the "scan to sign in" pattern with real examples
  • Set the rule: authenticate by going to the app yourself, never from a scanned code

Attackers moved the link into a picture because the picture was the blind spot. Close that blind spot, make the warning visible, and quishing turns from an invisible trap into one more flagged message your team already knows to ignore.

See it on your own Microsoft 365

A 20-minute call, or start free in your browser. EU-hosted, GDPR-aligned, no credit card.